The Klue supply chain attack keeps rippling outward. Roughly two dozen companies have now confirmed their Salesforce instances were compromised through the market intelligence platform’s integration.
The attack happened between June 11 and 12. Hackers used stolen legacy credentials to access Klue, then exploited OAuth tokens for customer integrations to siphon data in bulk. Salesforce yanked the Klue integration on June 17, and Gong followed suit. As of now, Salesforce’s status page still shows the integration disabled.
The named victims so far include AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. Autodesk, a Klue customer, clarified it wasn’t affected because it doesn’t use the Salesforce integration. That distinction matters — the blast radius depends entirely on which integrations each customer had enabled.
Klue has hundreds of customers, so this list could grow. But here’s where it gets stranger: a threat actor called Icarus claimed the breach and set up a Tor-based leak site, threatening to publish stolen data unless a ransom was paid. Klue confirmed the breach on Monday but hasn’t shared public findings since.
Behind the scenes, Klue reportedly told customers it contacted Icarus, who started deleting the stolen data. Icarus’s leak site has been down for a couple of days, which suggests a deal may have been struck.
Then the twist: Klue reportedly informed customers that Icarus themselves were hacked. Another threat actor now apparently has some of the stolen data and is running a separate extortion campaign. The incident allegedly affects 195 Klue customers, though the second actor may have only grabbed sample data from Icarus.
A supply chain breach breeding its own supply chain problem. No known group other than Icarus has publicly claimed the data, and Klue hasn’t responded to requests for comment.
