Back to Exposure Report
Supply Chain / SaaS June 23, 2026 Global

Klue (Supply Chain Attack)

One forgotten credential from 2022. A prototype integration that never shipped. Four years later: ~200 companies breached, including LastPass, HackerOne, and BeyondTrust.

OAuth tokensCustomer namesPhone numbersEmail addressesPhysical addressesSupport case dataSales dataSalesforce environment access
1

What happened?

On June 12, 2026, the hacking and extortion group Icarus gained access to Klue—a market research and competitive intelligence provider—using a credential that had been sitting dormant in the system since 2022. The credential was created for a third-party integration prototype that was never shipped. Nobody cleaned it up.

Once inside Klue, Icarus stole OAuth tokens that connected Klue to customers' Salesforce environments. Those tokens provided access to nearly 200 companies' CRM data. The breach cascaded from one vendor to hundreds of downstream victims.

2

What data was actually inside?

OAuth tokens providing access to customer Salesforce environments. LastPass confirmed hackers accessed customer names, phone numbers, email addresses, physical addresses, support case data, and sales data. Each affected company faces similar exposure depending on what their Salesforce instance contained.

Salesforce environments hold customer relationship data: contacts, communications, deals, support interactions. For companies like HackerOne (bug bounty coordination) or Tanium (endpoint management), that data reveals their own customer relationships and security operations.

3

Who gets hurt and how?

Customers of ~200 companies whose data resided in those companies' Salesforce environments. The victims include customers of security companies: LastPass (password management), HackerOne (bug bounty), BeyondTrust (privileged access), Snyk (application security), Recorded Future (threat intelligence).

The irony is substantial. Companies that sell security and trust products—breached through their market intelligence vendor. Their customers expected data protection. Instead, their data flowed through OAuth tokens to attackers via a four-year-old forgotten credential.

4

What did they think they were doing right?

LastPass emphasized their products, services, and infrastructure were not affected—customer vaults remained secure. The breach was limited to CRM data accessed through the Klue supply chain. The core password management service wasn't compromised.

But the Salesforce environment still contained customer information. Support cases, sales data, contact details. The security of the core product doesn't protect the business systems that surround it. OAuth integrations create data flows that extend beyond controlled environments.

5

What did they not know about their own data?

The credential from 2022. A prototype that never shipped but the access remained. Four years of a dormant integration sitting in the system, waiting for someone to find it. How many other forgotten credentials exist across how many other vendor relationships?

OAuth tokens accumulate as organizations integrate SaaS platforms. Each integration creates persistent access. Without regular audits of which tokens exist and what they access, organizations don't know their full exposure surface. The attack surface includes every integration ever configured.

If you use Salesforce, you probably have the same data types—emails, names, addresses, phone numbers. Do you know which fields contain PII?

6

What does attribution look like the morning after?

Each of the ~200 affected companies must assess their own exposure. What data existed in their Salesforce environment? Which customers were affected? Notification requirements vary by jurisdiction and data type. The incident response multiplies across every victim organization.

Icarus used extortion tactics. When negotiations with Klue failed, the impact cascaded to customers. Each downstream company faces its own decision: how to respond, what to disclose, how to notify affected individuals. The burden doesn't stay with the breached vendor.

7

What would have changed the outcome?

Regular audits of OAuth tokens and third-party integrations—identifying and revoking dormant credentials before attackers find them.

A 2022 credential shouldn't have existed in 2026. Prototype integrations that never ship should be cleaned up. Third-party access audits identify what connections exist, what they can access, and whether they're still needed. The organizations that prevent supply chain breaches are the ones that know their full integration landscape—and prune what's no longer required.

Klue found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.