# Klue OAuth Breach Enables "Icarus" Extortion Gang to Steal Salesforce Data From Enterprise Customers


Market intelligence platform Klue suffered a significant OAuth credential breach that allowed a relatively new extortion group called "Icarus" to steal Salesforce CRM data from multiple enterprise organizations. The incident marks an escalation in third-party application-based attacks targeting sensitive business intelligence and customer relationship data, with affected companies now receiving extortion demands for the stolen information.


Salesforce has already moved to contain the breach by disabling the Klue Battlecards integration across its platform, preventing further unauthorized access through the compromised connection. Security researchers at ReliaQuest and Huntress, both impacted by the incident, have published detailed technical analysis of the attack methodology.


## The Threat: OAuth Tokens Used for Mass Data Exfiltration


The attack centered on compromised OAuth credentials associated with Klue's Battlecards integration service accounts. Rather than targeting Klue's infrastructure directly, attackers gained access to stored OAuth tokens that granted them legitimate-appearing access to customer Salesforce instances.


Once armed with these tokens, the threat actors deployed automated Python scripts to systematically query Salesforce's REST API and exfiltrate customer data over nearly 24-hour periods. The attacks occurred across multiple customer environments simultaneously, suggesting a coordinated, large-scale campaign.


Salesforce immediately responded to the security incident by issuing a warning to its customer base:


> "To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident. As a result, organizations will not be able to connect to Salesforce via this app until further notice."


The threat actors behind the campaign, operating under the name "Icarus," have already begun sending extortion emails to affected organizations demanding payment for the stolen data. Security researchers confirmed that Icarus is a previously unknown extortion group believed to have launched operations in April 2026.


## Background and Context: Third-Party Integration Risks


The Klue Platform and Its Integration


Klue is a market intelligence and competitive intelligence platform widely used by enterprise sales and marketing teams. The Battlecards feature integrates directly with Salesforce CRM, allowing organizations to sync competitive intelligence data and insights directly into their sales workflows. This deep integration requires OAuth authentication, granting the application broad access to Salesforce data objects.


OAuth as an Attack Vector


OAuth tokens represent a persistent vulnerability in third-party integration ecosystems. Unlike passwords, which users might rotate, OAuth tokens often remain valid for extended periods and are frequently stored in application databases. Compromise of these credentials grants attackers:


  • Persistent access without requiring ongoing credential management
  • Legitimacy — API calls appear to come from authorized applications
  • Stealth — activity blends in with normal application usage patterns
  • Scale — single compromised service account can affect hundreds of customer organizations

  • Historical Precedent


    The attack methodology closely resembled previous data theft campaigns attributed to ShinyHunters, an extortion group known for targeting Salesforce through compromised third-party integrations. However, security researchers confirmed this campaign was executed by the separate, newly emerged Icarus group, marking a significant rise in attacks exploiting third-party OAuth vulnerabilities.


    ## Technical Details: The Attack Process


    ### Reconnaissance and Mapping Phase


    ReliaQuest's analysis revealed a methodical two-stage attack process. During the initial reconnaissance phase, attackers probed victim Salesforce instances using the /services/data/v59.0/sobjects endpoint to enumerate available data objects:


  • Standard objects (Accounts, Contacts, Opportunities, Leads)
  • Custom objects specific to each organization
  • Field structures and relationships
  • Data volume and content preview

  • This reconnaissance phase deliberately moved slowly and cautiously, designed to blend in with normal Battlecards application usage and avoid triggering security alerts.


    ### High-Speed Exfiltration Phase


    Once attackers identified valuable targets, they switched tactics dramatically. In one documented case, they executed approximately 1,000 API queries against the same endpoint within a 15-minute window—a burst of activity that prioritized speed over stealth.


    The attack progression shows clear intentionality:


    | Attack Phase | Duration | Query Volume | Purpose |

    |---|---|---|---|

    | Reconnaissance | 2-6 hours | Moderate (slow, steady) | Map Salesforce objects and identify valuable data |

    | Mapping | 6-12 hours | Gradual increase | Identify high-value records and relationships |

    | Exfiltration | 15 minutes to 6 hours | High (1000+ queries) | Rapid theft of identified datasets |


    The shift from cautious reconnaissance to aggressive exfiltration suggests either time pressure or a calculated pivot—attackers may have detected defensive monitoring and accelerated their timeline.


    ### Specific API Abuse


    Attackers leveraged Salesforce REST API endpoints designed for legitimate data access:


  • /services/data/v59.0/sobjects — enumerate available objects
  • /services/data/v59.0/query — execute SOQL queries to extract data

  • These endpoints are designed to be accessible to integrated applications, making detection particularly challenging when called through legitimate OAuth tokens.


    ## Implications: Enterprise Data Exposure and Extortion Risk


    ### Who Was Affected


    Organizations impacted span multiple industries and sectors relying on Salesforce CRM combined with competitive intelligence:


  • Sales-driven organizations with large opportunity pipelines
  • Competitive intelligence teams with proprietary market analysis
  • Enterprise software vendors with customer account data
  • Financial services firms with deal information and client details

  • Confirmed victims include ReliaQuest and Huntress, both major cybersecurity firms, indicating that sophisticated security organizations were successfully targeted.


    ### What Data Was Exposed


    Typical Salesforce exfiltration compromises:


  • Account and contact records — customer names, roles, contact information
  • Opportunity data — deal values, pipeline stage, probability assessments
  • Competitive intelligence — customer win/loss analysis, competitive positioning
  • Financial information — contract values, renewal dates, pricing
  • Custom fields — proprietary data specific to each organization

  • ### The Extortion Campaign


    Icarus has already begun contacting affected organizations with ransom demands via Session Messenger, a privacy-focused chat platform. The ransom note discovered by BleepingComputer used the alias "mr bean" and provided a Session ID for negotiations. Icarus's data leak site displayed a provocative message: "Get Ready — big corps getting listed. be ready."


    This messaging suggests a coordinated extortion campaign targeting multiple enterprises simultaneously, potentially with the intent to:


  • Maximize pressure by threatening public disclosure
  • Leverage competitive sensitivity of market intelligence
  • Create urgency through group extortion tactics

  • ## Recommendations: Detection, Response, and Prevention


    ### Immediate Actions (0-48 Hours)


    For organizations using Klue Battlecards:


  • Revoke OAuth tokens associated with the Klue integration immediately
  • Review Salesforce API logs for unauthorized queries between June 17-18, 2026
  • Check for extortion emails and monitor Session Messenger for contact attempts
  • Notify legal and incident response teams to prepare for extortion demands
  • Contact Klue support to understand the breach scope and timeline

  • For all Salesforce administrators:


  • Audit connected applications in Setup → Apps → Connected Apps
  • Review API usage logs for unusual query patterns or unfamiliar applications
  • Enable login history monitoring to detect unauthorized sessions
  • Implement IP restrictions on service accounts where possible

  • ### Short-Term Actions (1-2 Weeks)


  • Conduct a forensic investigation to determine what specific data was stolen
  • Notify affected customers or prospects if their data was exposed
  • Review backup and recovery procedures to ensure data integrity
  • Implement OAuth token rotation policies (shorter expiration windows)
  • Document incident details for regulatory reporting (GDPR, state laws, etc.)

  • ### Long-Term Prevention Strategy


    | Control | Objective |

    |---|---|

    | OAuth token rotation | Expire and refresh tokens every 30-90 days |

    | Salesforce IP allowlisting | Restrict API calls to known application IPs |

    | Custom object access controls | Limit third-party app access to necessary objects only |

    | API query logging and alerting | Flag bulk queries and unusual data access patterns |

    | Zero-trust verification | Require additional authentication for sensitive data access |

    | Third-party integration audits | Quarterly review of connected applications and permissions |


    ## HackWire Analysis


    This incident exposes a fundamental weakness in how enterprises manage third-party application access: OAuth tokens have become the new keys to the kingdom, yet many organizations treat them as "set and forget" credentials. Klue wasn't hacked through advanced persistence or zero-day exploitation—attackers simply compromised stored OAuth credentials and then methodically looted data through legitimate API calls that appeared normal to both Salesforce and the organization's security team.


    What's particularly concerning is the pattern: this follows ShinyHunters' playbook almost exactly, suggesting we're entering an era where extortion groups commodify third-party integration attack methods. Icarus appears to be an emerging player rapidly scaling this attack vector. The fact that security firms like Huntress and ReliaQuest were targeted suggests no organization is exempt—having strong security teams internally doesn't protect you from compromised credentials flowing through trusted applications.


    The timing also matters. Klue's user base skews heavily toward enterprise sales and marketing organizations during an economic period when deal pipelines are critical. Stolen opportunity data creates dual pressure: organizations fear both public disclosure embarrassing their sales motions and competitors gaining intelligence about their pipeline. This makes them prime extortion victims.


    Defenders need to treat OAuth tokens with the same rigor as privileged credentials: rotation, monitoring, IP restrictions, and least-privilege access. If your organization uses any Salesforce integration with OAuth access to customer data, assume those tokens are a target and act accordingly.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)