CARDS
CARDS
A compromised legacy credential in Klue integration infrastructure enabled OAuth-token access to connected Salesforce environments. The campaign is retained as a third-party SaaS supply-chain and CRM data-exposure scenario, with Icarus included as a source-bound analytical lead that requires deconfliction from other public actor reporting.
Last updated Jul 12, 2026, 2:48 PM EDT
Evidence Boundary
Bottom Line Up Front
A compromised legacy credential in Klue integration infrastructure enabled OAuth-token access to connected Salesforce environments. The campaign is retained as a third-party SaaS supply-chain and CRM data-exposure scenario, with Icarus included as a source-bound analytical lead that requires deconfliction from other public actor reporting.[1][1][2]
Potential access to Salesforce business and contact data in connected customer environments; product-platform impact must be scoped independently for each organization.[1][1][2]
Identify and disable affected connected applications, revoke and rotate OAuth tokens and legacy integration credentials, review Salesforce API and event logs, and validate downstream data exposure against primary disclosures and local telemetry.[1][1][2]
Decision Summary
A compromised legacy credential in Klue integration infrastructure enabled OAuth-token access to connected Salesforce environments. The campaign is retained as a third-party SaaS supply-chain and CRM data-exposure scenario, with Icarus included as a source-bound analytical lead that requires deconfliction from other public actor reporting.
The retained record scopes this as saas supply chain / salesforce oauth-token abuse activity during June 2026. Potential access to Salesforce business and contact data in connected customer environments; product-platform impact must be scoped independently for each organization.[1][1][2]
Identify and disable affected connected applications, revoke and rotate OAuth tokens and legacy integration credentials, review Salesforce API and event logs, and validate downstream data exposure against primary disclosures and local telemetry.[1][1][2]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the Klue/Salesforce OAuth incident mechanics; Moderate for Icarus as an analytical attribution lead pending organization-specific evidence and source deconfliction..[1][1][2]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
The Klue/Salesforce incident does not establish a Salesforce platform vulnerability or prove that Icarus caused every related event. Treat Icarus as an evidence-weighted analytical lead and validate with current source reporting and authorized telemetry.
Evidence Controls
IntelliOS
Citations