# Klue Breach Exposes Salesforce Customers: Third Major Third-Party App Compromise in Two Years


Salesforce customers face yet another data theft through a compromised third-party application integration. On June 17, Salesforce announced it had suspended the Klue Battlecards app following detection of unauthorized access to customer data. The breach marks the third major OAuth-based compromise targeting Salesforce ecosystems in recent years—a pattern that exposes fundamental vulnerabilities in how enterprises vet and monitor software-as-a-service integrations.


## The Threat


Threat actors successfully compromised Klue's Battlecards application, a competitive intelligence tool integrated with Salesforce, and leveraged the access to steal customer data from multiple organizations. Security researchers at ReliaQuest, who investigated the incident, confirmed that attackers used compromised OAuth tokens to authenticate directly to customers' Salesforce instances without triggering typical warning signs.


The attack was swift and aggressive. Over approximately 24 hours, threat actors automated data exfiltration using Python scripts that queried the Salesforce REST API. At one point, they executed nearly 1,000 API queries in just 15 minutes—a concentrated burst designed to grab as much data as possible before detection. The attackers sustained exfiltration for more than six hours, alternating between slower, stealthy pulls intended to blend into normal traffic and aggressive bulk extraction.


Among the confirmed victims was Huntress, a prominent cybersecurity vendor and managed detection and response (MDR) provider. The irony is stark: a security company designed to protect others fell victim to the same third-party compromise vector affecting thousands of other Salesforce customers.


## Background and Context


The Klue compromise is neither isolated nor novel—it represents the third major Salesforce data theft via compromised third-party app integrations in less than two years. The pattern began with Salesloft in 2025, followed by compromises involving Drift and Gainsight throughout 2025 and into 2026. Each incident followed the same playbook: threat actors targeted the third-party app, obtained OAuth credentials, and used them to access customer Salesforce instances.


This repeated pattern suggests a coordinated threat actor or group that has refined a reliable attack methodology against a high-value target surface. Salesforce's ecosystem of integrations is enormous—thousands of applications connect to Salesforce instances globally, and most customers trust "approved" integrations without continuous monitoring.


### Why Third-Party Integrations Matter


Salesforce doesn't operate in isolation. Customers deploy dozens of integrated applications—marketing automation tools, sales enablement platforms, analytics engines, and competitive intelligence systems. Each integration requires OAuth permissions to access specific Salesforce data. While OAuth is designed to be secure, it creates a trust boundary: customers implicitly trust that third-party applications will protect their credentials and not be compromised.


The repeated breaches suggest that this trust assumption is breaking down.


## Technical Details


Understanding how these attacks work is critical for defenders:


1. OAuth Token Compromise

Threat actors gained access to Klue's infrastructure and obtained OAuth tokens belonging to service accounts. These tokens functioned as legitimate credentials that could authenticate to customers' Salesforce instances. Unlike stolen user credentials, service account tokens often have broad permissions and may not trigger multi-factor authentication alerts.


2. API Exploitation

Once authenticated, attackers used the Salesforce REST API to query and exfiltrate data. The REST API is designed for legitimate integrations, meaning the traffic appeared normal from Salesforce's perspective. There was no brute-force attempt, no unusual login location, or other typical breach indicators—just authenticated API calls consuming data.


3. Exfiltration Strategy

Attackers employed a two-phase approach:

  • Phase 1 (Slow Pull): Initial queries executed slowly and incrementally, designed to evade detection by mimicking normal integration behavior
  • Phase 2 (Aggressive Extraction): Once confident they had undetected access, attackers executed bulk queries—nearly 1,000 in 15 minutes—to grab remaining data before discovery

  • 4. Detection Challenges

    Many organizations don't actively monitor third-party app API usage. Salesforce logs show millions of API calls daily; distinguishing malicious extraction from legitimate integration traffic requires baseline behavioral analysis that most customers lack.


    ## Who Was Affected


    While specific customer counts haven't been fully disclosed, the compromise affected an unknown number of Salesforce organizations across multiple industries. Confirmed victims include Huntress, but ReliaQuest's research suggests the breach was far broader.


    Data stolen likely included:

  • Customer contact information (names, emails, phone numbers)
  • Sales pipeline data (opportunity amounts, deal stages, customer names)
  • Account information (company names, industry, revenue)
  • Custom fields (organization-specific sensitive data)

  • The nature of Battlecards—a tool designed to surface competitive intelligence—means attackers may have gained insight into customers' sales strategies, target accounts, and deal intelligence.


    ## Implications


    This breach carries multiple consequences:


    ### For Salesforce Customers

    Organizations must now audit their integrated applications and implement stricter monitoring of third-party API activity. The assumption that "Salesforce-approved" means "safe" is no longer valid. Customers need visibility into what data each integration accesses and continuous monitoring for abnormal extraction patterns.


    ### For Salesforce as a Platform

    Three major third-party compromises in two years raise questions about Salesforce's vetting process for integrated applications and its visibility into partner security practices. While Salesforce correctly notes that these breaches don't result from platform vulnerabilities, the ecosystem's trust model is demonstrably weak.


    ### For Third-Party Vendors

    Developers whose applications integrate with Salesforce now face heightened scrutiny. A single compromise can affect thousands of downstream customers. Security standards for OAuth token management, infrastructure hardening, and incident response must meet enterprise-grade requirements—not startup norms.


    ### Business Risk

    Data theft from Salesforce instances can directly impact:

  • Competitive Intelligence: Stolen deal data and customer information
  • Regulatory Compliance: Many industries (healthcare, finance) face penalties for data exposure
  • Customer Trust: Customers learn that their vendor was breached
  • Operational Continuity: Incident response and remediation consume weeks of effort

  • ## Recommendations


    Organizations using Salesforce should take immediate action:


    Immediate (This Week):

  • Audit all connected third-party applications and their OAuth permissions
  • Revoke OAuth tokens for unused integrations
  • Review API audit logs for unusual exfiltration patterns (large result sets, unusual times, service accounts)

  • Short-Term (This Month):

  • Implement role-based access controls (RBAC) to limit what each integration can access
  • Enable session timeout policies on OAuth tokens
  • Establish baseline metrics for API activity by integration
  • Deploy alerts for anomalous query patterns (burst activity, bulk extraction)

  • Medium-Term (Next Quarter):

  • Conduct security assessments of critical third-party applications
  • Require third-party vendors to provide SOC 2 Type II reports
  • Implement API rate limiting and anomaly detection tools
  • Establish a SaaS security governance program

  • ## HackWire Analysis


    The pattern of repeated third-party compromises targeting Salesforce reveals a critical gap between enterprise security assumptions and reality. Companies treat Salesforce-integrated applications as "trusted" largely by virtue of being listed in an app marketplace—a vetting process that, as three major breaches now demonstrate, provides false confidence.


    What's particularly damaging is that this isn't a Salesforce platform vulnerability requiring technical sophistication to exploit. Threat actors aren't finding zero-days or bypassing platform security. They're compromising relatively simple targets—third-party SaaS vendors with far fewer security resources than Salesforce itself—and using legitimately-granted OAuth tokens to steal data. This is a human and organizational security failure, not a technical one.


    The fact that Huntress was among the victims is instructive. Huntress is a security-focused company with expertise in threat detection. If they didn't detect a data exfiltration happening through their own Salesforce instance, the average enterprise customer certainly won't. This suggests that Salesforce's API audit logs and alerting capabilities may be insufficient for detecting this class of attack, or that customers simply lack the operational capacity to monitor them effectively.


    The real vulnerability is the trust boundary between Salesforce and its third-party ecosystem. Every integrated app becomes a potential attack vector. Until Salesforce implements mandatory continuous security assessment of partners, mandatory incident notification, and better API activity monitoring with anomaly detection built into the platform, we should expect this pattern to continue. The third-party OAuth playbook is now proven, reliable, and highly profitable for threat actors—expect more variants.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)