Huntress·Technology / SaaS·
Salesforce data was downloaded.
Huntress confirmed that attackers copied business contacts, quotes, sales data, and messaging from its Salesforce account. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: A long-disused but still active credential was used for the initial compromise
- Consequence
- Confirmed: Salesforce data was downloaded.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Huntress
- Industry
- Technology / SaaS
- Disclosed
- Third party
- Klue
- Affected asset
- Huntress Salesforce account
- Product / vendor
- Salesforce
- Data involved
- Business Confidential
- Documented impact
- Data exposure
- Attached evidence
- 6 independent domains · 6 sources
2)Evidence-backed incident path
- 01
Reported cause
A long-disused but still active credential was used for the initial compromise
ConfidencePrimaryExact excerpt
E1“the threat actor seems to have leveraged a long-disused but still active credential to conduct the initial compromise”
huntress.com · Jun 18 - 02
Third party
Klue
ConfidencePrimaryExact excerpt
E2“Huntress is one of those customers of Klue”
huntress.com · Jun 18 - 03
Affected product
Salesforce
ConfidencePrimaryExact excerpt
E3“The data that was copied from our Salesforce account”
huntress.com · Jun 18 - 04
Reached
Huntress Salesforce account
ConfidencePrimaryExact excerpt
E4“The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging”
huntress.com · Jun 18 - 05
Observed
Salesforce data was downloaded.
ConfidenceConfirmedExact excerpt
E5“Your data has been downloaded”
huntress.com · Jun 18
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Not publicly established
No qualifying public evidence in the attached record.
- Whether any ransom or extortion payment was made
- That a Defence review would have prevented this incident
4)Relevance to your product
Third-party access can inherit more reach than the product team intended.
This pattern applies when…
- Products that authorize third-party integrations to copy CRM data.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Technology / SaaS
- 2 incident threads
- 1 incident threads
- 5 incident threads
- 2 incident threads
- 13 incident threads
- 5 incident threads
- 18 incident threads
- 16 incident threads
- 16 incident threads
- 16 incident threads
- 7 incident threads
- 29 incident threads
- Same incident family
- 56 Supply chain / third party
- Confirmed share
- 40% 52 confirmed · 78 reported
- Display family
- Supply chain Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Technology / SaaS in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
6 attached sources across 6 independent domains. At least one primary source is attached.
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.