# Icarus Extortion Group Compromises Klue Platform, Stealing Cybersecurity Firms' Sales Data
An emerging threat actor targets major security vendors through a supply chain attack on market intelligence software, exploiting trust in third-party integrations to harvest sensitive business information.
On June 11, 2026, the market intelligence platform Klue became the vector for a sophisticated supply chain attack that compromised the Salesforce instances of multiple cybersecurity firms, including prominent security vendors Huntress and Recorded Future. The incident reveals how attackers continue to exploit the interconnected nature of modern SaaS ecosystems, weaponizing trusted software integrations to gain access to high-value targets without directly attacking their own infrastructure.
## The Threat: OAuth Token Harvesting at Scale
The attack chain began when unauthorized actors gained access to Klue's backend servers and executed malicious commands. Rather than immediately exfiltrating data, the attackers took a calculated approach: they deployed a code update designed to harvest OAuth tokens for customers' Klue integrations across multiple platforms.
This technique is particularly dangerous because OAuth tokens grant delegated access to third-party applications without requiring the underlying user credentials to be exposed. Once obtained, these tokens effectively become skeleton keys to connected accounts.
Between June 11 and June 12, the attackers systematically abused Salesforce REST APIs to extract large volumes of CRM data from compromised Klue customer accounts. According to analysis from ReliaQuest, the exfiltration was both aggressive and sustained:
On June 12, Klue notified its customer base of the incident and immediately deactivated OAuth tokens for all users. The platform disabled integrations with major productivity and business applications, including Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. Five days later, on June 17, Salesforce independently detected unusual activity associated with the Klue Battlecards application integration and moved to revoke the application's access.
## Scope of Impact: Which Companies Were Hit?
Huntress and Recorded Future publicly confirmed their exposure, though the full scope of the supply chain attack likely extends to dozens of other Klue customers.
Huntress disclosed:
Recorded Future disclosed:
Critically, both firms emphasized that the attackers never gained direct access to their own infrastructure. The compromise was strictly limited to data stored within their Salesforce accounts through the Klue integration. This distinction matters: the threat actors did not obtain access to security tools, detection capabilities, threat intelligence, or customer vulnerability data.
However, Huntress noted that "several other cybersecurity companies use Klue," suggesting the real scope of affected organizations may be substantially broader than publicly disclosed. The typical lag between incident discovery and public disclosure—combined with organizational reluctance to disclose customer impact—means the full victim list may not emerge for weeks or months.
## Technical Deep Dive: The Attack Pattern
The Klue compromise follows a well-established playbook that has targeted major SaaS platforms over the past 18 months:
| Date | Platform | Vector | Threat Actor |
|------|----------|--------|--------------|
| 2024-2025 | Salesforce | Compromised integrations | ShinyHunters, UNC6395 |
| 2025 | Salesloft | Unauthorized access | Attributed to ShinyHunters |
| 2025 | Drift | Supply chain attack | UNC6395 |
| 2025 | Gainsight | Compromised API access | ShinyHunters / UNC6395 |
| June 2026 | Klue | Backend access + code deployment | Icarus |
The operational model is consistent: attackers identify a widely-used SaaS platform with broad integrations, compromise its systems, and weaponize the trust relationships it maintains with enterprise customers. Rather than attacking each target independently, a single compromise multiplies impact across dozens or hundreds of organizations using that platform.
What's notable about the Klue incident is the sophistication of the code injection vector. The attackers didn't simply steal API keys from plaintext storage or exploit an obvious vulnerability. They gained sufficient backend access to deploy code updates, suggesting either highly privileged compromised credentials or exploitation of a critical vulnerability in Klue's deployment pipeline.
## Attribution: The Emergence of Icarus
Huntress attributed the attack to Icarus, a newly emerged extortion and data theft group that appeared in April 2026. The attribution is based on multiple data points:
- An older entry from early May containing data allegedly stolen from another victim
- A June 16 entry pointing to Salesforce data matching the timeline and characteristics of the Klue compromise
The emergence of Icarus is significant because it represents a pattern: established extortion groups fragment, rebrand, or cede operations to newcomers as law enforcement pressure increases. Icarus's activity suggests the supply chain attack niche remains profitable and attractive to criminal organizations, despite multiple high-profile takedowns.
Notably, Icarus's leak site shows minimal activity compared to established extortion organizations, with only two disclosed breaches. This may indicate either limited operational capacity or a deliberate strategy of selective data publication to maintain mystique and pressure victims into paying extortion demands.
## Implications: Trust and Supply Chain Risk
This incident underscores several critical vulnerabilities in modern enterprise security architecture:
1. Integration Sprawl Creates Attack Surface
Organizations increasingly depend on dozens of third-party integrations. Each integration represents a potential entry point for attackers. In this case, cybersecurity firms—organizations whose core mission is defending against precisely these kinds of attacks—fell victim to compromise through a trusted vendor.
2. OAuth Token Compromise Is Difficult to Detect
Unlike credential theft or obvious data breaches, OAuth token harvesting can occur silently. Tokens grant delegated access without alerting the target of suspicious authentication. Legitimate API calls using harvested tokens may not trigger alerting systems designed to flag anomalous behavior.
3. Third-Party Incidents Expose First-Party Data
The Klue compromise is a reminder that an organization's security posture depends not just on its own controls, but on the controls maintained by every vendor it integrates with. Huntress and Recorded Future likely have strong security practices, yet their customer data was compromised through a vendor's failure.
## Recommendations: Defending Against Supply Chain Attacks
For Organizations Using Cloud SaaS Platforms:
For SaaS Platform Vendors:
---
## HackWire Analysis
The Klue incident represents a troubling inflection point in supply chain attack evolution. For years, cybersecurity firms have warned their customers about supply chain risk—while simultaneously becoming blind spots in their own security architecture.
That Huntress and Recorded Future were compromised through Klue is not surprising; it's inevitable. These firms spend their days discovering vulnerabilities in other people's software. Yet both fell victim to a compromise they had no direct visibility into, executed by an attacker with no need to breach their perimeter. The irony is not lost.
What's most concerning is what this attack signals about resource allocation in the attacker community. Supply chain attacks require substantial operational sophistication—gaining backend access to a SaaS platform, deploying code updates, exfiltrating data across multiple customer accounts. Yet the payoff is disproportionately large. One compromise unlocks access to dozens or hundreds of organizations, many of them high-value targets.
Icarus's emergence as a serious actor in this space suggests the ROI on supply chain attacks has convinced criminal organizations to invest in the technical capability to execute them. This will likely trigger a copycat wave. Expect to see similar attacks against platform management tools, integration marketplaces, and workflow automation platforms over the next 12 months.
The deeper issue is architectural: the modern SaaS ecosystem is fundamentally built on trust relationships that scale faster than security controls. Klue is likely a competent company with reasonable security practices. But competence is not sufficient when your customers have integrated you into 10+ other platforms, each with its own access to sensitive business data. The aggregate risk exceeds any single organization's ability to manage it.
Until we see structural changes to how OAuth token lifecycle is managed—or until customers become significantly more aggressive about segmenting data access—supply chain attacks will remain a high-return, low-friction attack vector.
— HackWire Editorial
---
## Related Coverage