Klue·Technology / SaaS·
Attackers used the data to extort companies.
Klue confirmed a breach involving legacy credentials, stolen OAuth tokens, customer data exfiltration, and an Icarus extortion claim. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Reported incident date
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: A previously compromised GitHub personal access token was used to introduce unauthorized code
- Consequence
- Reported: Attackers used the data to extort companies.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Klue
- Industry
- Technology / SaaS
- Disclosed
- Event date
- Affected asset
- Klue integration infrastructure
- Product / vendor
- Salesforce
- Data involved
- Authentication tokens · Business Confidential
- Reported impact
- Extortion demand
- Attached evidence
- 6 independent domains · 8 sources
2)Evidence-backed incident path
- 01
Reported cause
A previously compromised GitHub personal access token was used to introduce unauthorized code
ConfidenceSecondaryExact excerpt
E1“a Threat Actor leveraged a previously compromised GitHub personal access token (PAT) to introduce unauthorized code”
klue.com · Jul 02 - 02
Affected product
Salesforce
ConfidenceSecondaryExact excerpt
E2“OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce”
klue.com · Jun 19 - 03
Reached
Klue integration infrastructure
ConfidenceSecondaryExact excerpt
E3“unauthorized activity affecting a portion of Klue’s integration infrastructure”
klue.com · Jun 19 - 04
Observed
Attackers used the data to extort companies.
ConfidenceProbableExact excerpt
E4“download that data, and extort the companies”
techcrunch.com · Jun 23
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- Whether any ransom or extortion payment was made
- That a Defence review would have prevented this incident
4)Relevance to your product
One durable credential can carry yesterday's access into today's product.
This pattern applies when…
- Products that connect to Salesforce or similar third-party platforms using OAuth tokens.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Technology / SaaS
- 2 incident threads
- 1 incident threads
- 5 incident threads
- 2 incident threads
- 13 incident threads
- 5 incident threads
- 18 incident threads
- 16 incident threads
- 16 incident threads
- 16 incident threads
- 7 incident threads
- 29 incident threads
- Same incident family
- 56 Supply chain / third party
- Confirmed share
- 40% 52 confirmed · 78 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Technology / SaaS in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
Also relevant: Secret exposure testing · Dependency and SBOM control area
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
8 attached sources across 6 independent domains. No attached source is marked as an organization or regulator primary source.
- E4techcrunch.comKlue says hackers stole credential from 2022 that led to customer data breaches | TechCrunchEstablished press · Jun 23 · CitedEstablished pressCited
Exact excerpt
“data from its corporate customers”
- E1klue.comCrowdStrike Investigation Summary and Security Improvements - KlueOther public report · Jul 02 · CitedOther public reportCited
Exact excerpt
“collect third-party integration credentials including OAuth access and refresh tokens for Salesforce”
- E2, E3klue.comAn Update on the Recent Klue Security Incident - KlueOther public report · Jun 19 · CitedOther public reportCited
Exact excerpt
“subsequently accessed data within a number of connected customer environments”
Show all 8 sourcesShow the first six sources
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.