# Icarus Extortion Group Expands Salesforce Attack Campaign Via Compromised Klue Integration


Cybersecurity and technology companies continue to disclose breaches following an OAuth token abuse attack that leveraged a compromised third-party Salesforce integration, with the Icarus extortion group claiming responsibility and warning of additional victims to come.


## The Threat


The scope of the Salesforce data theft campaign has grown significantly since Salesforce initially disabled Klue's Battlecards application integration on June 17. What began as a single suspected breach at the market intelligence platform Klue has now revealed itself as a coordinated supply-chain attack affecting dozens of organizations across the cybersecurity, technology, and software vendor industries.


Companies confirmed as victims include:

  • Huntress (cybersecurity vendor)
  • LastPass (password manager)
  • HackerOne (bug bounty platform)
  • Recorded Future (threat intelligence)
  • Jamf (device management)
  • Snyk (developer security)
  • OneTrust (privacy and governance)
  • Insurity (insurance software)
  • Tanium (endpoint management)
  • Sprout Social (social media management)
  • Gong (conversation intelligence platform)

  • The extortion group Icarus has claimed credit for the attacks and indicated via dark web forums that additional victims are expected to emerge in the coming days. This public messaging pattern—common among extortion-focused threat actors—suggests either data exfiltration has already occurred and will be monetized, or that the group is attempting to pressure additional organizations into disclosure or negotiation.


    ## Background and Context


    The attack chain reveals a classic supply-chain compromise pattern: attackers breached Klue, a SaaS platform that provides competitive battlecards and market intelligence to enterprise clients. Once inside Klue's infrastructure, threat actors obtained OAuth tokens that Klue had provisioned to integrate with customers' Salesforce instances. These tokens functioned as keys to the kingdom—allowing attackers to authenticate directly to customer Salesforce environments without needing to crack passwords or bypass multi-factor authentication.


    Klue integrations typically connect to Salesforce CRM instances where sensitive business data resides: customer lists, deal pipelines, internal communications, and in some cases, API keys and authentication credentials. By leveraging stolen OAuth tokens, attackers gained legitimate-looking access to these systems, making detection significantly more difficult than a traditional break-in attempt.


    Timeline of disclosure:

  • June 17: Salesforce discovered the breach and disabled Klue's OAuth integrations
  • June 17: Huntress publicly disclosed compromise of its Salesforce instance
  • June 22: LastPass confirmed Salesforce data compromise via blog post
  • June 21-23: Additional companies issued disclosure statements
  • June 21: Gong disclosed that attackers accessed internal licensed user data for affected customers

  • ## Technical Details


    The mechanics of the attack underscore a critical vulnerability in the OAuth integration model: over-privileged access tokens.


    When Klue customers integrated the Battlecards application with Salesforce, they authorized Klue to access their Salesforce instances on their behalf. In most enterprise OAuth implementations, the permissions granted to third-party applications are broad—designed for convenience rather than the principle of least privilege. This meant Klue's OAuth tokens likely had access to:


  • Customer records and contact information
  • Sales opportunities and deal data
  • Internal communications and notes
  • Custom fields and business logic
  • Potentially API keys stored within Salesforce

  • Once attackers obtained these tokens from Klue's infrastructure, they could authenticate to Salesforce without triggering typical breach indicators. From Salesforce's perspective, requests bearing Klue's OAuth tokens appeared legitimate—coming from an authorized integration that the customer had voluntarily enabled.


    Secondary impact on Gong:

    Gong's disclosure that attackers accessed "internal licensed user data" for a subset of customers demonstrates that compromised OAuth tokens in one system can cascade across an ecosystem. Customers who had integrated both Klue and Gong with Salesforce faced dual exposure: not only was their Salesforce data at risk, but so was their Gong usage data (usernames, business titles, email addresses).


    Importantly, LastPass emphasized that while Salesforce data was compromised, customer password vaults remained unaffected, and there was "no evidence the threat actor accessed any Gong-related data." This distinction—between corporate systems (Salesforce) and core product infrastructure—is critical for understanding the breach's actual impact versus theoretical risk.


    ## Implications


    This incident exposes fundamental vulnerabilities in how enterprise SaaS platforms manage integrations and access controls:


    ### OAuth Token Hygiene

    Organizations and integration vendors have been slow to adopt OAuth token rotation, expiration windows, and scoped permissions. Many third-party apps request overly broad access permissions during initial setup, then retain those tokens indefinitely. If a vendor is breached, every customer using that integration becomes instantly vulnerable.


    ### Supply Chain Concentration Risk

    By integrating with Klue, dozens of technology and cybersecurity companies created a single point of failure. A breach at one vendor cascaded to compromise dozens of customers simultaneously. This is particularly concerning for cybersecurity vendors and financial firms, where the reputational damage and regulatory scrutiny can be severe.


    ### Detection Gaps

    OAuth-based attacks are notoriously difficult to detect. Unlike brute-force attempts or SQL injection attacks that generate suspicious log patterns, legitimate OAuth tokens generate legitimate-looking authentication events. Organizations cannot simply look for "failed login attempts"—the attacker's requests appear to succeed.


    ### Regulatory and Compliance Implications

    Companies affected by this incident face disclosure obligations under GDPR, CCPA, and various industry-specific regulations. For public companies, this may require SEC notification. The fact that OAuth token abuse was used—rather than a traditional breach—does not reduce regulatory obligations, even if customer data in products remained unaffected.


    ## Recommendations


    Organizations should implement multiple layers of defense:


    Immediate Actions:

  • Audit all active third-party OAuth integrations and their permission scopes
  • Revoke and re-issue OAuth tokens for any vendors with known breaches
  • Review Salesforce audit logs for unauthorized data access between June 10-20
  • Implement rate limiting on OAuth token usage

  • Medium-term Controls:

  • Enforce OAuth token rotation policies (tokens should expire every 30-90 days)
  • Implement least-privilege access—audit what permissions third-party apps actually need versus what was granted
  • Enable detailed audit logging and behavioral analytics to detect anomalous Salesforce access patterns
  • Segment OAuth tokens by functional scope (sales operations, customer success, finance) rather than granting blanket access

  • Strategic Changes:

  • Treat third-party integrations as security perimeter—apply the same scrutiny as direct vendor access
  • Require vendors to sign security agreements specifying OAuth token handling practices
  • Implement zero-trust principles for SaaS integrations: verify and validate every token request
  • Maintain an inventory of critical data stores and which integrations access them

  • ## HackWire Analysis


    This incident represents a worrying maturation of supply-chain attack tactics. Rather than targeting infrastructure providers or development tools (the typical SaaS security headlines), Icarus identified that business integration platforms—Klue, in this case—represent a higher-value target. Klue's customer base skews toward technology and cybersecurity companies, which means compromised data carries higher intelligence value and potentially stronger extortion leverage.


    What's particularly concerning is the ease of execution. Once Klue was breached, attackers didn't need to conduct complex lateral movement or privilege escalation within customer environments. OAuth tokens did the heavy lifting. This suggests that defenders are losing a critical battle: the assumption that a third-party SaaS vendor's authorization is trustworthy has become a liability rather than a security control.


    The pattern here—vendor breach → customer exposure cascades—will likely accelerate as more organizations rely on ecosystem integrations. We've seen this before (3CX, SolarWinds), but OAuth-based attacks scale even more efficiently than code injection supply-chain attacks because there's no need to compromise code or updates. Just steal the keys.


    For organizations reviewing this incident: the hard truth is that you cannot fully control vendor security. What you can control is how much access you grant and how quickly you can revoke it. Companies that granted Klue access to their entire Salesforce instance learned this lesson expensively. Those that had scoped permissions to specific objects or fields had significantly reduced blast radius.


    The Icarus group's public messaging about "more victims to come" should be taken seriously as both threat and opportunity: threat because disclosure cascades are coming, opportunity because organizations have a narrow window to audit their OAuth integrations before the next wave hits.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)