DEFENCE / RADAR

Public snapshot

Huntress·Technology / SaaS·

Salesforce data was downloaded.

Huntress confirmed that attackers copied business contacts, quotes, sales data, and messaging from its Salesforce account. The attached record does not establish the complete downstream scope.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: A long-disused but still active credential was used for the initial compromise
Consequence
Confirmed: Salesforce data was downloaded.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Huntress
Industry
Technology / SaaS
Disclosed
Third party
Klue
Affected asset
Huntress Salesforce account
Product / vendor
Salesforce
Data involved
Business Confidential
Documented impact
Data exposure
Attached evidence
6 independent domains · 6 sources

2)Evidence-backed incident path

  1. 01

    Reported cause

    A long-disused but still active credential was used for the initial compromise

    ConfidencePrimary
    Exact excerpt

    the threat actor seems to have leveraged a long-disused but still active credential to conduct the initial compromise

    huntress.com · Jun 18
    E1
  2. 02

    Third party

    Klue

    ConfidencePrimary
    Exact excerpt

    Huntress is one of those customers of Klue

    huntress.com · Jun 18
    E2
  3. 03

    Affected product

    Salesforce

    ConfidencePrimary
    Exact excerpt

    The data that was copied from our Salesforce account

    huntress.com · Jun 18
    E3
  4. 04

    Reached

    Huntress Salesforce account

    ConfidencePrimary
    Exact excerpt

    The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging

    huntress.com · Jun 18
    E4
  5. 05

    Observed

    Salesforce data was downloaded.

    ConfidenceConfirmed
    Exact excerpt

    Your data has been downloaded

    huntress.com · Jun 18
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • Whether any ransom or extortion payment was made
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that authorize third-party integrations to copy CRM data.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Technology / SaaS

130 incident threads in the 365-day public record
  1. 2 incident threads
  2. 1 incident threads
  3. 5 incident threads
  4. 2 incident threads
  5. 13 incident threads
  6. 5 incident threads
  7. 18 incident threads
  8. 16 incident threads
  9. 16 incident threads
  10. 16 incident threads
  11. 7 incident threads
  12. 29 incident threads
Same incident family
56
Supply chain / third party
Confirmed share
40%
52 confirmed · 78 reported
Display family
Supply chain
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Technology / SaaS in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

6 attached sources across 6 independent domains. At least one primary source is attached.

  1. E1, E2, E3, E4, E5
    huntress.comCybercrime Breaches Klue: Salesforce Data Impacted for ...Organization statement · Jun 18 · Primary
    Organization statementPrimary
    Exact excerpt
    business contacts, price quotes, and other sales-related data and messaging
  2. S2
    bleepingcomputer.comKlue OAuth breach linked to 'Icarus' Salesforce data theft attacksEstablished press · Jun 18 · Attached
    Established pressAttached
  3. S3
    news.lavx.huIcarus attackers use Klue OAuth breach to steal Salesforce data | LavX NewsOther public report · Jun 18 · Attached
    Other public reportAttached
  4. S4
    securityweek.comCybersecurity Firms Impacted by Klue Supply Chain Attack - SecurityWeekEstablished press · Jun 19 · Attached
    Established pressAttached
  5. S5
    csoonline.comKlue breach exposed Salesforce CRM data through stolen OAuth tokens | CSO OnlineEstablished press · Jun 22 · Attached
    Established pressAttached
  6. S6
    darkreading.comSalesforce Data Thefts Continue via Klue App CompromiseEstablished press · Jun 22 · Attached
    Established pressAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →