Klue OAuth Breach Linked To Icarus Salesforce Thefts
Klue's OAuth token leak gave attackers a direct path into multiple companies' Salesforce instances.
Icarus used the stolen tokens to pull customer and sales records from several organizations over recent weeks. The group then started an extortion campaign demanding payment to keep the data private.
Klue spotted unusual outbound connections to a remote server around June 12 and alerted customers itself, before the extortion emails went out. The incident shows how a single third-party access point can open doors across unrelated environments.
Icarus is a new group (surfaced April 2026). The OAuth-token playbook mirrors the earlier Salesloft Drift and Gainsight thefts, but those were pinned on other actors, not Icarus.
