ctipilot.ch

Icarus Salesforce OAuth extortion

campaign · campaign:icarus-klue-salesforce-oauth single-source

Icarus extortion campaign: a dormant Klue credential led to harvested OAuth tokens and bulk Salesforce CRM data theft across downstream customers.

Coverage timeline
3
first 2026-06-19 → last 2026-06-29
Peak priority
notable
3 notable
Sources cited
12
11 hosts
Sections touched
2
updates, weekly-looking-ahead
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
5
pinned v19.1 · see below
2026-06-243 appearances2026-06-29

ATT&CK techniques

5 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8 · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-06-25/klue-icarus-salesforce-oauth-breach-beyondtrust-and-lastpass · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8 · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8 · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8 · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×1

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-06-25/klue-icarus-salesforce-oauth-breach-beyondtrust-and-lastpass · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-06-24/8x8-confirms-klue-icarus-salesforce-exfiltration-in-an-sec-8 · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-06-25/klue-icarus-salesforce-oauth-breach-beyondtrust-and-lastpass · ATT&CK page ↗

Story timeline

  1. 2026-06-29Looking ahead — 2026-W26
    weekly-looking-ahead
  2. 2026-06-25Klue/Icarus Salesforce OAuth breach — BeyondTrust and LastPass added to the named-victim list
    updates
  3. 2026-06-248x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing
    updates

Where this entity is cited

  • updates2
  • weekly-looking-ahead1

Source distribution

  • securityweek.com2 (17%)
  • advisories.ncsc.nl1 (8%)
  • cisa.gov1 (8%)
  • cloud.google.com1 (8%)
  • edpb.europa.eu1 (8%)
  • enisa.europa.eu1 (8%)
  • helpnetsecurity.com1 (8%)
  • nationalcrimeagency.gov.uk1 (8%)
  • other3 (25%)

explore in graph

All cited sources (12)

Entries about Icarus Salesforce OAuth extortion (3)

2026-06-29 · view entry permalink →

NOTABLE

Looking ahead — 2026-W26

A focused, justified list — items already in motion, not predictions.

  • ShinyHunters PeopleSoft notifications are still landing — expect more named European education and public-finance victims. GTIG has notified ~100 organisations (68% higher education) and NAIC is the fresh high-profile case; patch internet-reachable PeopleSoft and hunt /PSEMHUB/ and /PSIGW/HttpListeningConnector. (Google GTIG; daily 06-28)
  • FortiBleed is not a one-and-done credential reset — full AD domain takeover is now confirmed at a NATO-aligned contractor. Finish session termination and credential rotation, then hunt for post-compromise AD persistence (Kerberos abuse, DCSync, DFS-backup exfiltration) rather than assuming the reset closed it. (CISA; daily 06-24)
  • The Klue/Icarus extortion surface is multiplying after the "resolution" — a second group is now extorting ~195 listed organisations. Any firm with a Klue/Salesforce integration should expect renewed extortion contact regardless of Icarus's stated data deletion; complete OAuth-grant revocation and CRM-egress monitoring. (SecurityWeek; daily 06-27)
  • CRA Single Reporting Platform go-live is ~75 days out (11 September); ENISA's dry-run schedule is due now. In-scope manufacturers — including Swiss exporters to the EU — should register and wire the 24/72-hour reporting flow into their PSIRT process before the obligation binds. (ENISA SRP)
  • EDPB Article 33 harmonised breach-notification template consultation closes 5 August. Still open with no in-window change; multi-jurisdiction breach-response owners have a closing window to comment before the EDPB sets a mandatory-adoption timeline. (EDPB)
  • npm v12 will disable install scripts by default — the week's Miasma worm wave is the reminder to audit CI now. Miasma's postinstall-and-SessionStart-hook propagation is exactly the kill chain --ignore-scripts / npm v12 defaults neutralise; inventory pipelines and AI-coding-tool hook configs that rely on build scripts. (Socket; daily 06-27)
  • libssh2 CVE-2026-55200 has a public PoC and an upstream fix commit, but tagged releases lag across the binding ecosystem — track the embedded-dependency fix pipeline. Inventory appliances, tooling and language bindings that ship libssh2 and chase each vendor's release rather than assuming a single library bump closes it. (NCSC-NL; daily 06-28)
  • Scattered Spider TfL sentencing is set for 16 July. First UK court outcome on the campaign; the vishing/social-engineering TTP precedent is directly relevant to European transport and public-sector identity-desk hardening. (UK NCA; daily 06-23)
outlook29 Jun 00:21Zmulti-sourceOpen finding ↗

2026-06-25 · view entry permalink →

NOTABLEupdate

Klue/Icarus Salesforce OAuth breach — BeyondTrust and LastPass added to the named-victim list

UPDATE · originally covered Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed (2026-06-21)

BeyondTrust and LastPass have both disclosed that business-contact and sales-related data was exfiltrated from their Salesforce environments via the compromised Klue integration, pushing the confirmed named-victim count past 14 (SecurityWeek, 2026-06-24 · Help Net Security, 2026-06-24).

The BeyondTrust exposure is the notable delta: a privileged-access-management vendor losing its CRM contact and support-case data to a SaaS supply-chain compromise illustrates that security-vendor customer lists are a deliberate targeting priority for the Icarus extortion crew. LastPass states customer vaults were not affected. Salesforce had already disabled the Klue Battlecards connection on 17 June (The Hacker News, 2026-06-19). Any organisation receiving a Salesforce "Connected App disabled" notice for Klue should treat it as an incident trigger and audit Event Log File ApiTotalUsage / ApiAnomalyEventStore records for bulk REST API reads in the June 11–17 window (T1199, T1528, T1213.003).

BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance

SecurityWeek

an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass

Help Net Security citing LastPass
incident25 Jun 04:59Zmulti-sourceOpen finding ↗

2026-06-24 · view entry permalink →

NOTABLEupdate

8x8 confirms Klue/Icarus Salesforce exfiltration in an SEC 8-K Item 1.05 filing

UPDATE · originally covered Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed (2026-06-21)

US cloud-communications provider 8x8 (NASDAQ: EGHT) filed a Form 8-K Item 1.05 on 2026-06-23 disclosing that an unauthorised party accessed its Salesforce environment on 2026-06-11/12 via a third-party integration — the Klue competitive-intelligence platform — the OAuth-integration vector behind the Icarus extortion campaign already tracked in prior briefs (SEC EDGAR — 8x8 Form 8-K, 2026-06-23).

The filing states the accessed data is limited to contract information, internal sales notes and business contact data (names, business emails, phone numbers, mailing addresses). As a publicly-listed company's mandatory material-incident disclosure, it is the formal confirmation that 8x8 is a named Klue-integration victim, extending the campaign's confirmed-victim list.

Defender takeaway for anyone running SaaS-to-Salesforce OAuth integrations (including EU public-sector users of competitive-intel tooling): audit Connected Apps in Salesforce Setup → App Manager for unexpected or stale OAuth grants, scope connected-app permissions to least privilege, and monitor EventType=OAuthToken in Salesforce Event Monitoring for anomalous token use (T1078.004 Valid Accounts: Cloud, T1550.001 token abuse).

incident24 Jun 05:11Zsingle-sourceOpen finding ↗