# Third-Party Integration Nightmare: Klue Breach Exposes Data from 15+ Enterprise Customers Including LastPass and BeyondTrust
A compromised legacy credential gave a threat actor access to Klue's infrastructure, enabling a cascade attack that compromised OAuth tokens and breached Salesforce instances across multiple high-profile cybersecurity and enterprise software companies. Over a dozen organizations have now publicly confirmed exposure.
## The Incident
On June 24, 2026, LastPass became the latest in a growing list of technology firms to disclose unauthorized access to customer data through a breach of Klue, a competitive intelligence platform that integrates with Salesforce and other enterprise tools. The attacker, operating under the alias Icarus, leveraged legacy credentials to infiltrate Klue's systems and then weaponized OAuth tokens to gain unauthorized access to third-party integrations.
The attack chain was methodical and well-executed:
1. Initial Access: Icarus obtained compromised legacy credentials for Klue's infrastructure
2. Token Generation: Once inside Klue, the attacker generated OAuth tokens for integrated third-party platforms
3. Downstream Breach: These tokens were used to breach connected Salesforce instances
4. Data Exfiltration: Automated scripts systematically extracted bulk customer data from the compromised Salesforce environments
Klue integrates with multiple enterprise platforms, making it an effective pivot point for supply chain-style attacks. Rather than targeting each company directly, the attacker compromised a central hub with access to many downstream systems.
## Companies Confirmed Affected
As of mid-June 2026, at least 15 organizations have publicly acknowledged exposure:
| Company | Industry | Data Exposed |
|---------|----------|--------------|
| LastPass | Password Management | CRM data, customer contact info, support case records |
| BeyondTrust | Identity & Access Management | Business contact info, sales data |
| 8×8 | Communications | Business data, customer contact information |
| Pendo | Product Management | Customer and business data |
| HackerOne | Bug Bounty Platform | Business information |
| Huntress | Cybersecurity | Customer data |
| Insurity | Insurance Tech | Business contact information |
| Jamf | Mobile Device Management | Customer contact data |
| OneTrust | Privacy/Compliance | CRM and business data |
| Recorded Future | Threat Intelligence | Business information |
| Snyk | Developer Security | Customer data |
| Sprout Social | Social Media Management | Business data |
| Tanium | Endpoint Management | Customer information |
| Gms-net | Communications Solutions | Salesforce data |
Huntress, among the first to disclose, estimated that the true scope extends to numerous other Klue customers who have not yet publicly acknowledged exposure.
## Technical Details: How the Attack Worked
The Klue incident represents a sophisticated supply chain attack that exploited the trust relationships built into modern SaaS integrations.
### The Attack Chain
Step 1: Legacy Credential Exploitation
The attacker obtained what Klue described as a "compromised legacy credential"—likely a forgotten service account, hardcoded API key, or abandoned administrative password. Legacy credentials are particularly dangerous because they often lack:
Step 2: OAuth Token Generation
Once inside Klue's environment, Icarus had sufficient access to generate OAuth tokens that Klue had previously issued to third-party integrations. OAuth tokens are designed to grant limited, delegated access without exposing the underlying passwords. However, if an attacker controls the system issuing the tokens, they can generate new tokens with broad permissions.
Step 3: Salesforce Instance Compromise
With valid OAuth tokens, the attacker could authenticate to connected Salesforce instances as if they were legitimate Klue API requests. Salesforce would have no way to distinguish legitimate traffic from malicious token usage.
Step 4: Bulk Data Exfiltration
The attacker deployed automated scripts to systematically extract data at scale. This wasn't manual reconnaissance—it was industrial-scale harvesting, suggesting premeditation and technical sophistication.
### Data Accessed
The compromised data was limited to systems integrated through Klue, not to core LastPass, BeyondTrust, or other companies' internal infrastructure. Exposed data included:
Notably, no encryption keys, password vaults, authentication credentials, or customer data stored within core products were compromised. LastPass explicitly confirmed that "customer vaults remain secure" and that "LastPass products, services, and infrastructure were not impacted in any way."
## Response and Containment
### Immediate Actions
Both Salesforce and Gong disabled the Klue integration in response to the incident, cutting off the attack vector. Affected companies took parallel action:
LastPass stated it had "discontinued access to Klue" entirely and worked with both Klue and Salesforce to understand the scope of the breach.
### Third-Party Leak Site
Before going offline, Icarus's Tor-based leak site listed several confirmed victims and at least four additional organizations that had not yet publicly disclosed exposure. Security researchers estimate the true victim count is significantly higher, with many Klue customers still investigating their environments or preparing disclosure notices.
## Implications and Risk Assessment
### For Affected Organizations
The breach underscores a critical risk in modern enterprise software: third-party integrations create implicit trust relationships that can become attack vectors. Organizations using Klue trusted it to:
1. Securely handle OAuth tokens
2. Maintain access controls on integration credentials
3. Log and monitor API activity
4. Alert on anomalous token generation or data access
When Klue failed on these fronts, the downstream organizations bore the consequences despite having no direct control over Klue's infrastructure.
### For the Broader Industry
This incident exemplifies the supply chain attack pattern that has become increasingly common in the SaaS ecosystem:
Each incident demonstrates that an attacker needs only to compromise one vendor to reach hundreds of downstream organizations. The Klue attack was comparatively smaller in scale but follows the same playbook.
### For Data Exposed Organizations
Exposed CRM data and customer contact information are valuable to attackers for:
Unlike password breaches or encryption key theft, CRM exposure doesn't immediately enable unauthorized system access—but it enables *human-targeted attacks* against employees and customers of the affected organizations.
## HackWire Analysis
The Klue incident exposes a structural vulnerability in how modern enterprises approach third-party risk: We've outsourced data security to platforms we don't control, and we're discovering the cost only after the breach.
This isn't Klue's negligence alone. Over the past three years, the SaaS integration ecosystem has exploded. Every Fortune 500 company now runs dozens of vendor integrations—each with OAuth tokens, API keys, and implicit trust. And most organizations still manage these integrations in spreadsheets if they manage them at all.
The "legacy credential" that opened this door wasn't a hypothetical problem. It was an actual, exploitable security debt that accumulated because:
1. Service accounts aren't inventoried systematically. Nobody knows which contractors, former employees, or departed integrations still have active credentials.
2. OAuth tokens are invisible to most enterprises. If Salesforce or Klue isn't actively monitoring token generation, no organization can know if new tokens are being created in their name.
3. Integration risk isn't quantified. A Klue integration looked like a convenient competitive intelligence tool. Few organizations asked: "What happens if Klue gets breached?"
The pattern accelerated after the 3CX and MOVEit incidents proved that supply chain attacks were no longer theoretical. Yet defensive posture hasn't kept pace. Most organizations still treat vendor integrations as fire-and-forget configurations.
Here's what needs to change: Every OAuth integration should require explicit token refresh policies, activity monitoring, and kill-switch controls. If an attacker generates tokens in your name, you should know within minutes, not months. Enterprises need inventory and monitoring for third-party integrations the same way they monitor on-premises Active Directory.
The companies affected here—BeyondTrust, LastPass, Snyk, OneTrust—are all *security vendors*. They understand defense in depth, least-privilege access, and supply chain risk. None of that prevented exposure through a Klue integration. That's the real lesson: even defenders can't protect against risks they've outsourced to platforms they don't run.
— HackWire Editorial
## Recommendations for Organizations
### Immediate Actions (Days 1-7)
### Medium-Term Actions (Weeks 2-8)
### Long-Term Strategic Changes
## Related Coverage