ctipilot.ch
← Back to Daily brief 2026-06-25
NOTABLEupdateincident

Klue/Icarus Salesforce OAuth breach — BeyondTrust and LastPass added to the named-victim list

discovered 2026-06-25 04:59 UTCrun 2026-06-25-da7fbd233 sourcesmulti-source

UPDATE · originally covered Klue OAuth-token breach — victim list grows, CRM-API abuse chain detailed (2026-06-21)

BeyondTrust and LastPass have both disclosed that business-contact and sales-related data was exfiltrated from their Salesforce environments via the compromised Klue integration, pushing the confirmed named-victim count past 14 (SecurityWeek, 2026-06-24 · Help Net Security, 2026-06-24).

The BeyondTrust exposure is the notable delta: a privileged-access-management vendor losing its CRM contact and support-case data to a SaaS supply-chain compromise illustrates that security-vendor customer lists are a deliberate targeting priority for the Icarus extortion crew. LastPass states customer vaults were not affected. Salesforce had already disabled the Klue Battlecards connection on 17 June (The Hacker News, 2026-06-19). Any organisation receiving a Salesforce "Connected App disabled" notice for Klue should treat it as an incident trigger and audit Event Log File ApiTotalUsage / ApiAnomalyEventStore records for bulk REST API reads in the June 11–17 window (T1199, T1528, T1213.003).

BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance

SecurityWeek

an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass

Help Net Security citing LastPass
PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.