← Back to news

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

The Hacker News19/06/2026, 09:03
Read full article →

Summary

AI-Generated

Key Points:

  • Unauthorized access to customer data occurred through the Klue app integration with Salesforce, following a breach by the Icarus group.
  • The incident exposed sensitive business information, including contacts and sales data, but did not compromise passwords or payment information. The breach was facilitated by a compromised legacy credential.
  • Organizations should disable the Klue app integration and monitor for unusual activity. Revoking OAuth tokens and credentials used in the integration is critical.

Technical Details: The attackers exploited a long-disused credential to gain access to Klue's infrastructure, allowing them to generate OAuth tokens for querying Salesforce environments. This incident is linked to previous OAuth abuse attacks targeting Salesforce.

MITRE ATT&CK Techniques:

  • T1078 - Valid Accounts (Defense Evasion)
  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1046 - Network Service Discovery (Discovery)

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.