Summary
Key Points:
- Unauthorized access to customer data occurred through the Klue app integration with Salesforce, following a breach by the Icarus group.
- The incident exposed sensitive business information, including contacts and sales data, but did not compromise passwords or payment information. The breach was facilitated by a compromised legacy credential.
- Organizations should disable the Klue app integration and monitor for unusual activity. Revoking OAuth tokens and credentials used in the integration is critical.
Technical Details: The attackers exploited a long-disused credential to gain access to Klue's infrastructure, allowing them to generate OAuth tokens for querying Salesforce environments. This incident is linked to previous OAuth abuse attacks targeting Salesforce.
MITRE ATT&CK Techniques:
- T1078 - Valid Accounts (Defense Evasion)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1046 - Network Service Discovery (Discovery)
IOCs Mentioned: None mentioned
Join the discussion — sign up to comment, upvote, and save articles.