# Third-Party Integration Nightmare: Klue Breach Exposes Data from 15+ Enterprise Customers Including LastPass and BeyondTrust


A compromised legacy credential gave a threat actor access to Klue's infrastructure, enabling a cascade attack that compromised OAuth tokens and breached Salesforce instances across multiple high-profile cybersecurity and enterprise software companies. Over a dozen organizations have now publicly confirmed exposure.


## The Incident


On June 24, 2026, LastPass became the latest in a growing list of technology firms to disclose unauthorized access to customer data through a breach of Klue, a competitive intelligence platform that integrates with Salesforce and other enterprise tools. The attacker, operating under the alias Icarus, leveraged legacy credentials to infiltrate Klue's systems and then weaponized OAuth tokens to gain unauthorized access to third-party integrations.


The attack chain was methodical and well-executed:


1. Initial Access: Icarus obtained compromised legacy credentials for Klue's infrastructure

2. Token Generation: Once inside Klue, the attacker generated OAuth tokens for integrated third-party platforms

3. Downstream Breach: These tokens were used to breach connected Salesforce instances

4. Data Exfiltration: Automated scripts systematically extracted bulk customer data from the compromised Salesforce environments


Klue integrates with multiple enterprise platforms, making it an effective pivot point for supply chain-style attacks. Rather than targeting each company directly, the attacker compromised a central hub with access to many downstream systems.


## Companies Confirmed Affected


As of mid-June 2026, at least 15 organizations have publicly acknowledged exposure:


| Company | Industry | Data Exposed |

|---------|----------|--------------|

| LastPass | Password Management | CRM data, customer contact info, support case records |

| BeyondTrust | Identity & Access Management | Business contact info, sales data |

| 8×8 | Communications | Business data, customer contact information |

| Pendo | Product Management | Customer and business data |

| HackerOne | Bug Bounty Platform | Business information |

| Huntress | Cybersecurity | Customer data |

| Insurity | Insurance Tech | Business contact information |

| Jamf | Mobile Device Management | Customer contact data |

| OneTrust | Privacy/Compliance | CRM and business data |

| Recorded Future | Threat Intelligence | Business information |

| Snyk | Developer Security | Customer data |

| Sprout Social | Social Media Management | Business data |

| Tanium | Endpoint Management | Customer information |

| Gms-net | Communications Solutions | Salesforce data |


Huntress, among the first to disclose, estimated that the true scope extends to numerous other Klue customers who have not yet publicly acknowledged exposure.


## Technical Details: How the Attack Worked


The Klue incident represents a sophisticated supply chain attack that exploited the trust relationships built into modern SaaS integrations.


### The Attack Chain


Step 1: Legacy Credential Exploitation

The attacker obtained what Klue described as a "compromised legacy credential"—likely a forgotten service account, hardcoded API key, or abandoned administrative password. Legacy credentials are particularly dangerous because they often lack:

  • Multi-factor authentication (MFA)
  • Activity monitoring
  • Regular rotation policies
  • Clear ownership documentation

  • Step 2: OAuth Token Generation

    Once inside Klue's environment, Icarus had sufficient access to generate OAuth tokens that Klue had previously issued to third-party integrations. OAuth tokens are designed to grant limited, delegated access without exposing the underlying passwords. However, if an attacker controls the system issuing the tokens, they can generate new tokens with broad permissions.


    Step 3: Salesforce Instance Compromise

    With valid OAuth tokens, the attacker could authenticate to connected Salesforce instances as if they were legitimate Klue API requests. Salesforce would have no way to distinguish legitimate traffic from malicious token usage.


    Step 4: Bulk Data Exfiltration

    The attacker deployed automated scripts to systematically extract data at scale. This wasn't manual reconnaissance—it was industrial-scale harvesting, suggesting premeditation and technical sophistication.


    ### Data Accessed


    The compromised data was limited to systems integrated through Klue, not to core LastPass, BeyondTrust, or other companies' internal infrastructure. Exposed data included:


  • Customer names and contact information (email, phone, physical addresses)
  • CRM records (customer relationship data, sales opportunities, deal information)
  • Support ticket data (support case history, customer issues, resolution notes)
  • Sales and business intelligence (pipeline data, prospect information, customer interactions)

  • Notably, no encryption keys, password vaults, authentication credentials, or customer data stored within core products were compromised. LastPass explicitly confirmed that "customer vaults remain secure" and that "LastPass products, services, and infrastructure were not impacted in any way."


    ## Response and Containment


    ### Immediate Actions


    Both Salesforce and Gong disabled the Klue integration in response to the incident, cutting off the attack vector. Affected companies took parallel action:


  • Rotated exposed OAuth tokens to invalidate any tokens the attacker had generated
  • Notified law enforcement (FBI, CISA, and international partners)
  • Engaged third-party incident responders and forensic teams
  • Launched investigations in coordination with Klue and Salesforce

  • LastPass stated it had "discontinued access to Klue" entirely and worked with both Klue and Salesforce to understand the scope of the breach.


    ### Third-Party Leak Site


    Before going offline, Icarus's Tor-based leak site listed several confirmed victims and at least four additional organizations that had not yet publicly disclosed exposure. Security researchers estimate the true victim count is significantly higher, with many Klue customers still investigating their environments or preparing disclosure notices.


    ## Implications and Risk Assessment


    ### For Affected Organizations


    The breach underscores a critical risk in modern enterprise software: third-party integrations create implicit trust relationships that can become attack vectors. Organizations using Klue trusted it to:


    1. Securely handle OAuth tokens

    2. Maintain access controls on integration credentials

    3. Log and monitor API activity

    4. Alert on anomalous token generation or data access


    When Klue failed on these fronts, the downstream organizations bore the consequences despite having no direct control over Klue's infrastructure.


    ### For the Broader Industry


    This incident exemplifies the supply chain attack pattern that has become increasingly common in the SaaS ecosystem:


  • SolarWinds (2020): Compromised software update affected thousands of government and private sector customers
  • MOVEit (2023): Unpatched file transfer tool became an attack vector for ransomware groups
  • 3CX (2023): Legitimate supply chain poisoning through compromised build infrastructure

  • Each incident demonstrates that an attacker needs only to compromise one vendor to reach hundreds of downstream organizations. The Klue attack was comparatively smaller in scale but follows the same playbook.


    ### For Data Exposed Organizations


    Exposed CRM data and customer contact information are valuable to attackers for:


  • Targeted phishing campaigns (spear-phishing using legitimate contact names and relationships)
  • Social engineering (pretexting attacks using knowledge of customer interactions)
  • Business intelligence theft (understanding customer bases, sales pipelines, and market positioning)
  • Email list monetization (selling contact databases to other threat actors)

  • Unlike password breaches or encryption key theft, CRM exposure doesn't immediately enable unauthorized system access—but it enables *human-targeted attacks* against employees and customers of the affected organizations.


    ## HackWire Analysis


    The Klue incident exposes a structural vulnerability in how modern enterprises approach third-party risk: We've outsourced data security to platforms we don't control, and we're discovering the cost only after the breach.


    This isn't Klue's negligence alone. Over the past three years, the SaaS integration ecosystem has exploded. Every Fortune 500 company now runs dozens of vendor integrations—each with OAuth tokens, API keys, and implicit trust. And most organizations still manage these integrations in spreadsheets if they manage them at all.


    The "legacy credential" that opened this door wasn't a hypothetical problem. It was an actual, exploitable security debt that accumulated because:


    1. Service accounts aren't inventoried systematically. Nobody knows which contractors, former employees, or departed integrations still have active credentials.

    2. OAuth tokens are invisible to most enterprises. If Salesforce or Klue isn't actively monitoring token generation, no organization can know if new tokens are being created in their name.

    3. Integration risk isn't quantified. A Klue integration looked like a convenient competitive intelligence tool. Few organizations asked: "What happens if Klue gets breached?"


    The pattern accelerated after the 3CX and MOVEit incidents proved that supply chain attacks were no longer theoretical. Yet defensive posture hasn't kept pace. Most organizations still treat vendor integrations as fire-and-forget configurations.


    Here's what needs to change: Every OAuth integration should require explicit token refresh policies, activity monitoring, and kill-switch controls. If an attacker generates tokens in your name, you should know within minutes, not months. Enterprises need inventory and monitoring for third-party integrations the same way they monitor on-premises Active Directory.


    The companies affected here—BeyondTrust, LastPass, Snyk, OneTrust—are all *security vendors*. They understand defense in depth, least-privilege access, and supply chain risk. None of that prevented exposure through a Klue integration. That's the real lesson: even defenders can't protect against risks they've outsourced to platforms they don't run.


    — HackWire Editorial


    ## Recommendations for Organizations


    ### Immediate Actions (Days 1-7)


  • Audit all active integrations with business intelligence, CRM, and analytics platforms
  • Inventory OAuth tokens granted to third-party applications in Salesforce, Google Workspace, Microsoft 365, and other cloud platforms
  • Monitor for suspicious CRM access patterns or bulk data exports from the last 90 days
  • Contact customers directly if their contact information was exposed in your CRM (don't rely on automated alerts)
  • Rotate compromised OAuth tokens and regenerate any that may have been exposed

  • ### Medium-Term Actions (Weeks 2-8)


  • Implement API access monitoring with alerts for unusual token generation, bulk exports, or anomalous API activity
  • Establish integration risk ratings for all third-party vendors based on data sensitivity and integration scope
  • Require MFA on all service accounts and API key management systems
  • Conduct security assessments of vendors with deep access to CRM, HR, or customer data systems
  • Update incident response playbooks to include third-party integration compromise scenarios

  • ### Long-Term Strategic Changes


  • Adopt Zero Trust principles for third-party integrations (verify every request, assume compromise)
  • Implement SaaS security platforms that provide unified visibility into cloud application activity
  • Establish vendor re-assessment cadence (annual security reviews, penetration testing clauses)
  • Segment integration data — limit what integrations can access to the minimum required for their function
  • Develop incident response relationships with key vendors (pre-established contacts, forensic support agreements)

  • ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Supply Chain Security](https://www.hackwire.news/category/supply-chain-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)