Klue Hack Impacts Salesforce, Gong Integrations via Icarus Threat Actor

person in black hoodie hacking a computer system

A significant cybersecurity incident involving Klue, a business data platform, has exposed sensitive customer information and disrupted integrations with Salesforce and other platforms. The breach, attributed to a threat actor operating under the moniker ‘Icarus,’ highlights the growing risks associated with supply chain attacks and the importance of robust credential management practices. Klue detected unauthorized activity affecting a portion of its integration infrastructure on June 12, 2026, marking the initial stage of what has unfolded into a widespread compromise.

Security researchers have determined that Icarus leveraged a compromised legacy credential to gain access to Klue’s systems. This access was then used to generate OAuth tokens, effectively breaching third-party platforms integrated with Klue, most notably Salesforce and Gong. The attackers were able to abuse the Salesforce REST API over a 24-hour window to exfiltrate CRM data. The specific method involved automated scripts connecting to connected Salesforce instances and executing unauthorized commands to harvest these tokens.

The consequences of this breach are far-reaching. Salesforce and Gong have swiftly responded by disabling the Klue integration in an attempt to contain the damage. Reports indicate that over a dozen organizations have already confirmed they’ve been impacted, demonstrating the widespread nature of the compromise. The data accessed through the Klue integration included critical CRM data such as customer names, phone numbers, email addresses, and physical addresses—information invaluable for targeted attacks and social engineering campaigns.

The technical details of the attack reveal a concerning pattern of exploitation. Hackers connected to Klue’s backend servers and executed unauthorized commands, pushing a code update that harvested OAuth tokens for customers’ Klue integrations. This technique allowed them to bypass traditional security controls and gain access to sensitive data residing within integrated platforms. Following the breach, all OAuth tokens were deactivated for impacted customers, and integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack were disabled.

This incident serves as a stark reminder of the vulnerabilities inherent in interconnected software ecosystems. Organizations utilizing integration platforms like Klue must prioritize strong credential hygiene practices, including regular rotation and multi-factor authentication. Security teams should also conduct thorough assessments of third-party integrations to identify potential attack vectors and implement robust monitoring capabilities to detect anomalous activity. Cybersecurity firms such as Huntress and Recorded Future have confirmed being impacted by this supply chain attack.

Sources: