CTIPilot

Icarus Salesforce OAuth extortion

campaign · campaign:icarus-klue-salesforce-oauth

Icarus extortion campaign: a dormant Klue credential led to harvested OAuth tokens and bulk Salesforce CRM data theft across downstream customers.

Coverage timeline
1
first 2026-06-19 → last 2026-06-21
Peak priority
high
1 high
Sources cited
10
8 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
5
pinned v19.2 · see below

ATT&CK techniques

5 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×1

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Collection TA0009

T1213.003Data from Information Repositories: Code Repositories×1

Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate software builds. They may be hosted internally or privately on third party sites such as Github, GitLab, SourceForge, and BitBucket. Users typically interact with code repositories through a web application or command-line utilities such as git.

Evidence: 2026-06-21/klue-oauth-token-breach-victim-list-grows-crm-api-abuse-chai · ATT&CK page ↗

Story timeline

  1. 2026-06-21Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed
    active-threats

Where this entity is cited

  • active-threats1

Source distribution

  • securityweek.com3 (30%)
  • bleepingcomputer.com1 (10%)
  • helpnetsecurity.com1 (10%)
  • huntress.com1 (10%)
  • klue.com1 (10%)
  • sec.gov1 (10%)
  • techcrunch.com1 (10%)
  • thehackernews.com1 (10%)

explore in graph

Entries about Icarus Salesforce OAuth extortion (1)

2026-06-21 · view entry permalink →

HIGHupdated

Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed

UPDATE (originally covered 2026-06-19): The Klue compromise first covered on 2026-06-19 (Icarus obtaining a legacy Klue credential) now has a named, growing victim list and a documented post-access technique. Klue confirms the attacker harvested customer-provisioned OAuth tokens for connected platforms (principally Salesforce, plus Gong, HubSpot, SharePoint and others) and used them to query customer CRM instances directly (Klue, 2026-06-19).

Huntress forensics show the stolen tokens were used to hit Salesforce REST endpoints at /services/data/v59.0/query/<STRING> with a python-urllib User-Agent, anomalous in a legitimate Klue-integration context (Huntress, 2026-06-18). Confirmed affected organisations now include Huntress, Recorded Future, Tanium, Jamf and Sprout Social; Icarus has publicly claimed the attack and is demanding contact via Session messenger (BleepingComputer, 2026-06-19). The chain (compromise an integration platform's legacy credential, harvest downstream OAuth tokens, query customer CRM APIs from the platform's legitimate IP range) bypasses perimeter controls. Detection surface: Salesforce Event Monitoring for a python-urllib API caller, unusual /services/data/v*/query/ volumes from non-user principals, and out-of-hours API sessions from unexpected source orgs. Hardening: audit and revoke OAuth grants to third-party SaaS vendors (especially inactive integrations), enforce IP restrictions on Salesforce connected-app policies, and scope integration-platform credentials so one compromised account cannot chain to every downstream tenant.

BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance

SecurityWeek

an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass

Help Net Security citing LastPass
Updaterun 2026-06-23-165387f6regionssourcestagsbody

At least nine Klue customers have now publicly confirmed Salesforce-CRM data impact from the 11–12 June Icarus intrusion: HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity and Sprout Social (SecurityWeek, 2026-06-22). Exposed data is sales-account and contact information (names, business emails, job titles, phone numbers and addresses) exfiltrated via OAuth tokens from a dormant Klue→Salesforce integration; the actor (Icarus, also tracked as UNC6395) had set a 22 June publication deadline.

The concentration of cybersecurity vendors in the victim list is the notable delta: contact data for security-operations staff at those firms' customers now sits in a threat-actor corpus and is prime material for precision spear-phishing aimed at security roles. The structural lesson is unchanged from first coverage, enumerate and revoke unused third-party OAuth grants in Salesforce (Setup → Identity → OAuth Usage), scope active grants to minimum-necessary objects, and alert via Salesforce Event Monitoring on a connected app pulling thousands of account records in a single short session.

Updaterun 2026-06-24-de656486entitiessectorssourcesbody

US cloud-communications provider 8x8 (NASDAQ: EGHT) filed a Form 8-K Item 1.05 on 2026-06-23 disclosing that an unauthorised party accessed its Salesforce environment on 2026-06-11/12 via a third-party integration, the Klue competitive-intelligence platform, the OAuth-integration vector behind the Icarus extortion campaign already tracked in prior briefs (SEC EDGAR, 8x8 Form 8-K, 2026-06-23).

The filing states the accessed data is limited to contract information, internal sales notes and business contact data (names, business emails, phone numbers, mailing addresses). As a publicly-listed company's mandatory material-incident disclosure, it is the formal confirmation that 8x8 is a named Klue-integration victim, extending the campaign's confirmed-victim list.

Defender takeaway for anyone running SaaS-to-Salesforce OAuth integrations (including EU public-sector users of competitive-intel tooling): audit Connected Apps in Salesforce Setup → App Manager for unexpected or stale OAuth grants, scope connected-app permissions to least privilege, and monitor EventType=OAuthToken in Salesforce Event Monitoring for anomalous token use (T1078.004 Valid Accounts: Cloud, T1550.001 token abuse).

Updaterun 2026-06-25-da7fbd23evidencesectorssourcesbody

BeyondTrust and LastPass have both disclosed that business-contact and sales-related data was exfiltrated from their Salesforce environments via the compromised Klue integration, pushing the confirmed named-victim count past 14 (SecurityWeek, 2026-06-24 · Help Net Security, 2026-06-24).

The BeyondTrust exposure is the notable delta: a privileged-access-management vendor losing its CRM contact and support-case data to a SaaS supply-chain compromise illustrates that security-vendor customer lists are a deliberate targeting priority for the Icarus extortion crew. LastPass states customer vaults were not affected. Salesforce had already disabled the Klue Battlecards connection on 17 June (The Hacker News, 2026-06-19). Any organisation receiving a Salesforce "Connected App disabled" notice for Klue should treat it as an incident trigger and audit Event Log File ApiTotalUsage / ApiAnomalyEventStore records for bulk REST API reads in the June 11–17 window (T1199, T1528, T1213.003).

Updaterun 2026-06-27-40e791d4prioritysourcesbody

Roughly two dozen companies have now publicly notified customers of the Klue–Salesforce OAuth-integration breach, up from eleven on June 25, with newly named EU-domiciled victims including Germany's Lucanet and Link11 alongside Blackbaud, Deel, Camunda and Tines (SecurityWeek, 2026-06-26).

Klue reportedly told customers that the attacker ("Icarus") was itself compromised and that the stolen dataset is now in the hands of a second, unnamed actor running an independent extortion campaign; Icarus's Tor leak site went offline (TechCrunch, 2026-06-25). The root cause is unchanged (a single over-privileged legacy OAuth integration credential granting bulk Salesforce access across ~195 customer orgs) reinforcing the standing action: audit and revoke dormant Connected Apps with export scopes, and alert on anomalous bulk ReportExport/API activity from integration service accounts.

incident21 Jun 04:55Zmulti-sourceOpen finding ↗