ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Catch Cheater
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Bug Sweep TSCM Investigation
      • Workers Compensation Fraud Investigation
      • Asset and Hidden Finances Investigations
    • Cyber Security
      • DIGITAL EVIDENCE AUTHENTICATION
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Assets Search 
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > Klue OAuth breach linked to ‘Icarus’ Salesforce recordsdata theft attacks
    Klue OAuth breach linked to ‘Icarus’ Salesforce recordsdata theft attacks
    18
    Jun
    • ForensicsS
    • 0 Comments

    Klue OAuth breach linked to ‘Icarus’ Salesforce recordsdata theft attacks

    Scam detection

    scam detection Data theft

    Market intelligence platform Klue suffered a OAuth breach that enabled the “Icarus” likelihood actors to rob Salesforce CRM recordsdata from more than one organizations in an ongoing extortion campaign.

    Sources instructed BleepingComputer of the attack the day earlier than these days, telling us that tons of organizations had their Salesforce recordsdata stolen and were now being extorted by the pretty novel extortion neighborhood.

    Cybersecurity companies ReliaQuest and Huntress dangle each and each revealed stories confirming the protection incident, with Huntress declaring that their Salesforce recordsdata became as soon as stolen in the attack.

    scam detection image

    Salesforce has since disabled the Klue Battlecards integration on its platform while the breach is investigated.

    “To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident,” Salesforce warned the day earlier than these days.

    “As a result, organizations will not be able to connect to Salesforce via this app until further notice.”

    If you are going to dangle any recordsdata concerning this incident or completely different undisclosed attacks, it is seemingly you’ll perhaps contact us confidentially by Sign at 646-961-3731 or at suggestions@bleepingcomputer.com.

    Scam detection Stolen OAuth credentials outdated school to rob Salesforce recordsdata

    ReliaQuest talked about that attackers received access to Klue Battlecards integration service accounts and outdated school OAuth tokens related to customer Salesforce conditions to reach recordsdata theft.

    The researchers seen the likelihood actors producing OAuth tokens and then the exercise of computerized Python scripts to query Salesforce’s REST API for nearly 24 hours.

    The exercise started with reconnaissance of a firm’s Salesforce conditions thru the ‘/products and companies/recordsdata/v59.0/sobjects’ endpoint ahead of exfiltrating recordsdata the exercise of the ‘/products and companies/recordsdata/v59.0/query’.

    ReliaQuest talked about that for one in all the organizations, the attackers slowly mapped out their Salesforce objects to title precious objects and then at the moment stole recordsdata when they knew what they mandatory.

    “The attacker then hit the same endpoint, sending almost a thousand queries in a 15-minute window in at least one environment,” explained ReliaQuest.

    “Where the first stage was a slow, steady pull designed to blend in, this burst traded stealth for speed, suggesting either time pressure or a shift to targeted records. In another case, the exfiltration was observed over 6 hours.”

    The researchers talked about the exercise carefully resembled old Salesforce third-celebration integration recordsdata theft attacks by the ShinyHunters extortion neighborhood, but were unable to attribute the attacks to the likelihood actor.

    On the opposite hand, BleepingComputer learned the day earlier than these days that ShinyHunters became as soon as now not at the help of this attack, but rather a lovely novel likelihood actor identified as “Icarus” who had already begun emailing extortion requires to Klue customers impacted by the breach.

    A ransom ticket shared with BleepingComputer confirmed that the emails were sent the exercise of the alias “mr bean” and incorporated a Session Messenger ID to contact them.

    scam detection Icarus extortion email
    Icarus extortion electronic mail
    Supply: BleepingComputer

    The likelihood actors’ recordsdata leak space additionally comprises a message hinting at the extortion campaign in a straightforward post titled “Get Ready,” declaring, “big corps getting listed. be ready.”

    scam detection Message on the Icarus data leak site
    Message on the Icarus recordsdata leak space
    Supply: BleepingComputer

    Icarus is believed to dangle launched in April 2026, and firstly listed two victims on its leak space, with BleepingComputer studying that as a minimum one in all these victims is hooked up to the Klue campaign. That firm has now been eradicated from the guidelines leak space, which would maybe honest reveal that negotiations are underway.

    In the present day, Huntress disclosed that it became as soon as amongst the organizations impacted by the Klue breach, confirming that they had received a the same extortion electronic mail as seen by BleepingComputer. On the opposite hand, the Session ID outdated school in later emails became as soon as completely different and became as soon as as a change the one listed on the Icarus recordsdata leak space, offering additional evident that they were at the help of the attack.

    “In the initial email, the adversary suggests, ‘we advice you to write to us on Session’ (sic),” reported Huntress.

    “The Session Messenger ID that they provided matched the same values included on the dark web leak site of a new extortion group dubbed ‘Icarus.'”

    In accordance to Huntress, Klue instructed customers that attackers first compromised the firm’s backend systems and then pushed a malicious code update that stole OAuth tokens customers exercise to integrate the Battlecards product with third-celebration platforms.

    The attackers reportedly outdated school a dormant but calm energetic credential created by Klue for a prototype integration. After gaining access to Klue’s ambiance, they stole customer OAuth tokens and outdated school them to query connected Salesforce environments straight.

    Klue later disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Pressure, and Slack while responding to the incident.

    Huntress talked about the stolen recordsdata comprises CRM-related recordsdata, in conjunction with industry contacts, gross sales communications, effect quotes, aggressive intelligence stories, and anecdote recordsdata.

    The cybersecurity firm talked about there became as soon as no evidence that likelihood intelligence, customer telemetry, passwords, rate card recordsdata, or engineering systems were compromised.

    Both ReliaQuest and Huntress shared IP addresses linked to the attacks, which would maybe perhaps perhaps be listed beneath:

    138.226.246.94
    212.86.125.24
    213.111.148.90
    94.154.32.160

    Organizations the exercise of Klue integrations are told to envision Salesforce and related SaaS logs for exercise originating from these addresses, revoke and rotate OAuth tokens, terminate energetic sessions, and review Salesforce logs for uncommon API exercise.


    scam detection article image

    Scam detection

    Take a look at every layer ahead of attackers dangle

    Security teams log 54% of winning attacks and alert on real 14%. The the leisure transfer thru your ambiance unseen.

    The Picus whitepaper reveals how breach and attack simulation checks your SIEM and EDR principles so threats discontinuance slipping by detection.

    Rep the whitepaper

    Learn More

    • Tags

    • Breach cybercrime email-fraud forensics|digital-forensics Investigation malware OAuth online-scam private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker

    Recent Posts

    • Spoiled fruit puree hospitalizes youngsters in Israel
    • Protection fights ‘voodoo forensics’ in Lindsay Clancy’s assassinate trial
    • Klue OAuth breach linked to ‘Icarus’ Salesforce recordsdata theft attacks
    • Her Son Died of a Rare Bone Most cancers. Would possibly presumably well Radioactive Fracking Extinguish Be to Blame?
    • Purchased a Boots electronic mail providing ‘free reward beauty pattern pack’? Neatly, 8.8 million of us acquired the same component from Romanian hackers taking a discover about to rob our credit ranking playing cards (and additional)

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    Spoiled fruit puree hospitalizes youngsters in Israel
    June 18, 2026
    Spoiled fruit puree hospitalizes youngsters in Israel
    Protection fights ‘voodoo forensics’ in Lindsay Clancy’s assassinate trial
    June 18, 2026
    Protection fights ‘voodoo forensics’ in Lindsay Clancy’s assassinate trial
    Klue OAuth breach linked to ‘Icarus’ Salesforce recordsdata theft attacks
    June 18, 2026
    Klue OAuth breach linked to ‘Icarus’ Salesforce recordsdata theft attacks

    Popular Tags

    administration Arrested Chinese Confirms Crypto cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity digital-forensics email-fraud Epstein Faces forensics|digital-forensics Former fraud hacker hackers House Investigation investigationcybersecurity Judge Justice Launches malware malwarefraud malwarephishing-attack Minnesota North online-scam online-scamphishing-attack opens Patel phishing-attack Police private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe Trump Trump’s warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO