Relevance: primary · Type: background
Confidence100%
Klue is a market intelligence platform.
Relevance: primary · Type: event
Confidence100%
Cybersecurity firms Huntress and Recorded Future disclosed they were impacted by a supply chain attack on Klue.
Relevance: primary · Type: event
Confidence100%
The attack on Klue began on June 11.
Relevance: primary · Type: action
Confidence100%
Attackers connected to Klue’s backend servers and executed unauthorized commands.
Relevance: primary · Type: action
Confidence100%
Attackers pushed a code update to harvest OAuth tokens for customers’ Klue integrations.
Relevance: primary · Type: action
Confidence100%
Klue notified customers of the incident on June 12.
Relevance: primary · Type: action
Confidence100%
Klue deactivated OAuth tokens for all customers.
Relevance: primary · Type: action
Confidence100%
Klue disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack.
Relevance: primary · Type: action
Confidence100%
ReliaQuest reported that hackers abused the Salesforce REST API to exfiltrate customer relationship management data over a 24-hour window.
Relevance: supporting · Type: action
Confidence100%
ReliaQuest observed a concentrated burst of nearly a thousand queries in 15 minutes during the data exfiltration.
Relevance: supporting · Type: action
Confidence100%
ReliaQuest observed sustained data extraction windows lasting over 6 hours.
Relevance: primary · Type: action
Confidence100%
Salesforce disabled the Klue Battlecards app integration on June 17.
Relevance: primary · Type: action
Confidence100%
Salesforce stated it detected unusual activity involving the Klue Battlecards app that may have resulted in unauthorized access to a subset of customer data.
Relevance: primary · Type: action
Confidence100%
Huntress confirmed it was among the companies affected by the supply chain attack.
Huntress, cybersecurity firm
Relevance: primary · Type: quote
Confidence100%
"The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging. No threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected," Huntress said.
Relevance: primary · Type: action
Confidence100%
Recorded Future confirmed it was among the companies affected by the supply chain attack.
Recorded Future, cybersecurity firm
Relevance: primary · Type: quote
Confidence100%
"While our investigation is ongoing, we believe the impact was limited to business data fields stored in our Salesforce database, such as client contact names and email addresses. Certain business contract information may also have been potentially included in the impacted data," Recorded Future said.
Relevance: primary · Type: background
Confidence100%
The incident was limited to the Klue-Salesforce integration.
Relevance: primary · Type: background
Confidence100%
Attackers did not access any systems belonging to or maintained by Huntress or Recorded Future.
Relevance: primary · Type: action
Confidence100%
Huntress stated it received attempted extortion communication from a threat actor calling itself "mr bean".
Relevance: primary · Type: action
Confidence100%
The extortion communication pointed to a Session Messenger ID associated with Icarus.
Relevance: supporting · Type: background
Confidence100%
Icarus is an extortion group that emerged in April 2026.
Huntress, cybersecurity firm
Relevance: primary · Type: quote
Confidence100%
"With those matching data points, we have high confidence that the Icarus actor is responsible for the Klue compromise and this supply chain attack," Huntress said.
Relevance: primary · Type: event
Confidence100%
Icarus listed Klue on its leak site on June 22.
Relevance: primary · Type: action
Confidence100%
Attackers gained access to Klue Battlecards integration service accounts.
Relevance: primary · Type: action
Confidence100%
Attackers used OAuth tokens associated with customer Salesforce instances to carry out data theft.
Relevance: primary · Type: action
Confidence100%
ReliaQuest researchers observed threat actors generating OAuth tokens and using automated Python scripts to query Salesforce's REST API for nearly 24 hours.
Relevance: supporting · Type: action
Confidence100%
ReliaQuest stated the activity began with reconnaissance of an organization's Salesforce instances through the '/services/data/v59.0/sobjects' endpoint.
Relevance: supporting · Type: action
Confidence100%
ReliaQuest stated attackers exfiltrated data using the '/services/data/v59.0/query' endpoint.
ReliaQuest, security firm
Relevance: supporting · Type: quote
Confidence100%
"The attacker then hit the same endpoint, sending almost a thousand queries in a 15-minute window in at least one environment," ReliaQuest explained.
Huntress, cybersecurity firm
Relevance: supporting · Type: quote
Confidence100%
Huntress reported that the adversary suggested in an initial email, "we advice you to write to us on Session".
Relevance: primary · Type: action
Confidence100%
Klue CEO Jason Smith confirmed the company discovered unauthorized activity on June 12 affecting part of Klue's integration infrastructure.
Jason Smith, Klue CEO
Relevance: primary · Type: quote
Confidence100%
"On June 12, we identified unauthorized activity affecting a portion of Klue's integration infrastructure. Since then, we've been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on," wrote Jason Smith.
Jason Smith, Klue CEO
Relevance: primary · Type: quote
Confidence100%
"Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments," wrote Jason Smith.
Relevance: primary · Type: background
Confidence100%
Klue stated there is no evidence that customer content stored directly within the Klue platform was impacted.
Relevance: supporting · Type: action
Confidence100%
Klue confirmed it engaged CrowdStrike to assist with the response.
Relevance: primary · Type: event
Confidence100%
At least nine organizations have publicly acknowledged the impact of the supply chain attack on Klue.
Relevance: primary · Type: event
Confidence100%
HackerOne, Jamf, OneTrust, Snyk, and Tanium disclosed they were affected by the attack.
Relevance: primary · Type: event
Confidence100%
Insurity and Sprout Social notified their customers of the incident.
Relevance: primary · Type: action
Confidence100%
Gong disabled its Klue integration.
Gong, revenue intelligence platform
Relevance: primary · Type: quote
Confidence100%
"We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails," Gong said.
Icarus, extortion group
Relevance: primary · Type: quote
Confidence100%
Icarus posted on its leak site: "As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated."
Relevance: supporting · Type: action
Confidence100%
Klue notified law enforcement of the attack.
forum Comments (0)
No comments yet. Be the first to comment.