Third-Party Incident Briefing Monthly Series
Edition 03: July 2026

11 min read

The Non-Human Identity Nobody Reviews

Inside the Klue to Salesforce OAuth breach, the third supply chain attack on Salesforce's integration ecosystem in under twelve months.

SaaS Supply ChainOAuthTPRM
A robotic sentinel scanning people at a castle entrance
Developing StoryAs of July 1, 2026

Klue's integration layer began showing anomalous activity on June 11, 2026. Salesforce disabled the Klue Battlecards app sometime between June 11 and June 17, with sources reporting different dates within that window and no single outlet or company statement resolving it further. Named victims confirmed impact through the last week of June, and reporting places the total affected organization count in the hundreds. This briefing reflects information available as of publication, cited to the outlets that reported it.

Organizations impacted

Hundreds

Reported range; no single final count has been published

Coverbase alert time

4.5 min

From disclosure to first customer notification

Root cause

Stale test credential

Created for an integration that was never deployed, never decommissioned

Data exposed

CRM-native records

Business contacts, sales communications, pricing, opportunity and deal notes

3rd Salesforce OAuth breach in under 12 months

Klue

Jun 11, 2026

Gainsight

Nov 2025

Salesloft

Aug 2025

Two different threat actors, one repeated playbook

01 · The Vendor

Who is Klue?

Klue is a niche business-to-business SaaS platform built for competitive intelligence and sales battlecards. Sales and marketing teams use it to track competitors, publish talking points to sales reps, and sync that intelligence into the systems those reps actually work in day to day, principally Salesforce and Gong.

In a typical vendor inventory, if Klue appears at all, it shows up as a sales-enablement tool. Low blast radius, low friction, an easy approval. It is rarely the kind of vendor that triggers a deep security review, because on paper it does not touch anything that looks sensitive. It manages battlecards, not customer data.

That framing was already out of date before June 11. Klue's product depends on a persistent, broadly scoped connection into your Salesforce environment: an OAuth-authorized integration with standing read and write access to CRM records, so that competitive intelligence can flow into deal notes and opportunity records in real time. The tool's entire value proposition requires it to sit inside your CRM with meaningful access. Most TPRM programs assess that relationship as if it were a read-only reporting dashboard.

Why this matters for TPRM

The question a program should be asking about any CRM-connected app is not "what does this vendor do." It is "what does this vendor's OAuth grant let it do inside my systems of record, and who is watching that grant." For Klue, and for the category of tools it represents, almost no program has an answer.

02 · What Happened

A stale credential in Klue's backend became a path into hundreds of companies' Salesforce environments, without touching a single customer password.

1

Klue's environment contained a long-disused but still active credential, originally created to test a third-party integration that was ultimately never shipped. It sat there, unused and undecommissioned, until the threat group Icarus found it.

2

Icarus is a relatively new extortion operation, with its leak site claiming activity dating back to April 28, 2026. Before Klue, the group had claimed an earlier breach of the Indonesian fintech Cazh.id (customer records, ID documents, and source code, per the group's own unverified claims). Klue is its most consequential confirmed target to date.

3

Using the stale credential, Icarus gained access to Klue's integration-connection backend, the internal system responsible for brokering Klue's connections into customer Salesforce and Gong environments. Anomalous behavior in that system began on June 11. Klue detected the unauthorized activity the following day and began notifying affected downstream vendors, including LastPass, on June 12.

4

From inside that backend, Icarus pushed a malicious update to Klue's integration layer. The update's function was to harvest OAuth tokens: the credentials that Klue's own customers had issued to let Klue talk to their Salesforce and Gong instances on their behalf.

A robotic sentinel outside an illuminated castle

This is the mechanism worth sitting with, because it is the part every other write-up will summarize in one sentence and move past.

An OAuth token issued to a SaaS integration is not a password. It is a standing authorization, typically long-lived, typically scoped broadly enough to cover whatever the integration needs to do its job, and typically invisible to the controls that watch for compromised employee accounts. Nobody rotates it on a schedule. Nobody requires MFA to use it. It does not show up in a login-anomaly report, because from Salesforce's perspective, the API calls made with a stolen Klue token look exactly like Klue behaving normally.

With those tokens, Icarus impersonated Klue directly inside each customer's Salesforce environment. No customer credential was phished. No customer employee clicked anything. The attacker authenticated as the app itself, using access the customer had granted months or years earlier and had no reason to be actively watching.

The data pulled out was CRM-native by design, because that is what an OAuth-authorized CRM integration has access to: business contacts, sales communications, pricing information, and opportunity or deal notes. Huntress, one of the earliest confirmed victims to disclose, additionally reported exposure of business names, product usage and trial details, and subscription information.

03 · Key Dates

A rolling disclosure that took two weeks to reach its current victim count, and still isn't finished.

April 28, 2026

Icarus surfaces

Icarus's leak site states the group has been active since this date. Its earlier, unverified claim against Cazh.id predates the Klue campaign.

June 11, 2026

Anomalous activity begins

Klue's integration-connection backend begins showing signs of unauthorized activity.

June 11-12, 2026

Detection and disclosure begins

Klue detects the unauthorized activity tied to its integration layer. LastPass reports being notified of the incident on June 12.

June 11-17, 2026

Integration disabled

Salesforce and Gong disable the Klue Battlecards app sometime within this window; reporting does not agree on a single day.

Mid to late June 2026

Extortion campaign

Icarus begins emailing affected companies under the alias "mr bean," relaying messages through compromised mail infrastructure at an unrelated third party, Global Retail Brands.

June 18-24, 2026

Rolling victim confirmations

Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, BeyondTrust, and LastPass (confirmed June 24) each disclose impact across roughly a two-week window.

Ongoing

Victim count in the hundreds

Reporting places the total affected organization count in the hundreds. No single outlet or company statement has published a final figure.

04 · The Pattern

Salesloft, Gainsight, Klue. Three app names, two threat actors, one identical playbook, run three separate times in under a year.

Read across the row, and the pattern is not subtle. Nobody is attacking Salesforce directly. Every actor in this table went after the smaller, lower-scrutiny SaaS tool that happens to hold a standing OAuth connection into Salesforce, because that connection is functionally a second front door into the CRM, and it is a door almost nobody watches.

Aug 8-18, 2025

Target

Salesloft Drift (AI customer-engagement integration)

Actor

UNC6395 / ShinyHunters

Vector

Compromised OAuth tokens tied to the Drift integration

Downstream Impact

700+ organizations; stolen CRM data mined for secondary secrets including AWS keys, Snowflake tokens, and passwords

Nov 2025

Target

Gainsight (customer-success/Salesforce-integrated app)

Actor

ShinyHunters-linked actors

Vector

Reused and related stolen OAuth tokens and app-level credentials; impersonation from non-approved IPs

Downstream Impact

Accessed via API activity that appeared legitimate; part of a combined campaign ShinyHunters later claimed reached roughly 1,000 organizations across Salesloft and Gainsight together

Jun 11-12, 2026

Target

Klue (competitive-intelligence/battlecard integration)

Actor

Icarus (new group, active since April 2026)

Vector

Long-disused legacy test credential, escalated to stolen customer OAuth tokens and Salesforce/Gong impersonation

Downstream Impact

Hundreds of organizations, including multiple security vendors

The industry has now had three separate, well-documented opportunities to internalize this lesson in under twelve months.

1

Salesloft was the first data point. Gainsight was the confirmation that it was a pattern, not a fluke.

2

Klue is the third instance of the same actor-methodology, from a different group entirely, which means the technique has now proven repeatable across at least two independent threat actors.

3

Icarus has not, as of publication, been assigned a formal threat-tracking identifier by a major intelligence vendor.

05 · Scope of Impact

The headline number is in the hundreds. The downstream questions matter more.

The Compromised Vendor

Klue itself. A niche B2B SaaS company now facing a breach-notification obligation to every one of its customers simultaneously, and a reputational hit that is disproportionate to the company's size relative to the names now associated with its breach.

3rd Party

Every organization that had the Klue Battlecards app connected to Salesforce or Gong. Hundreds of companies had CRM data pulled out through OAuth tokens they had issued long ago and had no active reason to be watching.

Several of the named victims (Huntress, LastPass, BeyondTrust, Tanium, Recorded Future) are themselves security vendors, which is its own irony worth sitting with: companies whose core business is telling other people to watch their attack surface were themselves running an unmonitored OAuth connection into their own CRM. None of the named victims in this incident are Coverbase customers or active prospects.

4th Party

Klue itself. A niche B2B SaaS company now facing a breach-notification obligation to every one of its customers simultaneously, and a reputational hit that is disproportionate to the company's size relative to the names now associated with its breach.

The Layer No One Tracks

Competitive-intelligence, sales-enablement, and marketing-ops tools connected to the CRM by OAuth. These almost never appear on a formal vendor inventory, because they are treated as internal tooling rather than as risk-bearing third parties. That is the same blind spot Edition 02 identified in the VS Code extension publisher sitting on every engineering endpoint. Here it is the AppExchange install a single account executive added last year, with nobody in security ever reviewing it.

06 · Remediation

There is no customer-side patch for a token that was already stolen and already used.

Klue's and Salesforce's public response has followed the standard playbook for this category of incident: disable the compromised integration, notify affected customers, and begin a rolling wave of confirmations as downstream vendors complete their own investigations. That sequence is necessary but not sufficient, because the exposure window for stolen CRM data does not close when the integration is disabled. The data that left during the active compromise is already out, and it does not expire.

For any organization that had Klue connected to Salesforce or Gong, the operational posture should be precautionary and ongoing, not a one-time cleanup.

The Root-Cause Lesson

The breach was not caused by a failure of Salesforce's security program, or even really Klue's.

It was caused by a structural blind spot in how every modern GTM stack works: dozens of small SaaS tools hold persistent, broadly scoped OAuth tokens into your CRM, and almost none of them are on anyone's vendor risk inventory

The OAuth token, a non-human identity, is the actual perimeter here. It typically carries access as broad as a full-time employee's, with a fraction of the monitoring.

07 · How Could You Have Prepared?

Three program-level shifts that would have raised your posture before June 11.

1

Inventory the OAuth layer, not just the vendor list

Most TPRM programs assess vendors that get a signed contract and a security questionnaire. Sales-enablement and competitive-intelligence tools like Klue routinely get installed by a single account executive or sales-ops person straight from the Salesforce AppExchange, with zero security review and no line item on the formal vendor list. Build and actively maintain a live inventory of every application holding a standing OAuth grant into Salesforce, Gong, HubSpot, or any other system of record, independent of whether that app was ever formally "onboarded" as a vendor.

2

Treat "Salesforce OAuth supply chain" as its own tracked risk category

Salesloft, Gainsight, and Klue are not three unrelated vendor breaches. They are three instances of one attack methodology, run against the same category of target by two different actors. A program that flagged Salesloft in August 2025 as a signal about the methodology, rather than a one-off breach at one vendor, would have had elevated monitoring on every CRM-connected integration well before Gainsight confirmed the pattern in November, let alone before Klue in June.

3

Scope and rotate OAuth tokens like any other credential with production access

A long-disused, undecommissioned credential is exactly what enabled the Klue breach, and it is a known, preventable failure mode. Require expiration policies, least-privilege scopes, and periodic re-authorization for any app with standing CRM access, including your vendors' own internal test and staging integrations, which is precisely the category of credential that started this chain.

08 · What a Monitoring Program Would Have Seen

A stale credential in Klue's backend was never going to be prevented by a vendor risk platform. What a well-instrumented program can do is shorten the distance between the first signal and a confident answer to "what is our exposure."

Stage 01 · August 2025

Before the breach

A program tracking "Salesforce OAuth supply chain compromise" as a portfolio-level category, rather than a tag on one vendor's record, would have flagged every CRM-connected integration for elevated review the moment Salesloft Drift was confirmed. The signal that mattered was the methodology, not the specific vendor.

Stage 02 · November 2025

The second confirmation

Gainsight is the point where a single incident becomes a pattern. A program ingesting threat intelligence at the actor-and-methodology level, not just per-vendor breach alerts, would have treated this as near-certain confirmation that a third incident was coming, and would have used the intervening months to build the OAuth inventory described in Section 07.

Stage 03 · June 2026

Disclosure to customer alert in 4.5 minutes

Within 4.5 minutes of Klue's disclosure, Coverbase customers with Klue in their vendor inventory received an alert mapped to their specific exposure profile: whether Klue was connected to Salesforce, Gong, or both, which data categories flowed through that integration, and what immediate action was recommended given that usage pattern. The industry average for a TPRM team to manually triage a vendor breach like this and produce a usable exposure summary is measured in days, not minutes.

Stage 04 · Mid to late June

Rolling victim confirmations

As Huntress, LastPass, BeyondTrust, and the rest confirmed impact across roughly two weeks, a program built on structured incident data updates each customer's exposure profile automatically as each new confirmation lands, rather than requiring a human to re-read every disclosure and manually reassess.

Stage 05 · Ongoing

90-day window

Stolen CRM data does not expire when Klue rotates a credential. Pricing, deal notes, and product usage details retain their value to an extortion group for as long as they remain useful leverage. The right posture for the next 90 days is to treat any anomalous Salesforce or Gong API activity, particularly from any app with recent extortion-campaign exposure, as elevated risk and route it to the same response queue as the original breach notification.

The Bottom Line

This is the third Salesforce OAuth supply chain breach reported in under a year, and the second threat actor to run the identical playbook.

That repetition is the story, more than any individual detail about Klue. A structural weakness in how modern GTM stacks work, meaning that dozens of small, over-trusted SaaS tools hold standing, broadly scoped, minimally monitored access into the systems that run your revenue operations, has now been exploited three separate times, by two different groups, in three separate public incidents, and each time the coverage has largely treated it as an isolated vendor failure rather than a category.

The question every TPRM program should be asking is not whether Klue was breached.

It is whether the program has a category for "OAuth-connected non-human identity with standing access to a system of record," tracked with the same rigor as a full-time employee's credentials. Without that category, the next entry in this pattern will look like a surprise. With it, next one starts to look like a forecast.

Sources

BleepingComputer, LastPass, Help Net Security, SecurityWeek, CSO Online, The Register, RH-ISAC, Huntress, The Hacker News, ReliaQuest, Salesforce Ben, Obsidian Security, Rescana, Mallory.ai, Dark Reading, ThreatLocker, Zscaler, Google Cloud Blog, Unit 42, Anomali, Salesloft/Clari Trust Center, AppOmni. Full source list available on request; see the accompanying research brief for individual citations.