Threat Briefing

Klue供应链泄露事件:OAuth令牌失窃,近200家企业Salesforce数据遭泄露

In June 2026, the integration infrastructure of SaaS provider Klue was exploited, leading to the theft of OAuth tokens and data breaches at nearly 200 downstream clients, including security vendors such as Huntress and Recorded Future. Analysis of attack methods, corporate impact, and defense recommendations.

Incident Overview

In June 2026, a supply chain attack targeting SaaS provider Klue impacted nearly 200 downstream organizations, including multiple cybersecurity vendors such as Huntress, Recorded Future, Tanium, and Jamf. The attackers exploited legacy credentials within Klue's integration infrastructure to steal OAuth tokens, then accessed customer-connected Salesforce environments to exfiltrate business contact information and sales data. The threat group Icarus conducted extortion via a Tor leak site, but subsequently suffered its own compromise, resulting in the stolen data falling into the hands of another unauthorized party for a second time.

Technical and Risk Analysis

Attack Chain

The attackers first discovered and exploited a long-abandoned but still valid credential within Klue’s integration infrastructure (MITRE ATT&CK T1078: Valid Accounts). Using this credential, they pushed malicious code specifically designed to steal OAuth tokens that customers had authorized Klue to use for connecting to their systems (T1528: Steal Application Access Token). With these tokens, the attackers impersonated Klue and used legitimate API queries to access customer Salesforce environments (T1550: Use Alternate Authentication Material), extracting business contact information and sales data (T1213: Data from Information Repositories), and exfiltrating it via web services (T1567.002: Exfiltration to Web Service).

Scope of Impact

Affected organizations were not limited to cybersecurity companies; they also included insurance providers, social media analytics platforms, and other SaaS customers. Fortunately, customer-facing products, infrastructure, and sensitive engineering data were not compromised, nor were passwords or payment card information. However, the leaked data was sufficient to support subsequent targeted phishing attacks.

Secondary Leak

After Icarus’s initial extortion, another unauthorized party claimed to have obtained the same data and launched a new round of extortion, indicating that the original attacker's own systems had also been compromised. This increases the risk of further data exposure and complicates the incident response process.

Enterprise Impact Analysis

Operational Risk

The affected Salesforce integrations were temporarily disabled, resulting in reduced efficiency for teams relying on Klue for market intelligence analysis. Customers had to manually review and rotate all related OAuth tokens, increasing the operational burden.

Financial Risk

If enterprises pay the ransom, they may face direct financial losses. Additionally, the data breach could trigger contract breach penalties, especially for clients with SLA constraints.

Compliance Risk

The leaked CRM data may contain personally identifiable information (PII), which could lead to regulatory investigations and fines under regulations such as GDPR and CCPA. Affected enterprises need to assess the data categories and promptly notify regulators.

Brand Risk

For security vendors like Huntress, customer trust may be damaged due to their own supply chain security incidents.For security vendors like Huntress, their customer trust may be damaged due to their own supply chain security incidents.

Data Risk

Leaked business contact information can be used for social engineering attacks, with the risk of phishing emails targeting executives or sales teams significantly increased.

Industry Trend Observations

Supply Chain Attacks Continue to Escalate

This incident is not an isolated case. In recent years, supply chain attacks through third-party SaaS integrations have been on the rise, such as the MoveIt transfer attack in 2023. Attackers are increasingly favoring the use of legitimate OAuth tokens and APIs to conceal malicious behavior.

OAuth Security Becomes a Focus

OAuth tokens, as the core of modern identity authorization, have become a major risk due to poor management. Enterprises need to establish a full lifecycle token management strategy, including limiting token permissions, regular rotation, and monitoring abnormal usage.

Attackers Attack Each Other

Icarus's own secondary breach reveals competition and betrayal within the underground criminal ecosystem. Enterprises should anticipate that data may circulate among multiple attackers, and the extortion pressure will not disappear with the end of the initial incident.

Defense and Response Recommendations

Enterprise Level

  • Identity Security: Enable multi-factor authentication (MFA) for all third-party integrations and mandate short-term tokens instead of long-term credentials.
  • Zero Trust: Implement the principle of least privilege, restricting integrated applications to only access necessary data domains.
  • Vulnerability Management: Regularly audit and remove legacy or unused credentials and integrations.

Technical Level

  • SIEM/SOAR: Integrate OAuth token usage logs, configure alert rules to detect abnormal token activity, such as requests from atypical IPs or time periods.
  • EDR/XDR: Monitor abnormal processes and network connections on endpoints, especially lateral movement targeting credential access.
  • Threat Intelligence: Subscribe to relevant IoC sources to promptly block known malicious IPs (e.g., 138.226.246[.]94, etc.).

Management Level

  • Incident Response: Develop a dedicated plan for third-party breaches, clearly specifying contacts for corporate legal counsel, insurance companies, and law enforcement agencies (e.g., FBI).
  • Third-Party Risk Management: Conduct security assessments of core SaaS vendors, requiring them to provide security incident disclosures and contingency plans.

SecurityPost Insight

The Klue breach sounds the alarm once again: enterprise security responsibilities can no longer be confined within their own firewalls. The proliferation of OAuth tokens from third-party integrations makes every connection point a potential entry path. In this attack, the attackers exploited "legacy" credentials—a problem for which many enterprises lack effective cleanup mechanisms.More noteworthy is the phenomenon of secondary leakage: the original attacker themselves being hacked indicates vulnerabilities within the ransomware-as-a-service (RaaS) ecosystem, and enterprises should be wary of the possibility of data being resold multiple times. In the future, OAuth-based supply chain attack techniques will become more automated, and enterprises must incorporate third-party identity governance into zero-trust architectures and audit SaaS integration security just as they audit internal systems.

It is recommended that CISOs list "integration risk" as a key review item for the second half of 2026, with particular attention to service providers that manage OAuth tokens.

Evidence route · securitypost

securitypost frames this note through Security Post publishes defensive cybersecurity intelligence for enterprise security leaders, covering thre.... Threat Briefing / Enterprise Security / AI & Cybersecurity explains the local editorial angle: Source links should be opened before the summary is reused. dates, names and status changes still need checking.

Source URL

  1. https://www.rescana.com/post/klue-supply-chain-breach-exposes-oauth-tokens-and-salesforce-data-in-multi-stage-cybersecurity-incident-june-2026Primary

Related articles

Back to channel