DEFENCE / RADAR

Public snapshot

Klue·Technology / SaaS·

Attackers used the data to extort companies.

Klue confirmed a breach involving legacy credentials, stolen OAuth tokens, customer data exfiltration, and an Icarus extortion claim. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Reported incident date
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: A previously compromised GitHub personal access token was used to introduce unauthorized code
Consequence
Reported: Attackers used the data to extort companies.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Klue
Industry
Technology / SaaS
Disclosed
Event date
Affected asset
Klue integration infrastructure
Product / vendor
Salesforce
Data involved
Authentication tokens · Business Confidential
Reported impact
Extortion demand
Attached evidence
6 independent domains · 8 sources

2)Evidence-backed incident path

  1. 01

    Reported cause

    A previously compromised GitHub personal access token was used to introduce unauthorized code

    ConfidenceSecondary
    Exact excerpt

    a Threat Actor leveraged a previously compromised GitHub personal access token (PAT) to introduce unauthorized code

    klue.com · Jul 02
    E1
  2. 02

    Affected product

    Salesforce

    ConfidenceSecondary
    Exact excerpt

    OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce

    klue.com · Jun 19
    E2
  3. 03

    Reached

    Klue integration infrastructure

    ConfidenceSecondary
    Exact excerpt

    unauthorized activity affecting a portion of Klue’s integration infrastructure

    klue.com · Jun 19
    E3
  4. 04

    Observed

    Attackers used the data to extort companies.

    ConfidenceProbable
    Exact excerpt

    download that data, and extort the companies

    techcrunch.com · Jun 23
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • Whether any ransom or extortion payment was made
  • That a Defence review would have prevented this incident

4)Relevance to your product

One durable credential can carry yesterday's access into today's product.

This pattern applies when…

  • Products that connect to Salesforce or similar third-party platforms using OAuth tokens.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Technology / SaaS

130 incident threads in the 365-day public record
  1. 2 incident threads
  2. 1 incident threads
  3. 5 incident threads
  4. 2 incident threads
  5. 13 incident threads
  6. 5 incident threads
  7. 18 incident threads
  8. 16 incident threads
  9. 16 incident threads
  10. 16 incident threads
  11. 7 incident threads
  12. 29 incident threads
Same incident family
56
Supply chain / third party
Confirmed share
40%
52 confirmed · 78 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Technology / SaaS in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

Also relevant: Secret exposure testing · Dependency and SBOM control area

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

8 attached sources across 6 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E4
    techcrunch.comKlue says hackers stole credential from 2022 that led to customer data breaches | TechCrunchEstablished press · Jun 23 · Cited
    Established pressCited
    Exact excerpt
    data from its corporate customers
  2. E1
    klue.comCrowdStrike Investigation Summary and Security Improvements - KlueOther public report · Jul 02 · Cited
    Other public reportCited
    Exact excerpt
    collect third-party integration credentials including OAuth access and refresh tokens for Salesforce
  3. E2, E3
    klue.comAn Update on the Recent Klue Security Incident - KlueOther public report · Jun 19 · Cited
    Other public reportCited
    Exact excerpt
    subsequently accessed data within a number of connected customer environments
  4. S4
    thehackernews.comSalesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer DataSpecialist reporting · Jun 19 · Attached
    Specialist reportingAttached
  5. S5
    thecybersecguru.comKlue Salesforce Breach Explained: Icarus OAuth Attack | The CyberSec GuruOther public report · Jun 20 · Attached
    Other public reportAttached
  6. S6
    techcrunch.comKlue hack results in data breach at several cybersecurity firms | TechCrunchEstablished press · Jun 22 · Attached
    Established pressAttached
Show all 8 sourcesShow the first six sources
  1. S7
    cybersecuritydive.comKlue investigating supply chain attack that targeted Salesforce integrations | Cybersecurity DiveSpecialist reporting · Jun 23 · Attached
    Specialist reportingAttached
  2. S8
    securityweek.comMore Klue Breach Victims Identified as Hackers Get Hacked - SecurityWeekEstablished press · Jun 26 · Attached
    Established pressAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →