~/f4n6 $ grep -r "Scope of Salesforce Attacks Expands as Icarus Leaks Data" ./investigations/ --include="*.md"

Scope of Salesforce Attacks Expands as Icarus Leaks Data

Jeff Davies 24 Jun 2026 8 min read

1. Executive summary

Market intelligence platform Klue disclosed on 19 June 2026 that an attacker obtained OAuth tokens used to connect Klue to customer Salesforce environments, after gaining access via a compromised legacy credential associated with a Klue integration service. The intrusion occurred on 11 June 2026 and was detected one day later. Multiple cybersecurity vendors — including Huntress, Recorded Future, ReliaQuest, Tanium, Jamf, Gong, HackerOne, Kudelski Security, Snyk, Insurity and Sprout Social — have confirmed their Salesforce CRM data was accessed. A previously unobserved extortion group calling itself "Icarus" has claimed the attack on its data-leak site and is contacting affected organisations directly. The bottom-line risk for EMEA financial services firms is unauthorised disclosure of CRM-resident business contacts, quotes and sales correspondence where Klue is integrated with Salesforce; no passwords, payment card data or core product telemetry are reported as compromised. Attribution to "Icarus" is currently unconfirmed — the group has no MITRE ATT&CK profile and the campaign TTPs resemble prior ShinyHunters-style OAuth abuse against Salesforce.

2. Regulatory framing

Article Trigger (fact in this item) Practical impact
DORA Art. 28 — ICT third-party risk — general principles Klue is an ICT third-party provider whose integration service was compromised, exposing customer Salesforce data. Reassess third-party risk register entries for Klue; document the incident and the controls now in place (token revocation, credential rotation).
DORA Art. 29 — preliminary assessment of ICT concentration risk Klue serves more than 250,000 companies; firms using Klue for Salesforce enrichment may have a concentration point. Determine whether Klue is a critical or important ICT service provider supporting CRM workflows and, if so, evaluate substitutability.
DORA Art. 30 — key contractual provisions with ICT third-party providers Klue has disconnected all integrations (Salesforce, Gong, HubSpot, SharePoint, Google Drive) and engaged CrowdStrike; contractual notification and audit rights are now in play. Review Klue contract for notification SLAs, audit rights, exit assistance and liability; trigger formal vendor risk review.
DORA Art. 17 — ICT-related incident management process A confirmed third-party-driven incident affecting customer Salesforce data requires a documented incident management response. Activate the firm's ICT incident management process; record detection, containment, eradication and recovery steps.
DORA Art. 18 — classification of ICT-related incidents and cyber threats The incident must be classified against the firm's ICT incident taxonomy (e.g. data exfiltration via third-party OAuth token abuse). Apply classification criteria; document severity, scope and impact.
DORA Art. 19 — reporting of major ICT-related incidents to competent authorities If, after classification, the incident is determined to be major (significant CRM data exposure, multiple affected clients, reputational impact), reporting obligations are engaged. Prepare initial notification within the applicable reporting window once classification is complete.
NIS2 Art. 21(2)(d) — supply chain security measures Klue sits in the supply chain between the firm and Salesforce; the compromise demonstrates a supply-chain vector. Verify supply-chain security measures (vendor due diligence, integration scoping, token hygiene) cover integration-service providers.
NIS2 Art. 23 — incident reporting obligations If the firm is in scope and the incident meets the significant-impact threshold, early warning and incident notification obligations apply. Prepare early warning within the early-warning window and follow-up notification per the applicable timeline.
UK NIS 2018 — OES/RDSP duties UK operators of essential services or relevant digital service providers using Klue for CRM enrichment must consider incident-handling duties. UK in-scope entities should review their competent-authority notification duties under the UK NIS Regulations 2018.

3. Technical analysis & attack chain

  1. Initial access — legacy credential at integration service. On 11 June 2026, an attacker used a compromised legacy credential associated with a Klue integration service to obtain OAuth tokens used to connect Klue to third-party platforms, including Salesforce (per Klue CEO Jason Smith's blog post).
  2. Token theft. The attacker used the integration-service foothold to obtain OAuth tokens for Klue's Salesforce (and other) integrations.
  3. Pivot to customer environments. Using the stolen tokens, the attacker authenticated to customer Salesforce environments and accessed CRM data. Huntress and ReliaQuest observed the activity and notified Klue.
  4. Detection. Klue detected the unauthorised activity on 12 June 2026, one day after initial access.
  5. Containment by vendor. Klue disconnected all integrations with Salesforce, Gong, HubSpot, SharePoint and Google Drive; revoked credentials, tokens and active integrations; engaged CrowdStrike for investigation and response.
  6. Extortion phase. A group calling itself "Icarus" (active since 28 April 2026 per its leak-site entry) began emailing affected customers directly. Huntress shared an extortion email with subject line "top secret email" purportedly sent from "mr bean", instructing the recipient to contact the attackers via Session messenger and threatening publication of stolen data within 48 hours.

Technical specifics relevant to defenders

  • Component abused: Klue integration service (vendor-side) and the OAuth tokens it held for customer Salesforce integrations. No specific CVE is associated with this incident; the vector is credential and token abuse, not a software vulnerability.
  • Data scope observed: Business contacts, price quotes, sales-related data and messaging. Huntress explicitly states no threat data, passwords, payment card information or engineering data relating to its agent/telemetry was affected. Huntress and other victims state there is no indication their products or infrastructure were compromised — the impact is specific to CRM data.
  • TTP parallels: ReliaQuest notes the campaign "resembles the 2025 and 2026 third-party OAuth abuse campaigns against Salesforce." The activity is distinct from prior ShinyHunters operations against Salesforce, Salesloft Drift and Gainsight, although Risky Business flags the possibility that "Icarus" is a fake persona, offshoot or collaborator of ShinyHunters.
  • Extortion tradecraft: Use of Session messenger for contact, short (48-hour) deadlines, direct victim contact in addition to the leak-site posting.

Unconfirmed / single-sourced claims. Attribution to "Icarus" is unconfirmed: the group has no MITRE ATT&CK profile and the extortion email's poor grammar and misspellings are consistent with multiple unaffiliated actors. The hypothesis that "Icarus" is a ShinyHunters offshoot or collaborator is analyst speculation from Risky Business, not corroborated by primary evidence.

4. Mitigation & containment

P1 — within 24 hours

  • Inventory exposure. Identify any business unit, subsidiary or vendor using Klue Battlecards or any other Klue integration with Salesforce. Confirm whether Klue has notified your organisation as a customer.
  • Rotate Salesforce credentials and API keys for any user, service account or integration that interacted with Klue data, including any OAuth refresh tokens issued to Klue.
  • Revoke and reissue OAuth tokens for any Klue-related Salesforce connected app; force re-consent.
  • Audit Salesforce audit logs and Event Monitoring (if licensed) for the period 11 June 2026 to date for: logins from unfamiliar ASNs/IPs, mass record reads, report exports, API calls originating from Klue integration IPs, and any session originating from outside expected geographies.
  • Block known Klue integration IPs at the WAF/proxy if Klue publishes them; otherwise restrict Salesforce API traffic to allow-listed sources until tokens are rotated.
  • Search mailboxes for the extortion email subject "top secret email" and the sender display name "mr bean"; quarantine and report any matches to the incident response team. Do not engage.

P2 — within 72 hours

  • Review Salesforce connected apps and remove any Klue-related app that is no longer required; re-authorise only after a documented risk assessment.
  • Enable Salesforce IP restrictions, MFA and session-based permissions for all CRM users; verify least-privilege profiles for sales/CRM roles.
  • Engage Klue in writing to obtain: scope of tokens compromised, list of customer environments accessed, timeline of attacker activity, and confirmation that all Klue-side tokens have been revoked.
  • Vendor risk review under DORA Art. 28/30: trigger formal review of Klue as an ICT third-party provider; document compensating controls and exit options.
  • Concentration-risk assessment under DORA Art. 29: determine whether Klue is a critical or important service provider for CRM workflows and document substitutability.

P3 — within 7 days

  • Tabletop exercise covering third-party OAuth token abuse scenarios; validate incident classification (DORA Art. 18) and reporting readiness (DORA Art. 19 / NIS2 Art. 23).
  • Contractual remediation: request from Klue post-incident report, root-cause analysis, and contractual undertakings on token storage, rotation cadence and integration-service authentication hardening.
  • Threat-model update: add "integration-service legacy credential compromise" as a documented scenario; review other vendors with similar integration patterns (Gong, HubSpot, SharePoint, Google Drive, Zoom) for the same exposure.
  • User awareness brief to sales/CRM teams on the extortion email pattern and the Session-messenger contact vector.

5. Indicators of compromise

Type Value Confidence Source
email-subject top secret email high Huntress extortion email shared with The Register
email-sender-display-name mr bean high Huntress extortion email shared with The Register
messaging-channel Session messenger (address not disclosed in source) high Huntress extortion email shared with The Register
dark-web-leak-site Icarus data-leak site (URL not disclosed in source) medium The Register / Risky Business
incident-date-initial-access 2026-06-11 high Klue CEO blog post via The Register
incident-date-detection 2026-06-12 high Klue CEO blog post via The Register
email-subject  top secret email
email-sender-display-name  mr bean
messaging-channel  Session messenger
incident-date-initial-access  2026-06-11
incident-date-detection  2026-06-12

6. Detection

rule AT_2026_06_24_Klue_OAuth_Extortion_Email
{
    meta:
        author = "Adverse Trace"
        date = "2026-06-24"
        description = "Detects extortion email content associated with the Klue/Salesforce OAuth token theft campaign attributed (unconfirmed) to 'Icarus'."
        reference = "https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743"

    strings:
        $subj = "top secret email"
        $sender = "mr bean"
        $klue = "Klue.com" ascii nocase
        $salesforce = "Salesforce" ascii nocase
        $session = "Session @" ascii nocase
        $exfil = "exfiltrated" ascii nocase
        $breach = "breach" ascii nocase

    condition:
        3 of ($subj, $sender, $klue, $salesforce, $session, $exfil, $breach)
}
title: Klue OAuth Token Abuse Against Salesforce (Klue supply-chain incident)
id: at-2026-06-24-klue-oauth
status: experimental
description: |
  Detects anomalous OAuth-token-driven access to Salesforce originating from
  Klue integration infrastructure following the 11 June 2026 Klue compromise.
  Hunt for unusual API/connected-app activity against Salesforce instances
  that previously integrated with Klue.
author: Adverse Trace
date: 2026-06-24
references:

  - https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743
logsource:
  product: salesforce
  service: event_monitoring
detection:
  selection_api_burst:
    EventType|contains:

      - "API"
      - "ConnectedApp"
    Application|contains:

      - "Klue"
    Uri|endswith:

      - "/services/data"
      - "/services/oauth2"
  selection_unusual_source:
    EventType: "Login"
    Application|contains: "Klue"
    LoginType: "Application"
  condition: selection_api_burst or selection_unusual_source
falsepositives:

  - Legitimate Klue integration activity prior to 11 June 2026
  - Scheduled Klue data syncs (validate against known schedules)
level: high

7. Sources

  • Dark Reading — Scope of Salesforce Attacks Expands as Icarus Leaks Data — https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data (23 Jun 2026)
  • BleepingComputer — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
  • DataBreaches.net — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://databreaches.net/2026/06/21/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
  • The Register — Security shops among the 'hundreds' of Klue hack victims — https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743
  • Risky Business — Risky Bulletin: Klue breach impacts security firms — https://news.risky.biz/risky-bulletin-klue-breach-impacts-security-firms/
  • Snyk — When a vendor's breach becomes yours: lessons from the Klue incident — https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/
  • SecurityWeek — Cybersecurity Firms Impacted by Klue Supply Chain Attack — https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/

8. Adverse Trace position

Severity: Moderate. This is a third-party-driven CRM data exposure with no reported compromise of products, infrastructure, passwords or payment data; however, the affected data (business contacts, quotes, sales correspondence) is commercially sensitive and the supply-chain pattern matches prior high-impact OAuth abuse campaigns against Salesforce. Attribution to "Icarus" remains unconfirmed — the group has no MITRE ATT&CK profile and the campaign TTPs overlap with ShinyHunters-style activity, so we treat the actor label as a working hypothesis rather than a confirmed attribution. EMEA financial services clients using Klue-integrated Salesforce should treat this as a P1 vendor incident: rotate tokens and credentials within 24 hours, audit Salesforce logs for the 11 June 2026 to present window, and trigger DORA/NIS2 third-party risk and concentration reviews. Adverse Trace will monitor for further victim disclosures, Icarus leak-site postings, and any vendor-side root-cause detail from Klue/CrowdStrike, and will update this advisory if the scope, severity or attribution changes.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies