Klue Hack Pushes Salesforce Integrations Into Supply-Chain Spotlight
Klue says attackers used a compromised legacy integration credential to obtain OAuth tokens for connected platforms including Salesforce, widening the incident across several affected customers.
The Klue breach is becoming a wider SaaS supply-chain incident, with multiple security and software companies saying data was reached through integrations tied to Salesforce and other connected services.
Table Of Content
SecurityWeek reported Monday that at least nine organizations have publicly acknowledged impact from the attack on Klue, a market intelligence platform used by sales and go-to-market teams. The disclosures include cybersecurity firms such as HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium, as well as Insurity and Sprout Social.
The important detail is not just the number of affected customers. It is the path. Klue says the attacker used a compromised legacy credential associated with an integration service, obtained OAuth tokens, and then accessed data in connected customer environments, including Salesforce. That makes the incident a reminder that SaaS integrations can carry the same blast-radius problem as traditional software supply chains.
What Klue says happened
In its public incident update, Klue says it identified unauthorized activity on June 12 affecting part of its integration infrastructure. The company says the attacker gained access through a compromised legacy credential tied to an integration service and used that access to obtain OAuth tokens used to connect Klue with third-party platforms, including Salesforce.
Klue says the incident was limited to affected third-party platforms based on its investigation so far, and that it has no evidence customer content stored inside the Klue platform was impacted. The company says it revoked affected credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, notified law enforcement, and engaged CrowdStrike to support the investigation and validate its response.
Those statements narrow the incident, but they do not make it small. A sales or market-intelligence integration often touches CRM records, account notes, contacts, opportunities, and other business context. When those connections are trusted across many customers, a single credential or token problem can become a cross-company incident.
Security vendors are treating it as a CRM data exposure
HackerOne said Klue’s OAuth integration with its Salesforce instance allowed an unauthorized party to access and copy a set of CRM data. The company described the exposed data as business relationship and sales activity information, including business contact information, sales account records, and opportunity records. HackerOne also said the impact did not extend to its products or infrastructure and that, under its data-segmentation policies, customer vulnerability data is not permitted in its CRM systems.
Gong said the incident originated with third-party integrator Klue, not Gong’s own products or systems. Gong said a subset of customers using the Klue integration may have had internal licensed user data accessed, including user names, business titles, and user emails, but said it had not identified direct impact to customer call recordings or transcripts. Gong said it revoked active access associated with the Klue integration, deactivated related tokens, blocked four potentially suspicious IP addresses, and blocked Klue API requests until further notice.
That pattern is consistent with SecurityWeek’s reporting: affected organizations are generally describing exposure in CRM or integration-linked data, while drawing a boundary around their own core products and infrastructure. The distinction matters for incident response because the immediate task is not only patching a vendor, but also understanding what data was replicated into the connected system and who can act on it.
Huntress points to the operational cleanup
Huntress said it was among the impacted organizations and framed the incident as a major supply-chain attack involving Salesforce data. Its public investigation notes that a threat actor named Icarus listed Klue on a leak site, while SecurityWeek reported that the actor threatened to publish information stolen from Klue customers’ Salesforce instances.
More practically, Huntress recommends reviewing indicators of compromise against logs from Salesforce, Klue, and other OAuth applications configured through Klue. It also recommends requesting missing logs from vendors when access logs are not available, considering session revocation for affected services, and reviewing email inboxes and spam folders for communications tied to the actor’s infrastructure or phrasing.
Those are useful response steps because OAuth integration incidents do not always end when one vendor disables a connector. Tokens, service accounts, active sessions, copied exports, and CRM records can all have separate lifetimes. Security teams need to verify what was accessed, where the same credentials or tokens were trusted, and whether attackers created follow-on phishing or social-engineering paths using the business contact data.
Why the incident matters beyond Klue
The Klue breach is a live example of a common enterprise tradeoff. Teams connect specialized SaaS tools to Salesforce, Gong, marketing systems, support tools, and collaboration platforms because that integration saves time and gives vendors useful context. But every integration adds a new credential-management, logging, and data-minimization requirement.
For customers, the lesson is to inventory connected apps as first-class security dependencies. That means knowing which vendors hold OAuth tokens, which scopes those tokens grant, which logs customers can retrieve without delay, how quickly a connector can be disabled, and what business data is exposed if a vendor account is compromised. It also means keeping sensitive operational data out of CRM fields that do not need it.
For vendors, the incident raises the bar for legacy credential cleanup and customer-visible incident tooling. Klue’s own update says the attacker used a compromised legacy credential associated with an integration service. That phrasing should push other SaaS providers to audit old service credentials, rotate long-lived tokens, tighten deployment controls, and make sure customers can quickly see which third-party platforms are connected.
The immediate story is still developing as companies publish their own notices. The durable lesson is already clear: SaaS integrations are part of the attack surface. If a connector can read CRM data across many customers, it deserves the same monitoring, segmentation, revocation planning, and vendor-risk scrutiny as code shipped into production.








No Comment! Be the first one.