U.S. — Klue, a market intelligence platform, disclosed a supply chain attack that began on June 11. Attackers connected to Klue's backend servers and executed unauthorized commands. Klue confirmed it discovered unauthorized activity on June 12 that affected a portion of its integration infrastructure and notified customers of the incident the same day.

The attackers pushed a code update to harvest OAuth tokens for customer integrations with Klue. These tokens were used to access customer data in third-party platforms. Klue deactivated OAuth tokens for all customers and disabled integrations including Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack.

ReliaQuest reported the hackers abused the Salesforce REST API to exfiltrate customer relationship management data over a 24-hour window. ReliaQuest observed nearly a thousand queries in 15 minutes during the data exfiltration. ReliaQuest researchers also observed threat actors generating OAuth tokens and using automated Python scripts to query Salesforce's REST API for nearly 24 hours. The activity began with reconnaissance of an organization's Salesforce instances and then moved to data exfiltration. Salesforce disabled the Klue Battlecards app integration on June 17, stating it detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data.

Klue CEO Jason Smith wrote, "On June 12, we identified unauthorized activity affecting a portion of Klue's integration infrastructure. Since then, we've been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on." Smith added, "Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments." Klue states there is no evidence that customer content stored directly within the Klue platform was impacted. Klue engaged CrowdStrike to assist with its response and notified law enforcement of the attack.

Cybersecurity firms Huntress and Recorded Future disclosed they were impacted by the supply chain attack. Huntress confirmed it was among the affected companies. "The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging. No threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected," Huntress said. Huntress also stated it received attempted extortion communication from a threat actor calling itself "mr bean," and this communication pointed to a Session Messenger ID associated with Icarus. "With those matching data points, we have high confidence that the Icarus actor is responsible for the Klue compromise and this supply chain attack," Huntress said. Icarus listed Klue on its leak site on June 22.

At least nine organizations have publicly acknowledged the impact of the supply chain attack on Klue, including HackerOne, Jamf, OneTrust, Snyk, and Tanium. Insurity and Sprout Social notified their customers of the incident. Gong disabled its Klue integration. "We can confirm no direct impact on call recordings or customer transcripts. Examples of data accessed included user names, user business titles, and user emails," Gong said.