ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Catch Cheater
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Bug Sweep TSCM Investigation
      • Workers Compensation Fraud Investigation
      • Asset and Hidden Finances Investigations
    • Cyber Security
      • DIGITAL EVIDENCE AUTHENTICATION
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Assets Search 
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > Klue OAuth breach victim listing grows as Icarus hackers claim attack
    Klue OAuth breach victim listing grows as Icarus hackers claim attack
    19
    Jun
    • ForensicsS
    • 0 Comments

    Klue OAuth breach victim listing grows as Icarus hackers claim attack

    Identity theft

    identity theft Klue + Salesforce

    Market intelligence platform Klue has publicly confirmed a novel safety incident that allowed threat actors to believe terminate OAuth tokens old to connect to prospects’ Salesforce environments, as the novel “Icarus” extortion community publicly claims the attack.

    The disclosure comes after cybersecurity corporations Huntress and ReliaQuest detailed how attackers abused compromised Klue Battlecards integrations to believe terminate Salesforce CRM recordsdata from extra than one organizations.

    In a assertion printed this week, Klue CEO Jason Smith confirmed that the corporate discovered unauthorized job on June 12 affecting portion of Klue’s integration infrastructure.

    identity theft image

    “On June 12, we identified unauthorized activity affecting a portion of Klue’s integration infrastructure. Since then, we’ve been working alongside trusted cybersecurity experts to understand what happened, support our customers, and restore the connections you rely on,” wrote Smith.

    “Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments.”

    The corporate says there is at expose no evidence that customer vow stored without lengthen at some level of the Klue platform modified into as soon as impacted and that the incident modified into as soon as restricted to third-birthday celebration integrations.

    Klue says it straight revoked affected credentials and tokens, eradicated unauthorized code, disabled impacted integrations, launched an investigation, and notified legislation enforcement. The corporate additionally confirmed it engaged CrowdStrike to lend a hand with the response.

    ReliaQuest and Huntress discovered that the attackers old stolen OAuth credentials associated with Klue integrations to rating true of entry to customer Salesforce environments and habits vivid-scale recordsdata theft.

    ReliaQuest observed attackers generating OAuth tokens and the utilization of Python scripts to effect a question to Salesforce’s API for extended periods, as recordsdata modified into as soon as stolen.

    Huntress later disclosed that its dangle Salesforce setting modified into as soon as tormented by the Klue breach and that the stolen recordsdata integrated business contacts, sales communications, pricing recordsdata, and other records.

    Identity theft Icarus claims responsibility

    While BleepingComputer and Huntress beforehand linked the incident to the Icarus extortion operation, the threat actors believe now publicly claimed responsibility on their recordsdata leak characteristic.

    “As you’ve probably already heard, Klue.com has been impacted by us recently. A number of other companies’ Salesforce instances, which were partners to Klue, were exfiltrated,” reads the Icarus post.

    identity theft Icarus claiming responsibility for the Klue breach
    Icarus claiming responsibility for the Klue breach

    The threat actors went on to stress Klue and affected organizations to contact them thru the Session messaging platform to forestall the leaking of stolen recordsdata.

    The post comes after BleepingComputer beforehand reported that the attacks were linked to Icarus, after sources shared extortion emails sent to affected organizations. Huntress additionally independently connected the operation to Icarus thru Session Messenger IDs old in the extortion emails and the community’s recordsdata leak characteristic.

    Since then, further victims believe disclosed that they were tormented by the attacks, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity.

    Nearly about all reveal the incident resulted in the theft of recordsdata from their Salesforce instances and did no longer believe an affect on their platforms, infrastructure, rate recordsdata, or internal systems.

    Several organizations warned that the stolen business contact recordsdata is liable to be old in apply-on phishing, social engineering, and extortion campaigns and urged prospects to be vigilant.


    identity theft article image

    Identity theft

    Take a look at every layer sooner than attackers keep

    Security teams log 54% of successful attacks and alert on fair 14%. The relief drag thru your setting unseen.

    The Picus whitepaper presentations how breach and attack simulation assessments your SIEM and EDR rules so threats stop slipping by detection.

    Obtain the whitepaper

    Read More

    • Tags

    • Breach cybercrime email-fraud forensics|digital-forensics hacker Investigation malware OAuth online-scam phishing-attack private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker

    Recent Posts

    • Recent Jersey council member and stale mob boss arrested for extortion
    • Hackers Claim to Leak Stolen Madison Square Garden Files
    • FBI Director Kash Patel Vows to Bring ‘Pig Butchering’ Crypto Criminals to Justice
    • DOJ opens probe into MLB after Satisfaction Night time controversy
    • Klue OAuth breach victim listing grows as Icarus hackers claim attack

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    FBI Director Kash Patel Vows to Bring ‘Pig Butchering’ Crypto Criminals to Justice
    June 19, 2026
    FBI Director Kash Patel Vows to Bring ‘Pig Butchering’ Crypto Criminals to Justice
    DOJ opens probe into MLB after Satisfaction Night time controversy
    June 19, 2026
    DOJ opens probe into MLB after Satisfaction Night time controversy
    eFAQ Publishes Investigation Into Alleged Scam Job and Coordinated Recognition Attacks
    June 19, 2026
    eFAQ Publishes Investigation Into Alleged Scam Job and Coordinated Recognition Attacks

    Popular Tags

    administration Arrested Confirms Crypto cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity digital-forensics director email-fraud Epstein Faces forensics|digital-forensics Former fraud hacker hackers House Investigation investigationcybersecurity Judge Justice Launches malware malwarefraud malwarephishing-attack Minnesota North online-scam online-scamphishing-attack opens Patel phishing-attack Police private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe Trump Trump’s warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO