# Klue Breach Exposes Salesforce Customers: Third Major Third-Party App Compromise in Two Years
Salesforce customers face yet another data theft through a compromised third-party application integration. On June 17, Salesforce announced it had suspended the Klue Battlecards app following detection of unauthorized access to customer data. The breach marks the third major OAuth-based compromise targeting Salesforce ecosystems in recent years—a pattern that exposes fundamental vulnerabilities in how enterprises vet and monitor software-as-a-service integrations.
## The Threat
Threat actors successfully compromised Klue's Battlecards application, a competitive intelligence tool integrated with Salesforce, and leveraged the access to steal customer data from multiple organizations. Security researchers at ReliaQuest, who investigated the incident, confirmed that attackers used compromised OAuth tokens to authenticate directly to customers' Salesforce instances without triggering typical warning signs.
The attack was swift and aggressive. Over approximately 24 hours, threat actors automated data exfiltration using Python scripts that queried the Salesforce REST API. At one point, they executed nearly 1,000 API queries in just 15 minutes—a concentrated burst designed to grab as much data as possible before detection. The attackers sustained exfiltration for more than six hours, alternating between slower, stealthy pulls intended to blend into normal traffic and aggressive bulk extraction.
Among the confirmed victims was Huntress, a prominent cybersecurity vendor and managed detection and response (MDR) provider. The irony is stark: a security company designed to protect others fell victim to the same third-party compromise vector affecting thousands of other Salesforce customers.
## Background and Context
The Klue compromise is neither isolated nor novel—it represents the third major Salesforce data theft via compromised third-party app integrations in less than two years. The pattern began with Salesloft in 2025, followed by compromises involving Drift and Gainsight throughout 2025 and into 2026. Each incident followed the same playbook: threat actors targeted the third-party app, obtained OAuth credentials, and used them to access customer Salesforce instances.
This repeated pattern suggests a coordinated threat actor or group that has refined a reliable attack methodology against a high-value target surface. Salesforce's ecosystem of integrations is enormous—thousands of applications connect to Salesforce instances globally, and most customers trust "approved" integrations without continuous monitoring.
### Why Third-Party Integrations Matter
Salesforce doesn't operate in isolation. Customers deploy dozens of integrated applications—marketing automation tools, sales enablement platforms, analytics engines, and competitive intelligence systems. Each integration requires OAuth permissions to access specific Salesforce data. While OAuth is designed to be secure, it creates a trust boundary: customers implicitly trust that third-party applications will protect their credentials and not be compromised.
The repeated breaches suggest that this trust assumption is breaking down.
## Technical Details
Understanding how these attacks work is critical for defenders:
1. OAuth Token Compromise
Threat actors gained access to Klue's infrastructure and obtained OAuth tokens belonging to service accounts. These tokens functioned as legitimate credentials that could authenticate to customers' Salesforce instances. Unlike stolen user credentials, service account tokens often have broad permissions and may not trigger multi-factor authentication alerts.
2. API Exploitation
Once authenticated, attackers used the Salesforce REST API to query and exfiltrate data. The REST API is designed for legitimate integrations, meaning the traffic appeared normal from Salesforce's perspective. There was no brute-force attempt, no unusual login location, or other typical breach indicators—just authenticated API calls consuming data.
3. Exfiltration Strategy
Attackers employed a two-phase approach:
4. Detection Challenges
Many organizations don't actively monitor third-party app API usage. Salesforce logs show millions of API calls daily; distinguishing malicious extraction from legitimate integration traffic requires baseline behavioral analysis that most customers lack.
## Who Was Affected
While specific customer counts haven't been fully disclosed, the compromise affected an unknown number of Salesforce organizations across multiple industries. Confirmed victims include Huntress, but ReliaQuest's research suggests the breach was far broader.
Data stolen likely included:
The nature of Battlecards—a tool designed to surface competitive intelligence—means attackers may have gained insight into customers' sales strategies, target accounts, and deal intelligence.
## Implications
This breach carries multiple consequences:
### For Salesforce Customers
Organizations must now audit their integrated applications and implement stricter monitoring of third-party API activity. The assumption that "Salesforce-approved" means "safe" is no longer valid. Customers need visibility into what data each integration accesses and continuous monitoring for abnormal extraction patterns.
### For Salesforce as a Platform
Three major third-party compromises in two years raise questions about Salesforce's vetting process for integrated applications and its visibility into partner security practices. While Salesforce correctly notes that these breaches don't result from platform vulnerabilities, the ecosystem's trust model is demonstrably weak.
### For Third-Party Vendors
Developers whose applications integrate with Salesforce now face heightened scrutiny. A single compromise can affect thousands of downstream customers. Security standards for OAuth token management, infrastructure hardening, and incident response must meet enterprise-grade requirements—not startup norms.
### Business Risk
Data theft from Salesforce instances can directly impact:
## Recommendations
Organizations using Salesforce should take immediate action:
Immediate (This Week):
Short-Term (This Month):
Medium-Term (Next Quarter):
## HackWire Analysis
The pattern of repeated third-party compromises targeting Salesforce reveals a critical gap between enterprise security assumptions and reality. Companies treat Salesforce-integrated applications as "trusted" largely by virtue of being listed in an app marketplace—a vetting process that, as three major breaches now demonstrate, provides false confidence.
What's particularly damaging is that this isn't a Salesforce platform vulnerability requiring technical sophistication to exploit. Threat actors aren't finding zero-days or bypassing platform security. They're compromising relatively simple targets—third-party SaaS vendors with far fewer security resources than Salesforce itself—and using legitimately-granted OAuth tokens to steal data. This is a human and organizational security failure, not a technical one.
The fact that Huntress was among the victims is instructive. Huntress is a security-focused company with expertise in threat detection. If they didn't detect a data exfiltration happening through their own Salesforce instance, the average enterprise customer certainly won't. This suggests that Salesforce's API audit logs and alerting capabilities may be insufficient for detecting this class of attack, or that customers simply lack the operational capacity to monitor them effectively.
The real vulnerability is the trust boundary between Salesforce and its third-party ecosystem. Every integrated app becomes a potential attack vector. Until Salesforce implements mandatory continuous security assessment of partners, mandatory incident notification, and better API activity monitoring with anomaly detection built into the platform, we should expect this pattern to continue. The third-party OAuth playbook is now proven, reliable, and highly profitable for threat actors—expect more variants.
— HackWire Editorial
## Related Coverage