Klue Breach: Stolen OAuth Tokens Expose Customer Salesforce Data
On June 12, market-intelligence platform Klue discovered unauthorized activity in its integration infrastructure. Attackers had used a compromised legacy credential tied to an integration service to obtain OAuth tokens connecting Klue to customers' third-party platforms, chiefly Salesforce.
Organizations named in BleepingComputer's reporting include Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, and Huntress. Stolen data includes business contacts, sales communications, and pricing. The newly surfaced Icarus group claimed the attack; Klue says data stored directly in its own platform shows no evidence of compromise.
The lesson for any AWS-hosted integration hub is the one Snowflake already taught: non-human identities and long-lived integration tokens are the soft perimeter. Inventory them, scope them, and rotate them on a schedule.