Breach report
Klue says an unrevoked 2022 credential led to theft of customers' Salesforce data

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The Vancouver competitive-intelligence vendor says a legacy integration credential let an attacker reach OAuth tokens connected to customers' Salesforce environments. LastPass, Jamf and others have confirmed impact.
What happened
Klue, a Vancouver-based market research company, detected a breach on 12 June 2026, according to TechCrunch. The company said the attacker used "a legacy credential associated with an integration service" created in 2022 for a limited pilot with a third party. That access reached systems holding OAuth tokens, the keys that let Klue's software read customer data in other cloud services such as Salesforce.
Salesforce disabled the Klue Battlecards integration, and Klue switched off integrations with eight platforms, including Salesforce, HubSpot, Gong and Google Drive, BleepingComputer reported.
Confirmed vs. claimed
Confirmed: Klue has acknowledged the legacy credential and the OAuth token access. LastPass, BeyondTrust, Jamf, HackerOne, Huntress, Snyk, Tanium and others confirmed their Salesforce data was affected, SecurityWeek reported. LastPass said its products, infrastructure and customer vaults were not touched.
Claimed: a group calling itself Icarus claimed responsibility and threatened to publish data unless paid. Klue has not said why the 2022 credential was never revoked, what type of credential it was, or whether it has engaged with the extortion demands.
Who is affected
The exposed data is CRM material held by Klue's customers: business contact names, phone numbers, email and postal addresses, support cases, sales communications and price quotes. If you are a customer of an affected company, your business contact details may be in that set.
What to do
- Klue customers: revoke and reissue any OAuth grants to Klue and review Salesforce login and API logs from June 2026.
- Audit third-party integrations for credentials left over from pilots that never shipped.
- If you receive an extortion email about this data, do not reply or pay; see our guide to handling extortion emails.
- Treat unexpected calls or emails quoting your support tickets with suspicion.
Sources
- TechCrunch — Klue says hackers stole credential from 2022 that led to customer data breaches (23 Jun 2026) Secondary
- BleepingComputer — Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks (18 Jun 2026) Secondary
- SecurityWeek — BeyondTrust, LastPass impacted by Klue-Salesforce incident (24 Jun 2026) Secondary
More breaches in Canada
- Duales (Duc app) — 02 Apr 2026