Icarus
Threat Actor Group
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Icarus threat actor group snapshot. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Decision Question | Which activity and public disclosures can be attributed to the Icarus label with source support, what trusted-integration and downstream exposure paths matter, and what should defenders validate first without overstating actor identity or victim impact? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is Icarus, what source-backed activity is tied to the label, how does it relate to Klue/Salesforce OAuth abuse, which victim claims are confirmed, and what should defenders do first? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Initial Observations | The source set supports Icarus as an emerging extortion actor label tied to Klue-originated OAuth-token abuse and downstream Salesforce CRM data theft. The strongest public evidence supports trusted SaaS integration abuse, Salesforce API data access, and extortion pressure, not a Salesforce platform vulnerability or classic file-encrypting ransomware. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary adds primary vendor detail for the compromised GitHub PAT, unauthorized integration-service code, credential collection, containment, and no-post-June-12 Klue-environment activity boundaries. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post freshly adds two-phase GitHub PAT and CI/CD precision: source-code download, second PAT discovery, credential testing, unauthorized build/deployment abuse, tampered production workload, and stored OAuth-token access. 30-Jul-2026 · Newly retained (>24h)Klue's restored-integrations update adds post-remediation availability and hardening status: Salesforce and Gong integrations were reinstated after CrowdStrike review, with static egress IP allowlisting, PKCE, tightened OAuth-token lifecycle policies, PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlist controls. 30-Jun-2026 · Newly retained (>24h)Newly retained (>24h) FINRA and ZeroFox sources strengthen financial-sector hunting guidance, suspicious infrastructure/user-agent leads, direct-email alias context, and the caveat that possible SLH association remains circumstantial. 15-Jul-2026 · Newly retained (>24h)Microsoft newly adds Storm-3138 nomenclature for Klue and broader ShinyHunters-associated Salesforce OAuth abuse context while preserving the no-Salesforce-platform-vulnerability boundary. [1, 2, 3, 4, 5, 6, 8, 9, 15, 28, 29, 30, 31, 34, 48, 50, 51] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
1-Topic
Icarus is an emerging data-theft and extortion actor label associated in public reporting with the Klue/Salesforce OAuth incident. In this brief, the topic is not simply whether Icarus is a mature actor name; it is whether source-backed reporting shows a repeatable operational pattern: compromised SaaS integration trust, OAuth-token-backed Salesforce access, CRM data collection, and extortion pressure against downstream organizations. [1, 3, 4, 5, 6, 8, 9]
The defensible framing is that attackers abused a trusted third-party integration path rather than exploiting Salesforce itself. Klue described unauthorized activity affecting integration infrastructure and OAuth tokens, while Salesforce stated the issue was limited to Klue's app connection and did not arise from a Salesforce platform vulnerability. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary newly adds that a compromised GitHub PAT was used to introduce unauthorized code into the integration service and collect third-party integration credentials, including Salesforce OAuth tokens. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post now refines the operational path as GitHub source-code access, second PAT discovery, credential testing, build/deployment-path abuse, and a tampered workload that enabled stored OAuth-token access. 30-Jul-2026 · Newly retained (>24h)Klue's July 27 primary update now adds that Salesforce and Gong integrations were reinstated after remediation review; treat that as current integration availability, not a change to the historical exposure model. [1, 2, 3, 5, 34, 50, 51]
The operational concern is broader than actor naming. Public victimology now includes direct notices and reporting across organizations such as Huntress, LastPass, Jamf, Recorded Future, HackerOne, BeyondTrust, Sprout Social, Pendo, 8x8, Link11, and additional Klue customers, with impact generally framed around Salesforce, CRM, sales, support, business-contact, or customer-relationship data. [4, 7, 15, 18, 19, 20, 21, 22, 23, 24, 25, 28, 29]
For defenders, the topic should drive action around OAuth app inventory, token revocation, Salesforce API telemetry, suspicious integration-account behavior, data-exposure scoping, and extortion evidence preservation. 03-Jul-2026 · Newly retained (>24h)Klue's remediation summary adds vendor-side hardening themes around PAT elimination, GitHub Apps or short-lived credentials, automated secret scanning, audit logging, SIEM centralization, EDR, CI/CD observability, and GitHub Actions allowlisting. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post freshly sharpens the control ask around source verification, runner restrictions, default-deny network controls, workload identity, refresh-token rotation or idle expiration, IP-range allow-listing, and dedicated low-privilege integration accounts where supported. 30-Jul-2026 · Newly retained (>24h)Klue's restored-integrations post newly adds static egress IP allowlisting with Salesforce/Gong, platform-wide PKCE, tightened OAuth token lifecycle policy, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlist controls. 30-Jun-2026 · Newly retained (>24h)FINRA's alert broadens response to Klue integrations with Salesforce, HubSpot, Gong, SharePoint, Zoom, Chorus, Clari, Google Drive, Slack, and other SaaS platforms. Attribution remains useful, but response should not wait for final confidence on whether Icarus overlaps with any other publicly named SaaS intrusion cluster. [3, 5, 26, 30, 34, 50, 51]
2-Persona / Audience Lens
This snapshot is written for threat intelligence teams, SaaS security owners, Salesforce administrators, IR teams, breach counsel, claims teams, and executives who need to understand whether Icarus represents an actor, a campaign, a Klue-specific incident, or a broader Salesforce/OAuth extortion pattern.
3-BLUF
- Icarus is best treated as an emerging data-theft/extortion actor or actor label tied in public reporting to the Klue/Salesforce OAuth-token supply-chain incident, not a long-established intrusion set with mature public attribution. 30-Jun-2026 · Newly retained (>24h)Newly retained (>24h) ZeroFox profiling supports an early observed window of late April to early May 2026 and financial motivation while keeping real-world operator identity unresolved. 15-Jul-2026 · Newly retained (>24h)Microsoft newly identifies the Klue incident as Storm-3138 activity inside broader ShinyHunters-associated OAuth-abuse tradecraft, which improves source deconfliction but does not by itself prove Icarus, UNC6395, Salesloft Drift, or ShinyHunters are interchangeable actor labels. [4, 5, 6, 8, 9, 31, 48]
- The operational pattern is SaaS trust abuse: compromise or abuse Klue integration infrastructure, obtain OAuth tokens for connected platforms, and query downstream Salesforce CRM data through a trusted integration path. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary newly clarifies the root path as a previously compromised GitHub PAT (personal access token) used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth tokens. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post freshly refines that path into source-code download, second PAT discovery, credential testing, unauthorized build/deployment abuse, and a tampered production workload that enabled stored OAuth-token access. 30-Jul-2026 · Newly retained (>24h)Klue's July 27 restoration update newly changes the integration-status picture: Salesforce and Gong integrations were reinstated after CrowdStrike-supported remediation review, with static egress IP allowlisting, platform-wide PKCE, tightened OAuth token lifecycle policy, PAT elimination, centralized monitoring, and runtime network filtering added. [1, 2, 3, 5, 34, 50, 51]
- Salesforce publicly framed the issue as limited to Klue's app connection, not a Salesforce platform vulnerability; that distinction matters for legal scoping and customer communications. [2, 8]
- Real-world exposure includes confirmed downstream organizations such as Huntress, LastPass, Jamf, and Recorded Future; 25-Jun-2026 · Addedthe monitoring run newly retained direct notices or filings for HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8. 27-Jun-2026 · Freshly reported (<24h)Freshly reported (<24h) SecurityWeek reporting now describes roughly two dozen Klue customers with customer notifications and adds AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines to the public-notice picture. 02-Jul-2026 · Newly retained (>24h)Newly retained direct notices add Saviynt and LogicMonitor/Catchpoint as additional organization-specific boundary sources. 05-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) Postman adds a direct Salesforce customer contact / sales-information exposure boundary, Gong non-customer-data-access caveat, and core-platform-services exclusion. 06-Jul-2026 · Newly retained (>24h)Newly retained (>24h) Deel and Insurity direct notices add business-contact/commercial CRM exposure, limited personal-data-in-CRM and active-secrets-in-CRM caveats, and platform/product/infrastructure non-impact boundaries. 08-Jul-2026 · Newly retained (>24h)Newly retained (>24h) OneTrust, Tines, and Thinkproject direct notices add CRM-related Salesforce, support-adjacent, UAT CRM, and product/platform non-impact boundaries. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update adds completed technical investigation, validated scope, finalized containment/remediation, no exposure beyond OneTrust's Salesforce environment after June 12 containment, and ongoing governance/compliance review. 08-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) Cresta, AlertMedia, and ABBYY trust-center notices add direct Salesforce/CRM impact boundaries and product, infrastructure, network, technology, or customer-data non-impact statements. 09-Jul-2026 · Freshly reported (<24h)Freshly reported (<24h) Snyk adds direct forensic-closure scoping: business CRM data only, direct impacted-customer notification, and no evidence of Snyk platform or sensitive-data impact. 10-Jul-2026 · Newly retained (>24h)Newly retained (>24h) SentinelOne public partner-update coverage adds Salesforce-only containment via Klue API integration, independently verified forensic completion, no lateral movement, and no core product, cloud infrastructure, production environment, or service impact. 12-Jul-2026 · Newly retained (>24h)Newly retained (>24h) Camunda and Tanium direct notices add Camunda standard business-contact/account CRM-only scoping with support-data exclusion and Tanium Salesforce sales-account/business-contact scoping with support, password, customer-security-data, product, and cloud-infrastructure exclusions. 26-Jul-2026 · Newly retained (>24h)Newly retained (>24h) Blackbaud direct trust-center notice adds ongoing-investigation status, no substantive July 22 update, and no known product, business-operations, or customer-service impact. 16-Aug-2026 · Newly retained (>24h)Newly retained (>24h) Betterment's Mass.gov notice-letter PDF adds a financial-services downstream boundary: Klue Labs sales-vendor access to a Salesforce database containing Betterment data, name/SSN file exposure, no Betterment computer-system access, and two years of Kroll identity monitoring. 20-Aug-2026 · Newly retained (>24h)Newly retained (>24h) ControlUp's direct notice adds ControlUp Salesforce business-data exposure through Klue's integration and product, production-environment, and infrastructure non-impact boundaries. Direct notices generally frame Salesforce/CRM, sales, support, or business-contact exposure rather than core product compromise. [4, 7, 8, 9, 15, 18, 19, 20, 21, 22, 23, 24, 25, 28, 29, 32, 33, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 49, 52, 53]
- 18-Aug-2026 · Newly retained (>24h)Thinkproject's August 12 status closure is a source-backed, organization-specific investigation update: Thinkproject says the Klue breach investigation has concluded, it is not aware of misuse of affected data, and monitoring continues. This does not close other victims' reviews or change Icarus attribution, Salesforce platform-vulnerability boundaries, or UNC6395/Salesloft Drift deconfliction. [40]
- Defenders should prioritize OAuth token revocation, connected-app review, Salesforce API/query telemetry, anomalous integration-account behavior, extortion communications, and data-exposure scoping. 26-Jun-2026 · Newly retained (>24h)Newly retained (>24h) practitioner analysis further emphasizes OAuth app inventory, risky-scope review, blast-radius mapping, centralized revocation, and persistence checks for new OAuth apps, admin accounts, or webhooks. 30-Jun-2026 · Newly retained (>24h)FINRA adds member-firm guidance to inspect REST API activity, OAuth token-use deviations, high-volume queries, suspicious IPs, and extortion attempts. 15-Jul-2026 · Newly retained (>24h)Microsoft adds Salesforce RTEM, connected-application attribution, high-privilege and unused app posture, app risk scoring, and CloudAppEvents hunting pivots for this class of abuse. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post freshly adds CI/CD boundary validation, GitHub Apps or workload identity, default-deny deployment networking, OAuth refresh-token rotation or idle expiration, IP-range allow-listing, and low-privilege integration-account review to the vendor-control checklist. 30-Jul-2026 · Newly retained (>24h)Klue's restored-integration update adds vendor-side control expectations for re-enablement, but customers still need their own historical data-access and exposure scoping. [1, 3, 5, 26, 30, 48, 50, 51]
4-Executive Summary
Icarus is currently best understood as a relatively new extortion actor label tied to Salesforce data theft through compromised SaaS integration trust. Public reporting around the Klue incident says attackers gained access to Klue integration infrastructure through a compromised legacy credential, obtained OAuth tokens used to connect Klue with third-party platforms including Salesforce, and used those tokens to access data in connected customer environments. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary newly clarifies that the access involved a previously compromised GitHub PAT used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. [1, 3, 4, 5, 6, 8, 34]
The incident is important because it bypasses the mental model that "the customer's Salesforce was hacked" or that an employee clicked a phish. The more precise model is third-party SaaS supply-chain access: a trusted app connection had access, the token represented that trust, and attackers used it to query CRM data through legitimate Salesforce APIs until the token and integration path were disabled. Salesforce stated the issue was limited to Klue's app connection and did not arise from a Salesforce platform vulnerability. [2, 3, 5]
Real-world examples make the risk concrete. Huntress publicly disclosed that CRM data such as business contacts, price quotes, sales communications, and competitive reports were impacted, while LastPass later confirmed customer-support and business-contact data exposure through Salesforce and stated that password vaults and core services were not affected. 25-Jun-2026 · AddedThe Icarus AI Monitoring Agent newly retained direct notices from HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8, further supporting the same boundary: Salesforce/CRM or sales-context data exposure through the Klue integration, not proof of core product compromise. [4, 7, 8, 20, 21, 22, 23, 24, 25]
27-Jun-2026 · Freshly reported (<24h)Fresh victimology reporting now puts the public notification set at roughly two dozen Klue customers and adds AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines to the public-notice picture. 27-Jun-2026 · Newly retained (>24h)The newly retained Link11 direct notice confirms certain Salesforce CRM business-contact and sales-related data exposure while excluding Link11 core systems, products, operational security infrastructure, and customer systems. [28, 29]
02-Jul-2026 · Newly retained (>24h)Newly retained (>24h) direct-notice coverage adds LogicMonitor/Catchpoint, which confirmed unauthorized access to Catchpoint's Salesforce environment and business relationship / sales activity data exposure while excluding LogicMonitor's primary Salesforce environment and production, monitoring, credential, payment, and operational customer data. 02-Jul-2026 · Newly retained; undatedSaviynt's Trust Portal notice is newly retained with no visible page-publication date and limits potential impact to certain Salesforce sales data while excluding Saviynt products, services, and customer data in Saviynt products. [32, 33]
05-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) direct-notice coverage now adds Postman's Security & Trust Portal notice, which confirms customer contact and sales information exfiltration from Salesforce via the compromised Klue service account between June 11-12, while stating customer data was not accessed from Gong and Postman core platform services remained secure and were not impacted. [35]
06-Jul-2026 · Newly retained (>24h)Newly retained (>24h) direct-notice coverage adds Deel and Insurity. Deel confirmed a compromised Klue connection exposed business contact and commercial CRM information plus a very limited amount of personal data synced to CRM, while saying the Deel platform itself was not involved. Insurity confirmed suspicious Klue connected-app activity, cloud/product/infrastructure non-impact, CRM business-contact exposure, and a very limited set of active credentials/secrets within CRM data that were rotated or reset. [36, 37]
08-Jul-2026 · Newly retained (>24h)Newly retained (>24h) direct-notice coverage adds OneTrust, Tines, and Thinkproject. OneTrust described Klue Battlecards OAuth abuse against CRM-related Salesforce data and support-email-related records while excluding customer OneTrust platform data, tenants, passwords, and payment-card data. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update newly adds completed technical investigation, validated scope, finalized containment/remediation, no evidence of exposure beyond OneTrust's Salesforce environment after June 12 containment, and ongoing governance/compliance review. Tines' July 1 update completed its review and limited impact to Salesforce CRM business information, with a small number of sensitive-information cases directly notified and no Tines customer environment, workflow, credential, secret, or token impact. Thinkproject scoped the incident to a Klue-authorized UAT CRM environment and business-contact/commercial information while excluding products and the customer product platform. 08-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible) Cresta, AlertMedia, and ABBYY trust-center notices add direct Salesforce/CRM impact boundaries and product, infrastructure, network, technology, or customer-data non-impact statements. [38, 39, 40, 41, 42, 43]
18-Aug-2026 · Newly retained (>24h)Newly retained (>24h) Thinkproject closure language adds a direct customer-specific endpoint to that row: the investigation has concluded, Thinkproject is not aware of misuse of the affected data, and monitoring continues. Treat that as a Thinkproject-only closure status, not as evidence that other Klue downstream customers have reached the same conclusion. [40]
09-Jul-2026 · Freshly reported (<24h)Freshly reported (<24h) direct-status coverage adds Snyk's July 8 forensic closure. Snyk said its Mandiant-assisted investigation was complete, the impact was limited to business CRM data, all impacted customers were notified directly, and no evidence of impact to the Snyk platform or sensitive data within it was found. [44]
This is closer to extortion-driven SaaS data theft than classic ransomware. Public reporting ties Icarus to leak-site pressure and extortion communications, but the source set does not show file-encrypting malware, network-wide ransomware deployment, or a direct Salesforce platform exploit. The defensible operational framing is therefore: valid SaaS trust was abused, CRM data was queried and exfiltrated, and victims then had to scope downstream exposure and extortion risk. [4, 6, 8, 9, 15]
03-Jul-2026 · Newly retained (>24h)Klue's July 1 CrowdStrike investigation summary adds containment and boundary detail without changing actor attribution: Klue says Salesforce notified it of suspected unauthorized third-party activity on June 12, Klue disabled affected GKE pods (Google Kubernetes Engine runtime workloads) and compromised GitHub PATs, rotated OAuth credentials, CrowdStrike did not identify evidence of threat-actor access outside systems related to the integration service, and there was no evidence of threat-actor activity in the Klue environment after June 12. [34]
30-Jul-2026 · Newly retained (>24h)Klue's July 27 restoration update newly changes the post-incident operations status: Salesforce and Gong reinstated Klue integrations in their marketplaces, and Klue said all integrations were again available for customers to enable after CrowdStrike's independent review of incident response and remediation work. Klue also reports static egress IP allowlisting with Salesforce and Gong, platform-wide PKCE, tightened OAuth token lifecycle policies, elimination of GitHub personal access tokens in favor of short-lived credentials, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlist controls. This supports a remediation and re-enablement milestone, but it does not erase the need for each affected customer to complete historical Salesforce/Gong exposure scoping and notification decisions. [50]
01-Aug-2026 · Freshly reported (<24h)Klue's July 31 CTO post freshly refines the mechanism behind that remediation story: Klue says the incident originated with a GitHub PAT, unfolded through source-code download, an additional PAT, credential testing, unauthorized build/deployment abuse, and a tampered production workload that enabled stored OAuth-token access, then was contained on June 12 with no CrowdStrike-identified attacker activity in Klue's environment after containment. Klue also frames CI/CD as a production security boundary and calls out GitHub Apps or workload identity, source verification, runner restrictions, default-deny network controls, refresh-token rotation or idle expiration, IP-range allow-listing, and least-privilege integration accounts where supported. This is Freshly reported (<24h) for the August 1 monitor run and changes root-cause precision, not actor identity, victim list, or the Salesforce platform-vulnerability boundary. [51]
26-Jun-2026 · Freshly reported (<24h)Freshly reported (<24h) status reporting adds a caveated live-extortion update: Klue reportedly told customers it remained in contact with Icarus, that Icarus said it was taking steps to delete data, and that the Icarus site appeared down, while a second unnamed actor claimed to have samples for a subset of customers and attempted direct extortion. This does not verify payment, operator identity, a complete data set, a confirmed 195-customer victim count, or full deletion of stolen data. [27]
30-Jun-2026 · Newly retained (>24h)Newly retained (>24h) FINRA and ZeroFox sources add actor-tradecraft and hunting precision: FINRA lists suspicious IPs and sender domains shared by companies, while ZeroFox adds suspicious API user agents, "mr bean" direct-email alias corroboration, and a first-observed late-April / early-May 2026 DLS footprint. ZeroFox's possible SLH association remains circumstantial because Icarus has not publicly acknowledged it. [30, 31]
15-Jul-2026 · Newly retained (>24h)Microsoft's July 13 research adds a source-backed comparator and nomenclature update: it describes mid-2025 to mid-2026 Salesforce abuse using OAuth consent and supply-chain paths associated with ShinyHunters tradecraft, identifies the June 2026 Klue incident as Storm-3138, and recommends Salesforce RTEM, connected-app attribution, app permission insight, high-privilege/unused-app review, risk scoring, and CloudAppEvents hunting. This improves deconfliction and detection guidance but does not merge Icarus with UNC6395/Salesloft Drift or prove a Salesforce platform vulnerability. [48]
5-Why It Matters
Icarus matters because it shows how one trusted SaaS integration can become a multi-customer data-access path. For organizations, the exposure is not just technical: Salesforce records often contain customer contacts, support notes, opportunity details, pricing, renewal context, and relationship intelligence that can be used for extortion, phishing, or competitive harm.
Primary Risk
CRM Data Theft
Data can include contacts, sales notes, quotes, support records, and relationship context.
Control Plane
OAuth Trust
The integration token can act like the trusted app until revoked or disabled.
Business Impact
Extortion
Public reporting ties the activity to leak-site pressure and victim communications.
6-Profile / Snapshot
Synced Actor Record
This actor record is shared by the Threat Actor Cards directory, the Icarus profile page, and the Icarus Flash Threat Intel Brief so identity, aliases, source boundaries, ATT&CK mapping, and IntelliOS product links stay aligned. The linked actor-card profile is Icarus Threat Actor Profile.
| Synced Field | Canonical Actor-Card Value | Flash Brief Use |
|---|---|---|
| Identity | Icarus / Emerging data-theft and extortion actor label tied to Klue/Salesforce OAuth-token abuse | Controls the actor name, headline framing, and entity-type language. |
| Aliases | Icarus hackers, Icarus extortion group, mr bean | Limits alias language to retained source-backed names and contact markers. |
| Source Boundary | Icarus is source-backed for the Klue-linked extortion/data-theft activity. UNC6395 is source-backed for the earlier Salesloft Drift Salesforce OAuth campaign; IntelliOS treats that as adjacent comparator context, not a proven Icarus alias. | Prevents comparator actors, related campaigns, or ambiguous labels from being treated as automatic aliases. |
| Targeting | SaaS, Cybersecurity, CRM / sales operations, Enterprise software | Keeps sector, surface, and affected-data language aligned with the searchable actor card. |
| Activity / ATT&CK | Trusted SaaS integration abuse, OAuth token theft, Salesforce API data collection, Leak-site and direct-email extortion; T1199 - Trusted Relationship, T1528 - Steal Application Access Token, T1078 - Valid Accounts, T1119 - Automated Collection, T1567 - Exfiltration Over Web Service | Keeps tactics, objectives, and ATT&CK mapping aligned across the card, detail page, and flash brief. |
| IOCs / Observables | 0 retained observable/context rows; no reported source count | Controls whether the flash brief republishes concrete observables or only cites source-count and behavioral hunting guidance. |
| Linked Products | Icarus Threat Actor Snapshot, Klue Campaign Threat Intel Brief, Salesloft Drift OAuth Comparator Brief | Keeps related PANDA products, campaign briefs, comparator briefs, and actor-profile links synchronized. |
| Attribute | Assessment | Sources |
|---|---|---|
| Entity Type | 30-Jun-2026 · Newly retained (>24h)Emerging data-theft and extortion actor label tied to Klue/Salesforce OAuth-token abuse; ZeroFox assesses Icarus as likely operationally immature, financially motivated, and first observed in late april to early may 2026 public dls footprint in zerofox reporting. | [4, 5, 8, 31] |
| Aliases / Contact Markers | Icarus hackers, Icarus extortion group, mr bean. 30-Jun-2026 · Newly retained (>24h)FINRA and ZeroFox both preserve the "mr bean" email alias as an extortion-communication marker, not a real-world identity. | [30, 31] |
| Icarus / UNC6395 Boundary | Icarus is source-backed for the Klue-linked extortion/data-theft activity. UNC6395 is source-backed for the earlier Salesloft Drift Salesforce OAuth campaign; IntelliOS treats that as adjacent comparator context, not a proven Icarus alias. | [9, 10, 11] |
| Target Pattern | Organizations whose SaaS integrations expose SaaS, Cybersecurity, CRM / sales operations, Enterprise software data through OAuth-connected applications. | [1, 3, 5] |
| Access Pattern | Abuse of trusted third-party integration credentials and OAuth tokens rather than a direct Salesforce platform exploit. | [1, 2, 3] |
| Objective | Bulk CRM data theft, direct extortion, leak-site pressure, and monetization of business-contact, sales, support, and relationship context. | [4, 6, 8, 9, 15, 31] |
| Unknowns | Public sources do not establish the real-world operator identity, nationality, complete infrastructure, or a proven relationship to UNC6395, ShinyHunters, Scattered Spider, SLH, or other Salesforce-focused intrusion labels. 30-Jun-2026 · Newly retained (>24h)ZeroFox notes possible SLH association signals from Telegram reposting and Session-contact overlap, but treats the relationship as inconclusive. 15-Jul-2026 · Newly retained (>24h)Microsoft's Storm-3138 label is retained as source-specific naming for Klue, not a resolved identity merge. | [3, 8, 9, 10, 11, 31, 48] |

7-Timeline of Known TA Group Activities
| Date / Period | Public Source Event | What It Means |
|---|---|---|
| August-September 2025 | Google Cloud / GTIG and FBI/IC3 described UNC6395 activity involving compromised Salesloft Drift OAuth tokens and Salesforce data theft. [10, 11] | Comparator event only: it shows the Salesforce/OAuth attack family and helps distinguish UNC6395 from the newer Icarus label unless a source directly merges them. |
| June 2026 | Klue disclosed unauthorized activity involving a compromised legacy credential associated with an integration service and OAuth tokens used to connect Klue to third-party platforms, including Salesforce. [1] | Establishes the source-backed access path for the Klue-linked incident. |
| June 2026 | Salesforce disabled the Klue app connection and stated the issue was limited to Klue's app connection, not a Salesforce platform vulnerability. [2, 8] | Sets the platform-vulnerability boundary and explains why connected-app review is central to response. |
| June 2026 | ReliaQuest and Datadog published practitioner analysis describing OAuth-token abuse, Salesforce REST API querying, automated collection behavior, and detection opportunities. [3, 5] | Provides the technical and forensic basis for hunting beyond executive-level breach notices. |
| June 2026 | Huntress disclosed its own Salesforce data impact and published an investigation tying the activity to Icarus through extortion communications and leak-site context. [4] | Connects the actor label to a real downstream victim disclosure and concrete CRM-data impact. |
| June 18, 2026 | BleepingComputer reported the Klue OAuth breach was linked to Icarus Salesforce data-theft attacks. [6] | Publicly amplified the Icarus label and the Klue/Salesforce supply-chain framing. |
| June 19, 2026 | BleepingComputer reported that Icarus claimed the attack and that the victim list was growing, naming additional downstream notices. [9] | Supports the public-claim and multi-victim dimension, while still requiring primary notice review per organization. |
| June 23, 2026 | 25-Jun-2026 · AddedLastPass confirmed a Klue-linked incident affecting business-contact, CRM, support-case, and sales-related data while stating vaults, products, services, and infrastructure were not affected. [7, 24] | Shows why CRM exposure can be serious even when the victim's core product or vault system is not compromised. |
| June 22-23, 2026 | 25-Jun-2026 · AddedPendo published a direct customer notice and 8x8 filed an SEC Form 8-K describing Klue-linked Salesforce CRM access and exfiltration, with both preserving product or operational boundary language. [23, 25] | Adds direct customer/regulatory evidence for the downstream victim-disclosure pattern already visible in media reporting. |
| June 24, 2026 | SecurityWeek reported additional disclosed victims and roughly 15 publicly emerging Klue/Salesforce incident victims. [15] | Provides the latest retained public-source snapshot of victim disclosures and scale. |
| June 25, 2026 | 26-Jun-2026 · Freshly reported (<24h)TechCrunch reported, based on a Klue customer update it said it viewed and verified with multiple sources, that Icarus told Klue it was taking steps to delete stolen customer data and that the Icarus site appeared down; the same report said a second unnamed actor claimed to have customer samples and was attempting direct extortion. [27] | Updates the live extortion-process picture while keeping second-actor possession, payment, operator identity, and claimed customer-count assertions qualified. |
| June 26, 2026 | 27-Jun-2026 · Freshly reported (<24h)SecurityWeek reported roughly two dozen Klue customers had notified customers of impact, named additional organizations including AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines, and noted Salesforce had not yet re-enabled the Klue integration. [28] | Updates disclosed-victim scale and adds a Salesforce-integration-status check while retaining primary notices as controlling sources for exact impact. |
| June 25-26, 2026 | 27-Jun-2026 · Newly retained (>24h)Link11 published a direct CRM-impact notice, and Jamf updated its notice to say threat-actor activity was isolated to June 11 and limited to Salesforce data accessed through Klue credentials. [18, 29] | Adds direct-notice precision for impact boundaries and reinforces the no-lateral-movement / no-core-system-impact pattern. |
| June 22 and June 26, 2026 | 06-Jul-2026 · Newly retained (>24h)Insurity's status notice and Deel's direct notice were newly retained. Insurity added CRM business-contact exposure and a very limited active-credentials/secrets finding inside CRM data; Deel added business-contact/commercial CRM exposure and a very limited personal-data-in-CRM caveat. [36, 37] | Adds primary victim-specific scoping detail without changing actor attribution, Salesforce platform-vulnerability language, or UNC6395 comparator treatment. |
| June 26, 2026 | 30-Jun-2026 · Newly retained (>24h)FINRA published a Klue OAuth/Salesforce exfiltration alert and ZeroFox published an Icarus intelligence profile. FINRA added suspicious IP and sender-domain indicators plus member-firm guidance; ZeroFox added first-observed timing, R&DE assessment, "mr bean" alias corroboration, DLS/direct-email tradecraft, and caveated SLH-association context. [30, 31] | Adds source-backed hunting and actor-profile detail without changing the Salesforce platform-vulnerability boundary or merging Icarus with UNC6395/SLH. |
| June 26, 2026 / undated | 02-Jul-2026 · Newly retained (>24h)LogicMonitor published a June 26 direct notice for Catchpoint Salesforce exposure. 02-Jul-2026 · Newly retained; undatedSaviynt's Trust Portal notice was newly retained with no visible page-publication date. Both reinforce organization-specific Salesforce or sales-data boundaries. [32, 33] | Adds direct customer-notice precision for two additional downstream organizations without changing actor attribution or the Salesforce platform-vulnerability boundary. |
| June 26-27, 2026 | 20-Aug-2026 · Newly retained (>24h)ControlUp's direct notice was newly retained as older source-backed victimology. ControlUp said the Klue incident resulted in unauthorized access to certain business data in ControlUp's Salesforce environment through Klue's integration, while ControlUp's solutions, production environment, and infrastructure were not harmed or compromised. [53] | Adds ControlUp-specific direct-notice scoping without changing actor attribution, Salesforce platform-vulnerability language, or UNC6395/Salesloft Drift comparator treatment. |
| July 1, 2026 | 03-Jul-2026 · Newly retained (>24h)Klue published a CrowdStrike investigation summary describing a compromised GitHub PAT, unauthorized code in Klue's integration service, collection of third-party integration credentials including Salesforce OAuth tokens, June 12 Salesforce notification, affected GKE pod and PAT disablement, OAuth credential rotation, no identified access outside integration-service systems, and no Klue-environment threat-actor activity after June 12. [34] | Adds primary vendor root-cause and containment precision without changing the Salesforce platform-vulnerability boundary or merging Icarus with UNC6395. |
| July 5, 2026 monitor retrieval | 05-Jul-2026 · Newly retained; undatedPostman's Security & Trust Portal notice was newly retained with no visible page-publication date. Postman says customer contact and sales information was exfiltrated from Salesforce via the compromised Klue service account between June 11-12, customer data was not accessed from Gong, and core platform services were not impacted. [35] | Adds a direct customer-specific Salesforce/Gong boundary without changing actor attribution, Salesforce platform-vulnerability language, or UNC6395 comparator treatment. |
| June 18-July 10, 2026 | 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject direct notices were newly retained as older sources. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update was newly retained for completed technical investigation status, validated scope, finalized containment/remediation, no evidence of exposure beyond Salesforce after June 12 containment, and ongoing governance/compliance review. 18-Aug-2026 · Newly retained (>24h)Thinkproject's August 12 final update was newly retained for investigation-concluded status, no known misuse of affected data, and continuing monitoring. 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY trust-center notices were newly retained with no visible page-publication dates. Together they add direct Salesforce/CRM impact boundaries, response actions, and product/platform non-impact statements. [38, 39, 40, 41, 42, 43] | Moves multiple organizations from aggregate public-notice context into direct-notice scoping and adds Thinkproject-specific closure without changing actor attribution, Salesforce platform-vulnerability language, or UNC6395 comparator treatment. |
| June 18-July 10, 2026 | 12-Jul-2026 · Newly retained (>24h)Camunda Trust Center and Tanium direct notices were newly retained as older sources. Camunda's final update narrows impact to standard business-contact and account information held in Salesforce CRM, excluding support data. Tanium's notice confirms Salesforce CRM access affecting sales-account and business-contact information while excluding support information, passwords, customer security data, products, and cloud infrastructure. [46, 47] | Moves Camunda and Tanium from aggregate victimology into direct-notice scoping without changing actor attribution, Salesforce platform-vulnerability language, or UNC6395/Salesloft Drift comparator treatment. |
| July 8, 2026 15:26 UTC / 11:26 AM ET | 09-Jul-2026 · Freshly reported (<24h)Snyk resolved its Klue incident status after a Mandiant-assisted forensic investigation, limiting impact to business CRM data, stating all impacted customers were directly notified, and finding no evidence of impact to the Snyk platform or sensitive data within it. [44] | Adds direct customer forensic-closure precision without changing actor attribution, Salesforce platform-vulnerability language, or UNC6395/Salesloft Drift comparator treatment. |
| July 9, 2026 | 10-Jul-2026 · Newly retained (>24h)Secure ISS publicly shared SentinelOne's Klue partner-update context, stating SentinelOne's independently verified forensic investigation was complete, impact was contained entirely to Salesforce through the Klue API integration, no lateral movement into SentinelOne systems was found, and core products, cloud infrastructure, production environments, and services were not affected. [45] | Adds SentinelOne-specific scope and containment precision while preserving the per-victim boundary rule and Salesforce platform-vulnerability distinction. |
| July 13, 2026 | 15-Jul-2026 · Newly retained (>24h)Microsoft published Salesforce OAuth-abuse research that identifies the Klue incident as Storm-3138 activity, places it inside a broader ShinyHunters-associated tradecraft pattern, and adds Salesforce connected-app visibility, posture, risk-scoring, and hunting guidance. [48] | Adds source-specific actor nomenclature and expanded detection guidance without merging Icarus with UNC6395/Salesloft Drift or changing the Salesforce platform-vulnerability boundary. |
| July 27, 2026 | 30-Jul-2026 · Newly retained (>24h)Klue said Salesforce and Gong reinstated Klue integrations and that all Klue integrations were again available for customers to enable after CrowdStrike's independent response/remediation review. Klue also cited static egress IP allowlisting, platform-wide PKCE, tightened OAuth token lifecycle policies, PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlist controls. [50] | Adds a primary restoration and remediation milestone; it does not change actor attribution, Salesforce platform-vulnerability language, or organization-specific historical exposure boundaries. |
| July 31, 2026 | 01-Aug-2026 · Freshly reported (<24h)Klue published a CTO lessons-learned post that refines the incident path into GitHub PAT access, source-code download, second PAT discovery, credential testing, unauthorized build/deployment-path abuse, a tampered production workload, stored OAuth-token access, June 12 containment, and durable CI/CD, credential, OAuth, and evidence-sharing lessons. [51] | Freshly reported primary engineering precision; it strengthens root-cause and vendor-control analysis without changing attribution, victimology, or Salesforce platform-vulnerability boundaries. |
8-Public Victim / Disclosure Matrix
| Victim / Organization | Public Date | Reported Result | Boundary |
|---|---|---|---|
| Huntress | June 2026 | Confirmed Salesforce CRM data exposure, including business contacts, price quotes, sales communications, and competitive reports. [4, 8] | Huntress did not frame this as compromise of product telemetry or engineering systems. |
| LastPass | June 23, 2026 | 25-Jun-2026 · AddedDirect response confirmed standard business-contact and CRM data exposure, including customer names, phone numbers, email addresses, physical addresses, support-case data, and sales-related data. [7, 15, 24] | LastPass stated products, services, infrastructure, and password vaults were not affected. |
| HackerOne | June 19, 2026 | 25-Jun-2026 · AddedDirect notice confirmed unauthorized access and copying of a set of HackerOne Salesforce CRM data through Klue's OAuth integration. [20] | HackerOne stated products and infrastructure remained secure and that its preliminary forensic investigation found no indication that customer vulnerability data was accessed. |
| Jamf | June 18, 2026 | Direct notice described unauthorized access to data in Jamf's Salesforce instance through the Klue integration and warned that exposed data could support phishing or social engineering. 27-Jun-2026 · Newly retained (>24h)Jamf's June 26 update says CrowdStrike confirmed activity was isolated to June 11 and limited to Salesforce data accessed through Klue integration credentials. [18] | Jamf reported no evidence of lateral movement or access to other systems or credentials; use the Jamf notice for Jamf-specific categories and customer guidance. |
| Recorded Future | June 18, 2026 | Direct notice described Klue integration-layer impact, Salesforce OAuth-token exposure, and affected business data fields. [19] | Treat as business-data exposure through the integration path, not proof of Recorded Future platform compromise. |
| Sprout Social | June 2026 | 25-Jun-2026 · AddedDirect notice described access to Sprout Social Salesforce CRM data, potentially including business contact details, organizational/account information, and related commercial CRM records. [22] | Sprout Social stated product/platform data, connected social profiles or credentials, published or scheduled content, authentication passwords, platform API keys, and Salesforce Service Cloud were not affected. |
| BeyondTrust | June 18, 2026 | 25-Jun-2026 · AddedDirect advisory described business-contact and general sales-related customer information exposure in BeyondTrust's Salesforce CRM system through Klue. [15, 21] | BeyondTrust stated employee accounts, infrastructure, network, products, product cloud environments, software code, customer instances, and product/service delivery were not affected. |
| Pendo | June 22, 2026 | 25-Jun-2026 · AddedDirect notice said unauthorized access involved business/contact data within Pendo's Salesforce instance. [23] | Pendo stated customer product data, authentication credentials, technical data, and its product or service delivery platform were not accessed or compromised based on its investigation to date. |
| 8x8 | June 23, 2026 | 25-Jun-2026 · Added8x8's Form 8-K said a threat actor exploited the Klue integration connected to its Salesforce CRM and exfiltrated competitively sensitive information, fragmented contract/opportunity information, sales notes, and business contact details. [25] | 8x8 said the incident was isolated to Salesforce information accessible through Klue and, based on investigation to date, did not impact business operations, service capability, or information-system availability. |
| Link11 | June 25, 2026 | 27-Jun-2026 · Newly retained (>24h)Direct notice said attackers abused valid Klue integration credentials to query certain Link11 Salesforce CRM data, including business contact information, company/account information, and sales-related CRM information. [29] | Link11 stated core systems, products, operational security infrastructure, and customer systems were not affected, and said it revoked OAuth/API tokens for the integration. |
| Saviynt | No visible page publication date | 02-Jul-2026 · Newly retained; undatedDirect Trust Portal notice said Saviynt was one of the impacted Klue customers and that potential impact was limited to certain sales data stored within Saviynt's Salesforce instance. [32] | Saviynt stated there was no impact to Saviynt products or services, or customer data in Saviynt products. |
| LogicMonitor / Catchpoint | June 26, 2026 | 02-Jul-2026 · Newly retained (>24h)Direct notice confirmed unauthorized access to Catchpoint's Salesforce environment, with accessed data appearing limited to business relationship and sales activity data such as business contact information, account information, sales opportunities, quotes, and other CRM records. [33] | LogicMonitor stated its primary Salesforce environment was not impacted and excluded customer monitoring data, production systems data, authentication credentials, payment information, and other operational customer data. |
| ControlUp | June 26, 2026; updated June 27, 2026 | 20-Aug-2026 · Newly retained (>24h)Direct notice said the Klue incident resulted in unauthorized access to certain business data contained within ControlUp's Salesforce environment through Klue's integration. [53] | ControlUp stated its solutions, production environment, and infrastructure were not harmed or compromised; use ControlUp's notice only for ControlUp-specific impact and customer-notice boundaries. |
| Postman | No visible page publication date | 05-Jul-2026 · Newly retained; undatedDirect Security & Trust Portal notice confirmed customer contact data and sales information was exfiltrated from Postman's Salesforce environment via the compromised Klue service account between June 11-12. [35] | Postman stated customer data was not accessed from Gong and that core platform services remained secure and were not impacted. |
| Deel | Last Update June 26, 2026 | 06-Jul-2026 · Newly retained (>24h)Direct notice confirmed unauthorized access to business contact and commercial information in Deel's CRM through a compromised Klue connection, plus a very limited amount of personal data synced to CRM. [36] | Deel stated the incident did not involve the Deel platform itself; Deel disconnected the vendor, revoked access, removed older access tokens, and warned customers about payment-request and credential-sharing social engineering. |
| Insurity | Updated June 22, 2026 | 06-Jul-2026 · Newly retained (>24h)Direct status notice confirmed Salesforce notified Insurity of suspicious Klue connected-app activity and that Insurity's review found a very limited set of active credentials/secrets inside CRM data, which Insurity rotated or reset. [37] | Insurity stated its cloud, managed infrastructure, related systems, and products were not impacted; organizations without direct Insurity notice were told no secrets connected to them were impacted. |
| OneTrust | June 24, 2026; updated July 10, 2026 | 08-Jul-2026 · Newly retained (>24h)Direct notice said a compromised Klue Battlecards integration was used to access CRM-related Salesforce data, standard business contact information, related CRM fields, and records related to support emails. 19-Jul-2026 · Newly retained (>24h)The July 10 update newly used by this run says OneTrust completed its technical investigation, validated incident scope and impacted data, and finalized containment and remediation measures. [38] | OneTrust stated the integration was not customer-configured or connected to customer OneTrust tenants, and said there was no evidence that passwords, payment cards, customer data processed in the OneTrust platform, or customer tenants were exposed. The July 10 update says independent forensics found no evidence of exposure beyond OneTrust's Salesforce environment following June 12 containment; governance and compliance review remained ongoing. |
| Tines | Updated July 1, 2026 | 08-Jul-2026 · Newly retained (>24h)Tines' completed investigation limited impact to Salesforce CRM business information, including business/account contacts, opportunity and sales-related records, commercial communications, CRM activity records, and limited support-adjacent information. [39] | Tines stated no customer environments, workflows, automations, credentials, tokens, secrets, authentication systems, production systems, or customer workflow data were affected; a small number of sensitive-information cases were directly notified. |
| Thinkproject | Updated August 12, 2026 | 08-Jul-2026 · Newly retained (>24h)Status notice said Klue had authorized access to Thinkproject's UAT CRM environment through an integration and that exfiltrated data may include business contact information and certain commercial information. 18-Aug-2026 · Newly retained (>24h)Newly retained (>24h) August 12 closure language says Thinkproject's investigation concluded, no misuse of affected data is known, and monitoring continues. [40] | Thinkproject stated no products or services were affected and that its CRM system is separate from, and not connected to, the customer product platform. The no-known-misuse statement is Thinkproject-specific and should not be generalized across other victims. |
| Cresta | No visible page publication date | 08-Jul-2026 · Newly retained; undatedDirect trust-center notice said Cresta's Salesforce instance was impacted and that business contact information, contractual information, and email correspondence may have been exposed. [41] | Cresta stated it had not found any indication that its products or infrastructure were impacted. |
| AlertMedia | No visible page publication date | 08-Jul-2026 · Newly retained; undatedDirect trust-center notice said a threat actor used stolen OAuth tokens to export CRM data from Klue customers, including AlertMedia, and AlertMedia disabled Klue access, revoked access, and rotated third-party Salesforce integration credentials. [42] | AlertMedia stated no customer data within the AlertMedia platform or systems supporting its products was affected. |
| Camunda | Final update July 1, 2026; trust-center profile updated July 10, 2026 | 12-Jul-2026 · Newly retained (>24h)Direct Trust Center updates said the Klue incident was limited to Camunda's Salesforce CRM environment, and the final externally validated update narrowed exfiltrated data to standard business-contact and account information held in Salesforce CRM. [46] | Camunda's final update stated support data was not included; its earlier investigation-results update excluded Camunda 8 SaaS production, customer cluster data, the support ticketing platform, and related infrastructure. |
| ABBYY | No visible page publication date | 08-Jul-2026 · Newly retained; undatedDirect trust-center notice said the Klue breach impacted Salesforce data accessed through Klue's integration. [43] | ABBYY stated its network, products, and technology were not affected, and said it revoked affected credentials, disabled the integration, discontinued Klue use, and completed a security review. |
| Snyk | Resolved July 8, 2026 15:26 UTC / 11:26 AM ET | 09-Jul-2026 · Freshly reported (<24h)Snyk's status page said its Mandiant-assisted forensic investigation was complete and confirmed the Klue/Salesforce impact was limited to business CRM data. [44] | Snyk stated all impacted customers were notified directly and that no evidence of impact to the Snyk platform or sensitive data within it was found. |
| SentinelOne | July 9, 2026 | 10-Jul-2026 · Newly retained (>24h)Secure ISS's public write-up of SentinelOne's Klue partner update said SentinelOne completed an independently verified forensic investigation and that impact was contained entirely within SentinelOne's Salesforce environment via the Klue API integration. [45] | The write-up said no lateral movement into SentinelOne systems was found, core products, cloud infrastructure, production environments, and services were not affected, and data analysis remains ongoing for any separate direct notifications. |
| Tanium | June 18, 2026 | 12-Jul-2026 · Newly retained (>24h)Direct notice said an unauthorized party gained access to Tanium Salesforce data and that potentially compromised data included sales-account data, opportunity names and values, sales-related messaging, and business-contact information. [47] | Tanium stated support information, passwords, customer security data, products, and cloud infrastructure were not affected, and said no password or credential reset was needed because of this incident. |
| Blackbaud | June 24, 2026; updated July 22, 2026 | 26-Jul-2026 · Newly retained (>24h)Direct trust-center update said Klue notified Blackbaud of the incident and that, as of July 22, Blackbaud's investigation remained ongoing with no substantive public update. [49] | Blackbaud stated there was no known impact to Blackbaud products and no impact to business operations or its ability to serve customers; detailed incident documents and FAQs remain behind active-customer login. |
| Betterment | August 5, 2026 notice letter; retained August 16, 2026 | 16-Aug-2026 · Newly retained (>24h)Mass.gov's Betterment notice letter says Klue Labs Inc. was a vendor used by Betterment's sales team with access to a Salesforce database containing Betterment data, and that unauthorized access involved a file containing name and Social Security number. [52] | Betterment stated its computer systems were not accessed and offered two years of Kroll identity monitoring; do not infer product-system, brokerage, bank, account-access, credential, or raw stolen-data compromise beyond the notice text. |
| Additional disclosed or reported organizations | June 19-July 10, 2026 | Public reporting named or referenced Tanium, Gong, OneTrust, Snyk, SentinelOne, and others as affected or disclosing impact. 27-Jun-2026 · Freshly reported (<24h)SecurityWeek's June 26 update added AlertMedia, Blackbaud, Camunda, Cresta, Lucanet, Link11, and Tines to the public-notice picture and described roughly two dozen notified customers. 02-Jul-2026 · Newly retained (>24h)Newly retained direct notices add Saviynt and LogicMonitor/Catchpoint as source-backed organization-specific examples. 05-Jul-2026 · Newly retained; undatedPostman is now retained as a direct notice for Salesforce/Gong scoping. 06-Jul-2026 · Newly retained (>24h)Deel and Insurity moved from aggregate public-notice context into source-backed direct-notice rows. 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject moved from aggregate public-notice context into direct-notice rows. 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY were newly retained as direct notices with no visible page-publication date. 09-Jul-2026 · Freshly reported (<24h)Snyk moved from aggregate public-notice context into a direct status row with forensic-closure boundaries. 10-Jul-2026 · Newly retained (>24h)SentinelOne moved from aggregate public-notice context into a source-backed public partner-update row. 12-Jul-2026 · Newly retained (>24h)Camunda and Tanium moved from aggregate public-notice context into direct notice rows. 26-Jul-2026 · Newly retained (>24h)Blackbaud moved from aggregate public-notice context into a direct trust-center row. 16-Aug-2026 · Newly retained (>24h)Betterment moved into a direct regulator-hosted notice-letter row. 20-Aug-2026 · Newly retained (>24h)ControlUp moved into a direct notice row for Salesforce business-data exposure and product/production/infrastructure non-impact language. [9, 15, 28, 32, 33, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 49, 52, 53] | Do not assume identical data fields, materiality, notification posture, Salesforce integration use, investigation status, identity-monitoring posture, or product impact across organizations; Autodesk is retained as a non-impact caveat where it may not have used the Salesforce integration. |
| Leak-site-only names | June 2026 | Icarus leak-site claims and third-party lists may contain additional names beyond primary notices. 26-Jun-2026 · Freshly reported (<24h)TechCrunch also reported a second unnamed actor claimed to have samples for a subset of Klue customers and claimed a larger affected-customer count. 27-Jun-2026 · Freshly reported (<24h)SecurityWeek repeated the 195-customer allegation as alleged and noted no known extortion group other than Icarus appeared to have publicly claimed possession. [9, 15, 27, 28] | PANDA does not treat a name, count, sample possession claim, payment claim, or operator-identity claim as confirmed unless a primary notice or reliable corroborating reporting is retained. |
9-Associated Campaigns / Activity Clusters
| Campaign / Cluster | Relationship To Icarus | Core Tradecraft | Sources |
|---|---|---|---|
| Klue OAuth / Salesforce CRM data-theft campaign | Source-backed Icarus-associated campaign in this snapshot. | 03-Jul-2026 · Newly retained (>24h)Compromised GitHub PAT and unauthorized integration-service code, stolen OAuth tokens, Salesforce API querying, CRM/support/sales data theft, extortion and leak-site pressure. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post adds source-code download, second PAT discovery, credential testing, build/deployment abuse, tampered production workload, and stored OAuth-token access. 15-Jul-2026 · Newly retained (>24h)Microsoft identifies this Klue activity as Storm-3138. | [1, 3, 4, 5, 6, 8, 9, 15, 34, 48, 51] |
| Huntress/Icarus extortion communications | Sub-activity inside the Klue-linked incident, used as public attribution support. | 26-Jun-2026 · Freshly reported (<24h)Extortion communications, Session Messenger identifiers, leak-site context, CRM-data proof discussion, reported Icarus site-down/deletion claims, and second-actor direct-extortion claims that remain caveated. | [4, 9, 27] |
| Salesloft Drift / Salesforce OAuth data theft | Adjacent comparator, not proven to be Icarus in this retained source set. | Compromised Salesloft Drift OAuth tokens, Salesforce data theft, UNC6395 attribution, customer downstream scoping. | [10, 11] |
| Broader SaaS integration / CRM extortion pattern | Analytic pattern, not a single proven Icarus campaign. | 26-Jun-2026 · Newly retained (>24h)Trusted SaaS integration abuse, valid token use, CRM/customer data collection, leak-site or direct extortion pressure, and OAuth grant/blast-radius governance across connected SaaS apps. 30-Jun-2026 · Newly retained (>24h)FINRA adds connected-platform breadth beyond Salesforce, while ZeroFox adds public-file-hosting, DLS, direct-email, and API-user-agent context. 15-Jul-2026 · Newly retained (>24h)Microsoft adds a broader OAuth consent plus SaaS supply-chain compromise pattern across Salesforce-connected applications. | [3, 5, 10, 11, 15, 26, 30, 31, 48] |
10-How The Campaign Works
| Step | Source-Backed Activity | Defensive Focus |
|---|---|---|
| 1. GitHub PAT / CI-CD foothold | 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary says the threat actor leveraged a previously compromised GitHub PAT to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post freshly adds that the attacker downloaded source code, obtained an additional PAT, tested credentials, abused a build/deployment path, and deployed a tampered production workload. [34, 51] | Validate vendor credential lifecycle, PAT retirement, source verification, runner restrictions, default-deny deployment networking, CI/CD controls, integration-account MFA posture, and third-party incident notifications. |
| 2. OAuth token harvesting | The attacker used that access to obtain OAuth tokens that connected Klue to third-party platforms, including Salesforce. Review high-privilege OAuth grants and scopes such as API access and offline or refresh access where present. 26-Jun-2026 · Newly retained (>24h)Obsidian reinforces OAuth app inventory, risky-scope assessment, and tenant-to-integration blast-radius mapping. [26] | Revoke tokens, disable connected apps, rotate integration credentials, and preserve token and OAuth evidence before cleanup. |
| 3. Trusted app impersonation | 15-Jul-2026 · Newly retained (>24h)The stolen integration tokens allowed the attacker to act through a trusted SaaS application path rather than by logging in as a normal employee; Microsoft emphasizes that this kind of activity can evade traditional authentication-focused detections because it operates through approved OAuth applications and integrations. [48] | Inventory connected apps, verify least privilege, and compare integration behavior against baseline. |
| 4. Automated Salesforce extraction | ReliaQuest observed automated REST API queries, object enumeration, pagination, and Python-urllib user agents during Salesforce data theft. | Hunt Salesforce API activity, unusual query volume, unfamiliar IPs/user agents, QueryMore behavior, report exports, Bulk API, and object enumeration. |
| 5. CRM and support-data theft | Customer CRM data was accessed in connected environments. Treat support cases, notes, attachments, opportunity records, and sales communications as potentially sensitive because they can contain customer context or mistakenly pasted secrets. | Scope objects, fields, files, support tickets, comments, attachments, custom objects, and downstream notification duties. |
| 6. Extortion and leak pressure | 26-Jun-2026 · Freshly reported (<24h)Public reporting describes Icarus extortion communications, Session Messenger IDs, data leak-site claims, and now a caveated report of Icarus deletion/site-down status plus a second unnamed actor's direct-extortion claims. [4, 9, 27] | Preserve communications, engage counsel, prepare stakeholder messaging, and avoid unsupported attribution, payment, operator-identity, or complete-data-possession claims. |
| 7. Restoration / re-enablement | 30-Jul-2026 · Newly retained (>24h)Klue says Salesforce and Gong reinstated Klue integrations after CrowdStrike's remediation review and that Klue added static egress IP allowlisting, PKCE, tighter OAuth token lifecycle policy, PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlist controls. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post adds longer-term control expectations for GitHub Apps or workload identity, source verification, runner restrictions, default-deny network controls, refresh-token rotation or idle expiration, IP-range allow-listing, and low-privilege integration accounts. [50, 51] | Treat vendor re-enablement as a forward-looking control milestone; keep customer-specific historical exposure, token, object-access, and notification scoping separate. |
11-Term Glossary
| Term | Meaning | Why It Matters Here |
|---|---|---|
| OAuth token | A delegated authorization artifact that lets an application access resources without repeatedly asking for a username and password. | Stolen or abused tokens can let a trusted SaaS app query Salesforce data until revoked or expired. |
| GitHub PAT | A GitHub personal access token: a credential string used by a person, script, or integration to authenticate to GitHub without an interactive login. | Klue's CrowdStrike summary says a previously compromised GitHub PAT was used to introduce unauthorized code into Klue's integration service. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post adds that the attacker used GitHub PAT access for source-code download, second PAT discovery, credential testing, and build/deployment-path abuse. |
| GKE pod containment | GKE means Google Kubernetes Engine. A pod is a running workload unit; containment here means disabling affected runtime pods so suspect integration-service code could no longer run while credentials were rotated. | This clarifies the Klue/CrowdStrike statement that affected GKE pods and PATs were disabled on June 12. |
| Salesforce connected app | A Salesforce integration object that allows an external application to access Salesforce APIs through OAuth scopes and policies. | Klue's app connection is the key trust path in this incident. 15-Jul-2026 · Newly retained (>24h)Microsoft's newly retained guidance highlights connected-application attribution, granted OAuth scopes, high-privilege/unused-app posture, and risk scoring as governance priorities. |
| CRM data | Customer relationship management data such as accounts, contacts, opportunities, cases, notes, quotes, and sales communications. | CRM data can expose customer relationships, sales context, support history, and targeted-phishing material. |
| Battlecards | Competitive enablement content used by sales teams to compare products, handle objections, and position against competitors. | Klue is a competitive enablement platform; exposed sales/competitive material can have strategic value beyond basic PII. |
| Competitive enablement | An industry term for tooling, content, and workflows that help revenue teams understand competitors and win deals. | It explains why Klue integrations may touch sensitive Salesforce sales and customer context. |
| Leak-site extortion | A pressure tactic where actors list or threaten to publish stolen data unless a victim responds or pays. | Icarus is framed here as extortion-driven data theft, not classic file-encrypting ransomware. |
12-Forensic Indicators & Hunting
| Artifact | What To Look For | Why It Matters |
|---|---|---|
| Salesforce connected app | Klue Battlecards / Klue integration authorization, token issuance, disabled/revoked state, unexpected permissions. | Confirms whether the affected trust path existed in the tenant. |
| API activity | High-volume REST API query activity, `/services/data/.../sobjects`, `/query`, `QueryMore`, Bulk API, report export, or object enumeration. | Separates normal integration sync from bulk data retrieval. |
| Vendor CI/CD and token controls | 03-Jul-2026 · Newly retained (>24h)For vendor assurance, validate PAT elimination, GitHub App or short-lived credential migration, automated secret scanning, audit logging, CI/CD observability, SIEM centralization, EDR, runtime workflow filtering, and approved-action allowlisting. [34] | Klue's CrowdStrike summary shifts part of the control discussion from only OAuth revocation to upstream integration-service and software-delivery governance. |
| OAuth app governance | 26-Jun-2026 · Newly retained (>24h)Inventory connected OAuth apps, inspect risky or excessive scopes, map users and tenants tied to each integration, and check for persistence artifacts such as new OAuth apps, admin accounts, or webhooks. [26] | Obsidian's practitioner analysis strengthens the post-incident blast-radius and persistence-check workflow. |
| Salesforce connected-app telemetry | 15-Jul-2026 · Newly retained (>24h)Use Salesforce RTEM/Defender-style telemetry where available to pivot on connected application attribution, granted OAuth scopes, highly privileged or unused apps, application risk score, anomalous Connected App activity, report exports, API events, and CloudAppEvents query pivots. [48] | Microsoft's newly retained guidance adds a detection and governance model for OAuth abuse that can look like legitimate integration activity. |
| User agent / IP | Python-urllib, unfamiliar infrastructure, non-Klue IP ranges, unusual request bursts, impossible provider geography. 30-Jun-2026 · Newly retained (>24h)FINRA and ZeroFox add public IP leads, and ZeroFox adds Python-urllib/3.12, Python-urllib/3.14, and 5238 user-agent leads. [30, 31] | ReliaQuest, Datadog, FINRA, and ZeroFox highlight automation and infrastructure anomalies as detection leads. |
| Data scope | Contacts, Accounts, Opportunities, Cases, Tasks, Notes, attachments, custom objects, Gong or other connected-platform data. | Determines business impact and notification scope. |
| Secrets in CRM/support records | Credentials, API keys, cloud tokens, VPN configs, Snowflake tokens, screenshots, support attachments, or plaintext customer secrets embedded in historical tickets or notes. | CRM/support data can convert a data-theft incident into follow-on access risk even when the SaaS platform itself was not exploited. |
| Extortion evidence | 26-Jun-2026 · Freshly reported (<24h)Emails, leak-site listings, Session identifiers, proof samples, countdowns, victim-naming claims, reported site-down/deletion statements, and second-actor outreach. Validate proof separately before accepting payment, operator, deletion, or sample-possession claims. [27] | Preserve for counsel, law enforcement, insurer coordination, and source-backed claim deconfliction. |
13-TTPs / Attack Flow
| Behavior | MITRE ATT&CK Mapping | Sources |
|---|---|---|
| Abuse a trusted third-party SaaS integration relationship. | T1199: Trusted Relationship | [1, 2, 3, 12] |
| Obtain and use OAuth/application tokens associated with connected platforms. | T1528: Steal Application Access Token | [1, 3, 5, 13] |
| 15-Jul-2026 · Newly retained (>24h)Authenticate through a trusted integration account or connected application and query data through legitimate APIs. | T1671: Cloud Application Integration | [3, 5, 16, 48] |
| Automate Salesforce object enumeration and record collection with scripted API calls. | T1119: Automated Collection | [3, 5, 17] |
| Exfiltrate SaaS/CRM records over API/web-service channels. | T1567: Exfiltration Over Web Service | [3, 5, 14] |
14-IOCs / Observables
No stable public Icarus blocklist is published here. Treat the entries below as behavioral observables and tenant-specific collection leads, not universal IOCs.
| Type | Indicator / Observable | What To Hunt / Collect |
|---|---|---|
| Scope note | No universal blocklist is published here; use public indicators only as hunting leads. | Use tenant-specific Salesforce, OAuth, connected-app, API, IP, user-agent, and extortion evidence collected during the investigation. |
| Connected app | Klue Battlecards / Klue integration authorization | Validate whether the connected app existed, when tokens were issued, whether it was disabled, and what scopes were granted. |
| User agent | Python-urllib or other automation-oriented user agents where not expected | Correlate with API query bursts and unfamiliar infrastructure; do not treat as sufficient by itself. |
| Salesforce API pattern | High-volume REST API queries, object enumeration, QueryMore, Bulk API, report exports | Use to scope collection and data-access impact. |
| Public IP leads | 30-Jun-2026 · Newly retained (>24h)FINRA and ZeroFox list 138.226.246[.]94, 212.86.125[.]24, 213.111.148[.]90, and 94.154.32[.]160; FINRA additionally lists 159.183.215[.]61 and 159.183.181[.]239. | Compare against Salesforce, OAuth, and connected-SaaS logs; do not treat one IP hit as attribution without tenant context. |
| Public user-agent leads | 30-Jun-2026 · Newly retained (>24h)ZeroFox lists Python-urllib/3.12, Python-urllib/3.14, and 5238 as suspicious API-log user agents. | Correlate with REST path access, query bursts, source IP, OAuth token, and object scope. |
| Public sender-domain leads | 30-Jun-2026 · Newly retained (>24h)FINRA lists baccarat.com[.]au, robinskitchen.com[.]au, and house.com[.]au as malicious sender-domain leads. | Search mail security logs for extortion or follow-on phishing attempts and preserve relevant messages for counsel. |
| Extortion communication | Leak-site references, Session Messenger IDs, proof samples, deadlines, and 30-Jun-2026 · Newly retained (>24h)the "mr bean" direct-email alias reported by FINRA and ZeroFox. | Preserve for counsel, insurer, and law-enforcement coordination; do not publish leaked sample contents. |
15-IR Playbook / Defensive Actions
| Priority | Action | Owner |
|---|---|---|
| 1 | Determine whether Klue Battlecards or related Klue integrations were connected to Salesforce, Gong, HubSpot, SharePoint, Google Drive, or other platforms. 30-Jun-2026 · Newly retained (>24h)FINRA specifically expands review to HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, Slack, and other third-party platforms. [30] | SaaS / IAM |
| 2 | 26-Jun-2026 · Newly retained (>24h)Revoke Klue OAuth tokens, disable connected apps where needed, preserve token and connected-app evidence before cleanup, and check for persistence through newly created OAuth apps, admin accounts, or webhooks. [26] | IAM / Salesforce Admin |
| 3 | Review Salesforce Event Monitoring, LoginHistory, ConnectedAppOAuthUsage, API Total Usage, report exports, object access, suspicious user agents/IPs, and FINRA-listed sender-domain leads. 30-Jun-2026 · Newly retained (>24h)Preserve mail evidence tied to the "mr bean" alias or claimed Icarus outreach. 15-Jul-2026 · Newly retained (>24h)Where available, add Microsoft's connected-app attribution, Salesforce RTEM, high-privilege/unused-app review, and CloudAppEvents hunting pivots. 01-Aug-2026 · Freshly reported (<24h)For vendor-control validation, ask for source verification, runner restrictions, default-deny deployment networking, GitHub Apps or workload identity, refresh-token rotation or idle expiration, IP-range allow-listing, and low-privilege integration-account support. 30-Jul-2026 · Newly retained (>24h)For re-enabled Klue integrations, validate static egress IPs, PKCE, OAuth lifecycle policy, and vendor-control attestations before customer enablement. [30, 31, 48, 50, 51] | SOC / Salesforce Admin |
| 4 | Scope object and field exposure: Contacts, Accounts, Opportunities, Cases, Tasks, Notes, attachments, custom objects, support communications, and any secrets pasted into tickets or notes. | IR / Legal |
| 5 | 26-Jun-2026 · Freshly reported (<24h)Preserve extortion communications and coordinate counsel, insurer, law enforcement, and customer-notification messaging. Keep Icarus deletion/site-down reporting and second-actor outreach caveated until proof is independently validated. 30-Jun-2026 · Newly retained (>24h)Treat ZeroFox's possible SLH association as a circumstantial lead, not a confirmed alias or merger. [27, 31] | Legal / Exec |
16-Decision Ready Actions
| Decision | Why It Matters | Likely Owner |
|---|---|---|
| Approve SaaS/OAuth emergency review | Icarus-style tradecraft abuses trusted integrations, so the response must cover connected apps and tokens, not only user passwords. | CISO / IAM |
| Preserve Salesforce evidence before revocation | Token revocation is urgent, but evidence loss can impair legal, notification, and scoping analysis. | IR / Legal |
| Scope support and CRM records for sensitive data | Support cases and sales notes may contain secrets, customer context, or targeted-phishing material. | IR / Business Owner |
| Tighten connected-app governance | Least privilege, token rotation, app review, and delegated-scope controls reduce repeat exposure. | SaaS Security |
| Prepare customer and partner communications | Several public examples separate CRM exposure from core product compromise; precise wording reduces confusion. | Legal / Comms |
| 30-Jun-2026 · Newly retained (>24h)Alert financial-services stakeholders and vendor owners | FINRA now explicitly frames the incident as relevant to member firms and critical vendors using Klue or connected SaaS platforms. | Compliance / Vendor Risk |
17-Exploitable Technology Risks
| Technology / Process | Exploitable Risk | Defensive Priority |
|---|---|---|
| OAuth / connected apps | Broad scopes, long-lived refresh tokens, stale integrations, and weak app governance can create durable third-party access. | Inventory apps, review scopes, rotate/revoke tokens, and enforce least privilege. |
| Salesforce APIs | Legitimate API access can enable high-volume object enumeration and data export without endpoint malware. | Enable and review Event Monitoring, API usage, report export, object access, and unusual automation. |
| CRM/support data | Records can contain business-sensitive context, customer details, and accidentally embedded secrets. | Scope fields, notes, attachments, cases, and custom objects; search for credentials and keys. |
| Third-party SaaS vendors | Vendor integration compromise can affect downstream customers even when the customer's core platform is not directly exploited. | 01-Aug-2026 · Freshly reported (<24h)Require incident notification, logs, integration scoping, token-rotation commitments, CI/CD boundary evidence, short-lived credential controls, default-deny deployment networking, and least-privilege integration-account support in vendor governance. [51] |
19-Source Summary & Confidence
| Tier | Retained Sources | What This Tier Supports | Caveat |
|---|---|---|---|
| Tier 0 - Primary / Vendor & Direct Victim Disclosures | Klue, Salesforce Status, Huntress, Jamf, Recorded Future; 25-Jun-2026 · Addednewly retained direct sources for HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8; 27-Jun-2026 · Newly retained (>24h)Link11 direct notice and Jamf update; 02-Jul-2026 · Newly retained (>24h)Saviynt and LogicMonitor/Catchpoint direct notices; 03-Jul-2026 · Newly retained (>24h)Klue/CrowdStrike investigation summary; 05-Jul-2026 · Newly retained; undatedPostman Security & Trust Portal notice; 06-Jul-2026 · Newly retained (>24h)Deel and Insurity direct notices; 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject direct notices; 19-Jul-2026 · Newly retained (>24h)OneTrust July 10 investigation-closure update; 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY trust-center notices; 09-Jul-2026 · Freshly reported (<24h)Snyk Status forensic closure; 10-Jul-2026 · Newly retained (>24h)Secure ISS public coverage of SentinelOne's Klue partner update; 12-Jul-2026 · Newly retained (>24h)Camunda Trust Center and Tanium direct notices; 26-Jul-2026 · Newly retained (>24h)Blackbaud Trust Center update; 30-Jul-2026 · Newly retained (>24h)Klue July 27 restored-integrations update; 01-Aug-2026 · Freshly reported (<24h)Klue July 31 CTO security-lessons post; 16-Aug-2026 · Newly retained (>24h)Betterment Mass.gov notice letter; 20-Aug-2026 · Newly retained (>24h)ControlUp direct notice | Vendor incident facts, Salesforce platform boundary, root-cause and containment detail, two-phase GitHub PAT/CI-CD intrusion precision, restored integration status, direct downstream exposure statements, regulator-hosted financial-services notice language, customer-notice language, ongoing-investigation status, and completed forensic-scope closure. | Primary notices control each organization's exact impact; do not generalize one victim's fields, platform exclusions, support-data exclusions, password findings, investigation status, investigation-closure status, sensitive-data findings, product-impact boundary, or identity-monitoring posture to all victims. Betterment is retained only for the notice-letter boundary: name/SSN file language, no Betterment computer-system access, and two-year Kroll identity monitoring. ControlUp is retained only for ControlUp-specific Salesforce business-data exposure and product, production-environment, and infrastructure non-impact language. Klue engineering lessons refine the vendor root-cause/control model; they do not add a victim, prove a Salesforce platform vulnerability, or close every downstream exposure review. Restored Klue integration availability is a vendor restoration milestone, not proof that every downstream customer's historical exposure review is complete. Secure ISS is retained only for the public SentinelOne partner-update summary because the underlying SentinelOne portal notice is gated. |
| Tier 0 - Direct Victim Closure Update | 18-Aug-2026 · Newly retained (>24h)Thinkproject August 12 status-history closure update | Adds a direct customer-specific investigation endpoint: Thinkproject says its Klue breach investigation concluded, it is not aware of misuse of affected data, and monitoring continues. | Use only for Thinkproject scoping; do not generalize no-known-misuse or investigation-concluded language across other Klue downstream victims. |
| Tier 1 - Practitioner / CTI / Regulator Guidance | ReliaQuest, Datadog Security Labs; 26-Jun-2026 · Newly retained (>24h)Obsidian Security; 30-Jun-2026 · Newly retained (>24h)FINRA and ZeroFox | OAuth-token abuse mechanics, Salesforce API hunting, observed automation, user-agent clues, SaaS-to-SaaS OAuth blast-radius framing, financial-sector mitigation guidance, and actor-tradecraft context. | Practitioner detections should be adapted to each Salesforce tenant and data-retention window; actor-affiliation claims remain caveated when based on reposts or shared contact artifacts. |
| Tier 2 - Corroborating News | BleepingComputer, The Hacker News, SecurityWeek; 26-Jun-2026 · Freshly reported (<24h)TechCrunch; 27-Jun-2026 · Freshly reported (<24h)SecurityWeek June 26 update | Public timeline, Icarus claim context, named-victim expansion, LastPass coverage, extortion-status updates, victim-notice scale, and broad stakeholder awareness. | Secondary reporting is useful for synthesis but should not outrank primary notices for exact victim impact; claim-only second-actor, leak-site, payment, and operator-identity assertions remain qualified. |
| Tier 3 - Framework / Definitions | MITRE ATT&CK | Standard behavior mapping for trusted relationship abuse, token theft, valid-account use, automated collection, and SaaS/API exfiltration. | Framework mappings classify behavior; they do not prove attribution. |
| Tier 4 - Community Signal | None retained | No reliable community-source finding was promoted into this version. | Leak-site or social chatter should be treated as lead-only unless corroborated. |
| Tier 5 - Custom Source (defined by user) | None supplied | No user-supplied private/custom source was used. | Customer-specific Salesforce logs would materially improve confidence. |
| Tier 6 - Custom Integrations with API/Keys | One checked, none promoted | No API-derived signal was promoted into the brief. | Retain negative checks in monitoring audit, not in finding language. |
| Tier 7 - Inner Discovery / Carved URLs | None retained | No carved inner URLs were promoted. | Future carved victim notices should be promoted only if directly relevant and accessible. |
| Tier 8 - Expansion Research | GTIG / FBI UNC6395 comparator sources; 15-Jul-2026 · Newly retained (>24h)Microsoft Security Blog on ShinyHunters-associated Salesforce OAuth abuse and Klue as Storm-3138 activity | Adjacent Salesforce OAuth-token data-theft pattern for deconflicting Icarus from UNC6395, Salesloft Drift, Storm-3138, and ShinyHunters-associated tradecraft. | Comparator and vendor-specific actor labels are not aliases unless sources explicitly merge them. |
20-Real World Examples
| Example | What It Shows | Boundary |
|---|---|---|
| Huntress | Confirmed Salesforce CRM data impact, including business contacts, price quotes, sales communications, and competitive reports. [4, 8] | Huntress publicly limited impact away from product telemetry and engineering data. |
| LastPass | 25-Jun-2026 · AddedDirect LastPass response confirmed customer and support-related CRM data exposure through Salesforce in the Klue incident. [7, 24] | LastPass stated vaults, products, services, and infrastructure were not affected. |
| Betterment | 16-Aug-2026 · Newly retained (>24h)Mass.gov's Betterment notice letter adds a financial-services example in which Klue Labs was a sales-team vendor with access to a Salesforce database containing Betterment data, and the accessed file contained name and Social Security number. [52] | Betterment stated its computer systems were not accessed and offered two years of Kroll identity monitoring; do not expand this into product, brokerage, bank, account-access, credential, or raw stolen-data claims. |
| Thinkproject | 18-Aug-2026 · Newly retained (>24h)Thinkproject's August 12 status-history update adds a direct closure example: its investigation concluded, no misuse of affected data is known, and monitoring continues. [40] | This closure is source-bound to Thinkproject and does not prove the same investigation status or misuse finding for other Klue downstream victims. |
| Additional downstream notices | 25-Jun-2026 · AddedDirect notices and reporting describe additional disclosures involving Recorded Future, Tanium, Jamf, Sprout Social, Gong, BeyondTrust, HackerOne, Snyk, OneTrust, Pendo, 8x8, SentinelOne, and other organizations. 27-Jun-2026 · Freshly reported (<24h)SecurityWeek added a roughly two-dozen-notification scale update and additional names, while 27-Jun-2026 · Newly retained (>24h)Link11 provided a direct notice for business-contact and sales-related CRM exposure. 02-Jul-2026 · Newly retained (>24h)Saviynt and LogicMonitor/Catchpoint add direct-notice boundaries for sales or CRM exposure with core-product and operational-data exclusions. 05-Jul-2026 · Newly retained; undatedPostman adds a direct Salesforce customer-contact/sales-information exposure example while excluding Gong customer-data access and Postman core-platform-services impact. 06-Jul-2026 · Newly retained (>24h)Deel and Insurity add direct-notice examples for business/commercial CRM exposure, limited personal-data-in-CRM, limited active-secrets-in-CRM, and product/platform/infrastructure exclusions. 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject add direct CRM-related, support-adjacent, sensitive-information, and UAT CRM examples. 19-Jul-2026 · Newly retained (>24h)OneTrust also adds a completed-investigation example with validated scope, finalized containment/remediation, and no evidence of exposure beyond Salesforce after June 12 containment. 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY add direct trust-center examples with no visible publication dates. 09-Jul-2026 · Freshly reported (<24h)Snyk adds a direct status-page example for Mandiant-assisted forensic closure, business-CRM-only impact, and platform/sensitive-data non-impact. 10-Jul-2026 · Newly retained (>24h)SentinelOne adds a public partner-update example for Salesforce-only containment via Klue API integration, independent forensic verification, no lateral movement, and product/cloud/production exclusions. 12-Jul-2026 · Newly retained (>24h)Camunda and Tanium add direct examples for Salesforce CRM data-category scoping and support/password/product/cloud exclusions. 26-Jul-2026 · Newly retained (>24h)Blackbaud adds a direct ongoing-investigation/no-product-impact update. 16-Aug-2026 · Newly retained (>24h)Betterment adds a regulator-hosted notice-letter example for name/SSN file exposure and no Betterment computer-system access. 20-Aug-2026 · Newly retained (>24h)ControlUp adds a direct notice example for Salesforce business-data exposure through Klue's integration with product, production-environment, and infrastructure non-impact language. [9, 15, 18, 19, 20, 21, 22, 23, 25, 28, 29, 32, 33, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 49, 52, 53] | Do not assume every organization had the same data fields, scope, notification duties, Salesforce integration posture, investigation status, investigation-closure status, identity-monitoring posture, product-impact boundary, or business impact; each primary notice controls. |
| Klue | Vendor-origin integration incident that enabled access to connected third-party platforms. 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary adds that a compromised GitHub PAT enabled unauthorized integration-service code and credential collection, and that Klue disabled affected GKE pods/PATs (runtime workloads and personal access tokens) and rotated OAuth credentials on June 12. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post adds the freshest primary engineering detail for source-code download, second PAT discovery, credential testing, build/deployment-path abuse, tampered production workload, and stored OAuth-token access. [1, 34, 51] | Klue said customer content stored in Klue was not impacted based on its investigation to date; CrowdStrike did not identify evidence of access outside systems related to the integration service or after June 12 containment. |
| Claim-only victim lists | 26-Jun-2026 · Freshly reported (<24h)Icarus leak-site claims, third-party lists, and the newly reported second-actor claims may contain additional names or counts, but they remain lead-only until supported by primary notices or reliable corroboration. [9, 15, 27] | This page does not treat a name, customer count, payment allegation, operator description, or sample-possession claim as confirmed without corroboration. |
21-Source Weighting / Relevance
| Source Group | What It Supports | Confidence |
|---|---|---|
| Primary vendor and direct victim disclosures | Klue and Salesforce establish the integration/OAuth-token scope and platform-vulnerability boundary; 03-Jul-2026 · Newly retained (>24h)Klue's CrowdStrike summary adds primary root-cause and containment detail for the GitHub PAT, unauthorized integration-service code, OAuth credential collection, GKE pod/PAT disablement (runtime workloads and personal access tokens), token rotation, and no-post-June-12 Klue-environment activity boundary. 01-Aug-2026 · Freshly reported (<24h)Klue's CTO post adds fresh primary engineering precision for two-phase GitHub PAT/CI-CD intrusion flow, stored OAuth-token access, and durable credential, deployment, OAuth, and distributed-evidence controls. 30-Jul-2026 · Newly retained (>24h)Klue's July 27 primary update adds restored Salesforce/Gong integration availability and remediation-control detail for re-enablement. Huntress, Jamf, and Recorded Future provide baseline downstream context; 25-Jun-2026 · Addednewly retained direct notices or filings for HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8 provide stronger downstream-disclosure evidence. 27-Jun-2026 · Newly retained (>24h)Link11 and Jamf's update add direct boundary precision. 02-Jul-2026 · Newly retained (>24h)Saviynt and LogicMonitor/Catchpoint add two direct downstream notices with Salesforce sales/CRM exposure boundaries and product or operational-data exclusions. 05-Jul-2026 · Newly retained; undatedPostman adds a direct Salesforce/Gong boundary and core-platform-services exclusion. 06-Jul-2026 · Newly retained (>24h)Deel and Insurity add direct CRM-scope and limited personal-data/active-secret caveats. 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject add direct CRM/support-adjacent/UAT CRM scoping and response detail. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update adds investigation-complete and finalized-containment/remediation precision. 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY add direct trust-center boundaries without visible publication dates. 09-Jul-2026 · Freshly reported (<24h)Snyk adds direct forensic closure, Mandiant involvement, business-CRM-only scope, and Snyk platform/sensitive-data exclusions. 10-Jul-2026 · Newly retained (>24h)SentinelOne adds public partner-update scope for Salesforce-only containment, independent forensic verification, no lateral movement, and no product/cloud/production impact. 12-Jul-2026 · Newly retained (>24h)Camunda and Tanium add direct Salesforce CRM scoping and support/password/product/cloud exclusion precision. 26-Jul-2026 · Newly retained (>24h)Blackbaud adds ongoing-investigation and no-known-product-impact status. 20-Aug-2026 · Newly retained (>24h)ControlUp adds Salesforce business-data exposure and product/production/infrastructure non-impact boundaries. [1, 2, 4, 18, 19, 20, 21, 22, 23, 24, 25, 29, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 49, 50, 51, 53] | High; fresh engineering precision and restored integration availability remain separate from customer-specific historical exposure closure |
| Thinkproject Status | 18-Aug-2026 · Newly retained (>24h)Direct customer-specific closure language for the Thinkproject row: investigation concluded, no known misuse of affected data, and continued monitoring. [40] | High for Thinkproject only; not a generalized victim-closure finding |
| ReliaQuest / Datadog / Huntress / Obsidian Security / FINRA / ZeroFox / Microsoft | 26-Jun-2026 · Newly retained (>24h)Attack mechanics, Salesforce telemetry, victim impact, extortion communications, defensive scoping, and OAuth app governance / blast-radius review. 30-Jun-2026 · Newly retained (>24h)FINRA and ZeroFox add public IOC leads, financial-sector response guidance, first-observed actor timing, and caveated association handling. 15-Jul-2026 · Newly retained (>24h)Microsoft adds Storm-3138 nomenclature, broader ShinyHunters-associated Salesforce OAuth tradecraft context, and connected-app telemetry/posture/hunting guidance. [3, 4, 5, 26, 30, 31, 48] | Medium-High; affiliation and actor-label leads remain caveated |
| BleepingComputer / The Hacker News / SecurityWeek / TechCrunch | 26-Jun-2026 · Freshly reported (<24h)Public timeline, corroboration, LastPass/Huntress examples, additional downstream notices, Icarus framing, and caveated live extortion-status reporting. 27-Jun-2026 · Freshly reported (<24h)SecurityWeek adds the latest retained victim-notification scale and extra public-notice names. [6, 7, 8, 9, 15, 27, 28] | Medium; claim-only subclaims remain qualified |
| GTIG / FBI on UNC6395; Microsoft on ShinyHunters-associated OAuth abuse | 15-Jul-2026 · Newly retained (>24h)Comparison to the earlier Salesloft Drift Salesforce OAuth campaign, Storm-3138/Klue naming, and broader actor-label deconfliction across Salesforce OAuth abuse paths. | Medium-High for comparator context; do not treat comparator labels as aliases without explicit source support |
| MITRE ATT&CK | Standard behavior mapping for trusted relationships, token theft, valid accounts, automated collection, and SaaS/API exfiltration. | High for behavior definitions |
22-Source Deconfliction
| Source Issue / Tension | Where Sources Agree | Where They Differ | PANDA Handling |
|---|---|---|---|
| Core source agreement | Sources consistently describe the Klue event as third-party SaaS/OAuth trust abuse that enabled downstream Salesforce data access. | Sources differ in how much detail they provide about exact fields, affected customers, Icarus infrastructure, second-actor claims, leak-site status, and internal Klue root cause. | Use Klue/Salesforce for root scope, victim notices for per-company impact, practitioner sources for hunting, and fresh media updates only for caveated extortion-status changes. 03-Jul-2026 · Newly retained (>24h)Use Klue's CrowdStrike summary for the GitHub PAT (personal access token) / unauthorized integration-service code / GKE pod containment / no-post-June-12 Klue activity details. 01-Aug-2026 · Freshly reported (<24h)Use Klue's CTO post for the fresher source-code download, second PAT discovery, credential testing, unauthorized build/deployment-path abuse, tampered production workload, and stored OAuth-token access detail. 30-Jul-2026 · Newly retained (>24h)Use Klue's restored-integrations update for current Salesforce/Gong re-enablement and vendor-hardening status, not as proof that every downstream customer completed historical exposure scoping. 26-Jun-2026 · Freshly reported (<24h)Do not treat reported deletion steps or second-actor claims as proof of full data deletion, full data possession, payment, or operator identity. [1, 2, 3, 4, 5, 27, 34, 50, 51] |
| Salesforce breach vs Salesforce-connected exposure | Retained sources support Salesforce-connected data exposure through Klue's app connection. | Headlines can imply a Salesforce platform breach; Salesforce states the issue was limited to Klue's app connection. | Do not call this a Salesforce platform vulnerability or direct Salesforce breach without new evidence. 01-Aug-2026 · Freshly reported (<24h)Klue's fresh CTO post frames the access path as GitHub PAT and CI/CD abuse inside Klue, followed by stored OAuth-token access; it does not alter Salesforce's platform-vulnerability boundary. 30-Jul-2026 · Newly retained (>24h)Klue's reinstatement of Salesforce and Gong integrations is a remediation/restoration milestone, not retroactive evidence that Salesforce was the original vulnerability. [2, 8, 50, 51] |
| Icarus actor label maturity | Huntress and media sources use Icarus for the Klue-linked extortion/data-theft activity. | The public record does not yet provide a mature actor profile, real-world operator identity, nationality, or complete infrastructure map; Microsoft now uses Storm-3138 for the Klue incident while public reporting continues to use Icarus. | Treat Icarus as an emerging actor label tied to this campaign, not a fully mature intrusion-set attribution. 15-Jul-2026 · Newly retained (>24h)Use Microsoft's Storm-3138 as source-specific nomenclature and deconfliction context, not as proof that every public Icarus reference maps cleanly to Microsoft's broader ShinyHunters-associated activity set. [4, 6, 8, 9, 48] |
| Icarus vs UNC6395 | Both Icarus/Klue and UNC6395/Salesloft Drift involve Salesforce-connected OAuth or SaaS integration abuse. | GTIG and FBI source UNC6395 to Salesloft Drift; Microsoft now adds Storm-3138 nomenclature for Klue inside a wider ShinyHunters-associated tradecraft discussion, but this source set still does not prove UNC6395 is an alias for Icarus. | Use UNC6395 as an adjacent comparator, not a confirmed alias, until a source explicitly merges the labels. 15-Jul-2026 · Newly retained (>24h)Microsoft improves the comparator model by grouping Salesforce OAuth abuse paths, but the page keeps UNC6395/Salesloft Drift, Storm-3138/Klue, and public Icarus extortion labeling separated. [9, 10, 11, 48] |
| Icarus vs SLH / Scattered Lapsus$ Hunters | ZeroFox observed Telegram reposting and Session-contact overlap that may point to association signals. | ZeroFox also states Icarus has not publicly acknowledged or claimed an SLH affiliation, so the record does not support merging labels. | 30-Jun-2026 · Newly retained (>24h)Treat SLH linkage as circumstantial association context, not a confirmed alias, operator identity, or attribution merger. [31] |
| Victim names and impact | Primary notices and reliable reporting establish multiple named downstream organizations with Salesforce/CRM or business-data exposure. | Affected objects, fields, legal materiality, customer notification posture, product-impact boundaries, and second-actor claimed customer counts vary or remain unverified. | Publish only source-backed victim names and preserve each notice's impact boundaries. 05-Jul-2026 · Newly retained; undatedPostman's direct notice is retained for its own Salesforce customer-contact/sales-information exposure, Gong non-customer-data-access caveat, and core-platform-services exclusion. 06-Jul-2026 · Newly retained (>24h)Deel and Insurity are retained for organization-specific CRM/commercial-data, limited personal-data, and active-secrets-in-CRM caveats, not as uniform victim-scope findings. 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject are retained for their own CRM, support-adjacent, UAT CRM, sensitive-information, and product/platform exclusion boundaries. 19-Jul-2026 · Newly retained (>24h)OneTrust's July 10 update is retained for its own completed technical investigation, validated scope, finalized containment/remediation, Salesforce-only post-containment forensic boundary, and ongoing governance/compliance review. 18-Aug-2026 · Newly retained (>24h)Thinkproject's August 12 update is retained for its own investigation-concluded, no-known-misuse, continuing-monitoring boundary, not as a uniform victim-scope finding. 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY are retained as Newly retained (publication date not visible) direct notices, not uniform scope findings. 09-Jul-2026 · Freshly reported (<24h)Snyk is retained for its own business-CRM-only, Mandiant-assisted forensic-closure, direct-notification, platform non-impact, and sensitive-data non-impact boundary. 12-Jul-2026 · Newly retained (>24h)Camunda and Tanium are retained for their own direct Salesforce CRM data-category and product/platform exclusion boundaries, not as uniform scope findings. 16-Aug-2026 · Newly retained (>24h)Betterment is retained for its own Mass.gov notice-letter name/SSN file, no-Betterment-computer-system-access, and Kroll identity-monitoring boundary, not as a universal financial-services impact model. 20-Aug-2026 · Newly retained (>24h)ControlUp is retained for its own Salesforce business-data exposure and product, production-environment, and infrastructure non-impact boundary, not as a uniform victim-scope finding. 26-Jun-2026 · Freshly reported (<24h)TechCrunch's second-actor report is retained as claim-only extortion context, not a confirmed victim count or complete affected-customer list. [4, 7, 9, 15, 18, 19, 20, 21, 22, 23, 24, 25, 27, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 46, 47, 52, 53] |
| Disclosed-victim scale | Public sources show the victim list continued expanding after the first wave of direct notices. | SecurityWeek's June 26 update raises the public-notification scale to roughly two dozen companies and adds multiple names, but not every listed organization has an equally accessible direct notice or identical Salesforce integration posture. | 27-Jun-2026 · Freshly reported (<24h)Use the roughly two dozen figure and added names as freshly reported victimology scale, while preserving direct-notice boundaries where available and retaining Autodesk as a non-impact caveat. [28, 29] |
| Ransomware vs extortion | Sources support extortion pressure, leak-site claims, and CRM data theft. | No retained source shows file encryption, ransomware deployment, or broad endpoint malware in this campaign; the latest status reporting concerns alleged deletion steps, site availability, and second-actor extortion pressure. | Frame as SaaS data theft and extortion unless new evidence shows encryption or malware deployment. 26-Jun-2026 · Freshly reported (<24h)Fresh reporting changes the extortion-process status, not the ransomware classification. [4, 6, 8, 9, 15, 27] |
23-About the Contributors
| Contributor | Who They Are / What They Do | Contribution & Why It Matters | Sources |
|---|---|---|---|
| Klue | Competitive enablement SaaS vendor | 03-Jul-2026 · Newly retained (>24h)Primary incident disclosure, integration-path explanation, and newly retained CrowdStrike investigation summary for root-cause, containment, and security-hardening detail. 30-Jul-2026 · Newly retained (>24h)Newly retained restored-integrations update for Salesforce/Gong re-enablement and added controls including static egress IP allowlisting, PKCE, tightened OAuth token lifecycle policy, PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlists. 01-Aug-2026 · Freshly reported (<24h)Freshly retained CTO lessons-learned post adds two-phase GitHub PAT/CI-CD intrusion detail, stored OAuth-token access, and durable credential, deployment, OAuth, and incident-evidence controls. | [1, 34, 50, 51] |
| Salesforce | CRM platform provider | Platform-boundary statement and connected-app context. | [2] |
| Huntress | Security vendor and direct impacted organization | Victim/practitioner analysis, Icarus attribution context, and CRM-data impact detail. | [4] |
| ReliaQuest / Datadog | Practitioner research | Salesforce API hunting, automation, and OAuth-token mechanics. | [3, 5] |
| Direct downstream notices | Impacted organizations and public-company disclosure | 27-Jun-2026 · Newly retained (>24h)Victim-specific Salesforce/CRM exposure statements, product-impact boundaries, regulatory disclosure context, and newly retained Link11/Jamf boundary updates. 05-Jul-2026 · Newly retained; undatedPostman adds a direct Salesforce/Gong split and core-platform-services exclusion. 06-Jul-2026 · Newly retained (>24h)Deel and Insurity add direct CRM-scope, limited personal-data, active-secret, and product/platform boundary precision. 08-Jul-2026 · Newly retained (>24h)OneTrust, Tines, and Thinkproject add older direct CRM/support-adjacent/UAT CRM scoping. 19-Jul-2026 · Newly retained (>24h)OneTrust adds completed-investigation, validated-scope, finalized-containment/remediation, Salesforce-only post-containment forensic boundary, and ongoing governance/compliance review. 08-Jul-2026 · Newly retained; undatedCresta, AlertMedia, and ABBYY add direct trust-center boundaries without visible publication dates. 09-Jul-2026 · Freshly reported (<24h)Snyk adds direct forensic-closure and platform/sensitive-data exclusion boundaries. 10-Jul-2026 · Newly retained (>24h)Secure ISS public coverage adds SentinelOne-specific Salesforce containment, independent forensic verification, and product/cloud/production non-impact boundaries. 12-Jul-2026 · Newly retained (>24h)Camunda and Tanium add direct CRM data-category scoping and support/password/product/cloud exclusion boundaries. 26-Jul-2026 · Newly retained (>24h)Blackbaud adds ongoing-investigation and no-known-product-impact status. 16-Aug-2026 · Newly retained (>24h)Betterment adds regulator-hosted notice-letter evidence for Klue vendor access to a Salesforce database, name/SSN file exposure, no Betterment computer-system access, and Kroll identity monitoring. 20-Aug-2026 · Newly retained (>24h)ControlUp adds direct Salesforce business-data exposure and product, production-environment, and infrastructure non-impact language. | [18, 19, 20, 21, 22, 23, 24, 25, 29, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 49, 52, 53] |
| Thinkproject Status | Direct downstream investigation closure | 18-Aug-2026 · Newly retained (>24h)August 12 status-history update says Thinkproject's Klue breach investigation concluded, no misuse of affected data is known, and monitoring continues; retained only as a Thinkproject-specific closure boundary. | [40] |
| BleepingComputer / SecurityWeek / THN | Security media | 27-Jun-2026 · Freshly reported (<24h)Public corroboration, named-victim tracking, LastPass coverage, stakeholder context, and the latest retained roughly two-dozen-notification scale update. | [6, 7, 8, 9, 15, 28] |
| FINRA / ZeroFox | Regulatory guidance and threat intelligence | 30-Jun-2026 · Newly retained (>24h)Financial-sector mitigation guidance, public IOC leads, first-observed actor timing, alias corroboration, DLS/direct-email tradecraft, and caveated SLH-association handling. | [30, 31] |
| Microsoft Security Research | Expansion research and SaaS/OAuth defender guidance | 15-Jul-2026 · Newly retained (>24h)Source-specific Storm-3138 naming for the Klue incident, ShinyHunters-associated Salesforce OAuth abuse context, no-Salesforce-platform-vulnerability boundary reinforcement, and Defender/Salesforce connected-app telemetry, posture, and hunting guidance. | [48] |
24-KEV and CVE Details
No CVE or CISA KEV entry is associated with Icarus or the Klue incident in this source set. This is an OAuth/SaaS trust-path incident, not a software vulnerability in Salesforce. If a customer discovers separate vulnerable software, weak credentials, or misconfigured connected-app controls during scoping, track those as local findings rather than Icarus-specific CVEs.
25-MITRE ATT&CK Lifecycle Mapping
| Lifecycle Phase | MITRE Mapping | How It Applies |
|---|---|---|
| Initial Access | T1199: Trusted Relationship | Compromise or abuse of a trusted SaaS vendor/integration path. |
| Credential / Token Access | T1528: Steal Application Access Token | OAuth tokens used to access Salesforce-connected data. |
| Persistence / Defense Evasion | T1078: Valid Accounts / T1671: Cloud Application Integration | 15-Jul-2026 · Newly retained (>24h)Trusted app/token-backed access and connected applications can look like legitimate integration activity; Microsoft newly maps cloud application integration as relevant to Salesforce OAuth abuse. [48] |
| Collection | T1119: Automated Collection | Automated object enumeration and CRM data collection. |
| Exfiltration | T1567: Exfiltration Over Web Service | SaaS/API-based extraction and follow-on extortion pressure. |
26-Common Questions Q&A
| Question | Answer |
|---|---|
| Who is behind Icarus? | Public sources used here do not identify a real-world person, nationality, or named legacy group behind Icarus. Treat Icarus as an emerging extortion actor label associated with Klue-linked Salesforce data theft. 15-Jul-2026 · Newly retained (>24h)Microsoft's newly retained research identifies the Klue incident as Storm-3138 activity, which is useful source-specific nomenclature but not a real-world identity. [4, 6, 8, 9, 48] |
| Is Icarus also UNC6395? | Not proven in this source set. UNC6395 is source-backed for the Salesloft Drift Salesforce OAuth campaign, while Icarus is source-backed for the Klue-linked extortion/data-theft activity. 15-Jul-2026 · Newly retained (>24h)Microsoft adds Storm-3138/Klue and ShinyHunters-associated tradecraft context, but the shared pattern remains SaaS/OAuth trust abuse, not confirmed shared operator identity. [9, 10, 11, 48] |
| Is Icarus tied to SLH? | 30-Jun-2026 · Newly retained (>24h)Not confirmed. ZeroFox observed Telegram reposting and Session-contact overlap that raises a possible affiliation, but also states Icarus has not acknowledged or claimed that affiliation. Treat SLH linkage as a lead, not an alias. [31] |
| Was Salesforce itself vulnerable? | Salesforce stated the issue was limited to Klue's app connection and did not arise from a Salesforce platform vulnerability. Customers still need to scope their own Salesforce data exposure if the Klue integration was present. [2, 8] |
| Is this ransomware? | This is better described as extortion-driven SaaS data theft. Public sources support leak-site pressure and stolen CRM data; they do not show file encryption or network-wide ransomware deployment in this campaign. [4, 9, 15] |
| Does the latest reporting mean the stolen data is gone? | 26-Jun-2026 · Freshly reported (<24h)No. TechCrunch reported that Klue told customers Icarus said it was taking steps to delete data and that the Icarus site appeared down, but the same report also described a second actor's claim to have samples for a subset of customers. Treat deletion, second-actor possession, payment, operator identity, and claimed customer-count details as unverified unless independently corroborated. [27] |
| Why is CRM data sensitive if core products were not breached? | CRM and support records can include business contacts, sales context, quotes, support cases, contract clues, customer relationship maps, and sometimes pasted secrets. That data can fuel targeted phishing, fraud, social engineering, and extortion. |
| What should a defender check first? | Confirm whether the Klue connected app existed, preserve Salesforce API and OAuth evidence, revoke suspicious tokens, scope objects and fields accessed, and review extortion communications before making public claims. |
27-Talking Points
Executive
"This is a SaaS trust problem. A third-party integration had access to CRM data, and once that trust path was abused, downstream organizations had to scope customer and sales records even though Salesforce itself was not the root vulnerability."
Salesforce Admin
"Start with connected-app and API evidence: Klue app presence, token status, OAuth usage, unusual API user agents, object enumeration, query bursts, report exports, and data touched after the suspected window."
Breach Counsel
"Do not frame this as a Salesforce platform breach unless evidence supports that. The better public-source language is third-party OAuth-token abuse through Klue's app connection, with customer-specific data scope still requiring local validation."
Threat Intel
"Icarus is useful as an actor label, but the higher-confidence analytic frame is the playbook: SaaS integration compromise, OAuth token theft, Salesforce API extraction, and extortion. Keep UNC6395 as a source-backed comparator for Salesloft Drift unless a source directly merges the actor labels."
SaaS Security
"For this class of incident, endpoint telemetry may be quiet. The strongest evidence lives in connected-app inventories, OAuth-token state, Salesforce Event Monitoring, API query volume, user agents, source infrastructure, and the actual objects and fields accessed."
28-Additional IntelliOS Threat Intel Products on this Topic
Synced Actor Card Detail
Icarus Threat Actor Profile
Use for the canonical database-backed actor identity, alias, source-reconciliation, and product-link layer.
Related Campaign Brief
Klue Campaign Threat Intel Brief
Companion campaign analysis for the Klue supply-chain incident and downstream Salesforce data exposure.
Comparator Brief
Salesloft Drift OAuth Comparator Brief
Adjacent Salesforce OAuth-token abuse pattern used for UNC6395/Salesloft Drift deconfliction.
29-AI Agent Delta Updates
Current Brief Version
v3.3
Initial Publish Date
24-JUN-2026
First AI Agent Update Run
25-JUN-2026 02:03 AM ET
Latest AI Agent Update Run
25-AUG-2026 02:01 AM ET
AI Monitoring Updates Applied
60
Next Scheduled Monitor
Daily at 6:00 AM ET for 2 years
| Update Time | Agent / Monitor | Delta Type | Evidence / Change | Affected Cards | Action Required |
|---|---|---|---|---|---|
| 25-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Salesforce Help/Trust Klue and Salesloft Drift advisories, Klue primary article/security-incident/status pages, Klue public article index, ControlUp, Thinkproject, Betterment/Mass.gov legal notice leads, Nudge Security Klue breach tracker, RH-ISAC, ThreatLocker, Doppler breach dashboard, AI security incident catalogs, Rescana, AppOmni, Obsidian, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, FINRA Salesloft Drift comparator guidance, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found source-backed findings already represented on-page, Klue's August 24 product/AI deal-support article that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Klue's latest retained incident updates remain the July 27 restored-integrations post and July 31 CTO security-lessons post; Salesforce's Klue Battlecards advisory remained the June 17 platform-boundary notice already cited; ControlUp, Thinkproject, and Betterment remained represented by their retained direct or regulator-hosted notices. No newly retained source changed confidence, victimology, timeline, technical detail, scoping, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 24-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, ControlUp, Lucanet, Thinkproject, Betterment/Mass.gov legal notice leads, Nudge Security Klue breach tracker, Huntress support mirror, Snyk trust/status mirrors, BankInfoSecurity, RH-ISAC, ThreatLocker, Beazley, eSentire, Doppler, Neuracybintel, SalesforceBen, Gblock, Rescana, AppOmni, Anomali, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, FINRA Salesloft Drift comparator guidance, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found source-backed findings already represented on-page, Klue product/blog updates that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Klue's latest retained incident updates remain the July 27 restored-integrations post and July 31 CTO security-lessons post; Salesforce's Klue Battlecards advisory remained the June 17 platform-boundary notice already cited; ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF. No newly retained source changed confidence, victimology, timeline, technical detail, scoping, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 23-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, ControlUp, Thinkproject, Betterment/Mass.gov legal notice leads, Nudge Security Klue breach tracker, Aviatrix/Clearphish/TechJack/Beazley-style recaps, SOCRadar/BreachSense Icarus ransomware profiles, RH-ISAC, ThreatLocker, eSentire, Delinea August 2026 SaaS/OAuth explainer, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, FINRA Salesloft Drift comparator guidance, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found source-backed findings already represented on-page, product/blog updates and secondary recaps that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF; BleepingComputer's Klue/Icarus coverage remained the June 18 and June 19 incident reporting already cited; Salesforce's Klue Battlecards security advisory remained the June 17 platform-boundary notice already cited. No newly retained source changed confidence, victimology, timeline, technical detail, scoping, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 22-AUG-2026 02:00 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, ControlUp, Thinkproject, Betterment/Mass.gov legal notice leads, Nudge Security Klue breach tracker, SOCRadar/BreachSense Icarus ransomware profiles, RH-ISAC, ThreatLocker, eSentire, Delinea August 2026 SaaS/OAuth explainer, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, FINRA Salesloft Drift comparator guidance, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found source-backed findings already represented on-page, Klue product/blog updates that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF; BleepingComputer's newest Salesforce tag item remained the August 12 City-Forum comparator story already checked but not retained; Klue's newest visible public blog item was an August 20 product/Claude connector article, not an incident update. No newly retained source changed confidence, victimology, timeline, technical detail, scoping, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 21-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, ControlUp, Thinkproject, Betterment/Mass.gov legal notice leads, SOCRadar/BreachSense Icarus ransomware profiles, RH-ISAC, ThreatLocker, eSentire, Delinea August 2026 SaaS/OAuth explainer, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found source-backed findings already represented on-page, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF; BleepingComputer's newest Salesforce tag item remained the August 12 City-Forum comparator story already checked but not retained. No newly retained source changed confidence, victimology, timeline, technical detail, scoping, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 20-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | 20-Aug-2026 · Newly retained (>24h) | Newly retained (>24h): ControlUp's direct Klue Third-Party Cybersecurity Incident notice was published June 26, 2026, updated June 27, 2026, and retrieved August 20, 2026 at 02:01 AM ET. The notice adds source-backed ControlUp-specific scoping: unauthorized access to certain business data in ControlUp's Salesforce environment through Klue's integration, while ControlUp says its solutions, production environment, and infrastructure were not harmed or compromised. Freshness label: Newly retained (>24h). [53] | BLUF, Timeline, Public Victim / Disclosure Matrix, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use ControlUp as a ControlUp-specific direct notice; do not generalize its data categories or product-impact boundary across other victims. |
| 20-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | 20-Aug-2026 · Qualified | Freshness labels for this run: ControlUp Klue Third-Party Cybersecurity Incident, published June 26, 2026 and updated June 27, 2026 = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, ControlUp, Lucanet, Betterment/Mass.gov legal notice leads, SOCRadar/BreachSense Icarus ransomware profiles, Delinea August 2026 SaaS/OAuth explainer, BankInfoSecurity, RH-ISAC, ThreatLocker, Cybersecurity Dive, Dark Reading, TechRadar, TechCrunch, Rescana, Gblock, SalesforceBen, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources were checked. Duplicate reporting, SEO rewrites, sidebar/date noise, leak-site-only aggregation, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating direct customer notices from duplicate recaps, leak-site aggregation, and comparator-only OAuth reporting. |
| 19-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, Betterment/Mass.gov legal notice leads, ClaimDepot/Dapeer legal recap leads, SOCRadar Icarus ransomware profile, Bright Defense breach index, Huntress support mirror, TechJack, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, TechRadar, TechCrunch, BankInfoSecurity, Infosecurity Magazine, CybelAngel, Rescana, Crimson7, Gblock, SalesforceBen, Mallory.ai Storm-3138, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, City-Forum Salesforce/ServiceNow comparator reporting, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate legal/SEO recaps, vendor-analysis rewrites, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/City-Forum material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Betterment remained represented by the retained Mass.gov primary PDF; Thinkproject remained represented by the retained August 12 status-history closure; SOCRadar's recent profile freshness remained checked-but-not-retained aggregation/leak-site material; ClaimDepot and Dapeer did not add primary notice detail. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 18-AUG-2026 02:04 AM ET | Icarus AI Monitoring Agent | 18-Aug-2026 · Newly retained (>24h) | Newly retained (>24h): Thinkproject's public status history was updated August 12, 2026 at 2:01 PM and retrieved August 18, 2026 at 02:04 AM ET. The final update says Thinkproject's investigation into the Klue breach has concluded, Thinkproject is not aware of misuse of the affected data, and monitoring continues. This adds direct customer-notice closure to the already retained Thinkproject UAT CRM, business-contact/commercial-information, product/service non-impact, and phishing/payment-change warning boundaries. Freshness label: Newly retained (>24h). [40] | BLUF, Executive Summary, Timeline, Public Victim / Disclosure Matrix, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use Thinkproject as an organization-specific closure example; do not generalize its no-known-misuse or investigation-concluded status across other victims. |
| 18-AUG-2026 02:04 AM ET | Icarus AI Monitoring Agent | 18-Aug-2026 · Qualified | Freshness labels for this run: Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, final update August 12, 2026 2:01 PM = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, Thinkproject status history, Betterment/Mass.gov legal notice leads, SOCRadar Icarus ransomware profile, Bright Defense breach index, Huntress support mirror, TechJack, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, TechRadar, TechCrunch, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources were checked. SOCRadar's August 15 profile update was reviewed as checked-but-not-retained aggregation/leak-site material because its victim and IOC list did not improve source-backed Klue/Icarus analysis enough for public promotion and included ransomware/TTP assertions not validated by primary Klue incident sources. Duplicate legal/SEO recaps, crawler/sidebar date noise, vendor-analysis rewrites, leak-site-only claims, social posts, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating direct investigation-closure updates from duplicate summaries and leak-site-derived aggregation. |
| 17-AUG-2026 02:00 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, Betterment/Mass.gov/Dapeer legal recap leads, Nudge Security Klue tracker, Obsidian July 24 SaaS/OAuth update, SOCRadar Icarus ransomware profile, Wiz, Rescana, CybelAngel, Crimson7, Gblock, Tech-Insider, TechJack, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, TechRadar, TechCrunch, CSO Online, AppOmni, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate legal/SEO recaps, vendor-analysis rewrites, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Betterment remained represented by the retained Mass.gov primary PDF; Dapeer and similar legal recaps did not add primary detail. Obsidian's July 24 update had already been reviewed by the July 24 monitor note. SOCRadar's Aug 11 profile update remained aggregation/leak-site material without stronger source-backed uplift. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 16-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | 16-Aug-2026 · Newly retained (>24h) | Newly retained (>24h): Massachusetts Attorney General Data Breach Notification Portal / Betterment 2026-1291 - Betterment PDF, published August 5, 2026 and retrieved August 16, 2026 at 02:01 AM ET for this Icarus snapshot. The notice adds a direct downstream financial-services victimology boundary: Klue Labs Inc. was a vendor used by Betterment's sales team with access to a Salesforce database containing Betterment data; unauthorized access involved a file containing name and Social Security number; Betterment's computer systems were not accessed; and two years of Kroll identity monitoring were offered. Freshness label: Newly retained (>24h). [52] | BLUF, Public Victim / Disclosure Matrix, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Contributors, Citations, Version Change Log, PANDA index timestamp | Use Betterment as an organization-specific notice-letter boundary; do not infer Betterment product-system, brokerage, bank, account-access, credential, or raw stolen-data compromise. |
| 16-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | 16-Aug-2026 · Qualified | Freshness labels for this run: Massachusetts Attorney General / Betterment PDF, published August 5, 2026 = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, Betterment/Mass.gov/Dapeer legal recap leads, Security Arsenal RingCentral/ShinyHunters SaaS/OAuth comparator, Rescana, SOCRadar, Wiz, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, TechRadar, TechCrunch, CSO Online, AppOmni, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources were checked. Security Arsenal's August 15 RingCentral/ShinyHunters article was reviewed as Freshly reported (<24h) checked-but-not-retained comparator background because it did not change Icarus/Klue analysis. Duplicate legal/SEO recaps, vendor-analysis rewrites, leak-site-only claims, social posts, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating direct victim notices from duplicate legal/SEO recaps and comparator-only OAuth abuse reporting. |
| 15-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, Wiz Cloud Threat Landscape, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, SOCRadar Icarus ransomware profile, TechRadar, TechCrunch, CSO Online, AppOmni, FINRA Salesloft Drift and Gainsight comparator alerts, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Klue's public article index was reviewed at run time: the newest visible Klue item was an Aug 12, 2026 win-loss clips article, not a security-incident update; retained security-specific Klue items remained the July 31 CTO lessons post, July 27 integration restoration post, July 1 CrowdStrike investigation summary, and June 18 incident update. Wiz's Klue incident row was reviewed as Newly retained (>24h) checked-but-not-retained aggregation because it did not improve confidence, attribution, victimology, timeline, technical detail, scoping, mitigation, or source deconfliction over retained primary/practitioner sources. Neuracybintel's RingCentral/ShinyHunters article was reviewed as Freshly reported (<24h) checked-but-not-retained comparator background because it only referenced Klue as contextual SaaS/OAuth history and did not change Icarus/Klue analysis. Rescana Salesloft Drift/UNC6395/Icarus phrasing and similar comparator summaries were not promoted because they conflate labels without stronger source-backed attribution. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 14-AUG-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, SOCRadar Icarus ransomware profile, TechRadar, TechCrunch, CSO Online, AppOmni, FINRA Salesloft Drift and Gainsight comparator alerts, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Klue's public article index was reviewed at run time: the newest visible Klue item was an Aug 12, 2026 win-loss product/use-case article, not a security-incident update. SOCRadar's Icarus profile and Klue victim pages were reviewed but not promoted because they remained ransomware/leak-site aggregation without stronger source-backed uplift over retained Huntress, Klue, Salesforce, ReliaQuest, Datadog, SecurityWeek, BleepingComputer, TechCrunch, direct victim notices, and ZeroFox/FINRA material. Neuracybintel's Aug 14, 2026 Trezor shipping-partner article was reviewed as Freshly reported (<24h) checked-but-not-retained background because it only referenced Klue as contextual SaaS/supply-chain history and did not change Icarus/Klue analysis. FINRA Salesloft Drift and Gainsight alerts were reviewed as comparator material and did not merge UNC6395, Gainsight, Salesloft Drift, ShinyHunters, or Icarus actor labels. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 13-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary blog/security-incident/status pages, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, Protos Labs, TechRadar, TechCrunch, SalesforceBen, CSO Online, AppOmni, SOCRadar Icarus ransomware profile, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. BleepingComputer's City-Forum Salesforce/ServiceNow report was reviewed as checked-but-not-retained comparator material: published Aug 12, 2026 07:07 PM ET; retrieved Aug 13, 2026 02:01 AM ET; freshness label Freshly reported (<24h). It was not promoted because it describes guest-user exposure through Salesforce Experience Cloud and ServiceNow portals, not Klue OAuth-token theft, the Icarus actor label, or a Salesforce platform vulnerability. SOCRadar's Aug 10 Icarus profile update was also reviewed but not promoted because it remained leak-site/aggregation material without stronger source-backed analytic uplift. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 12-AUG-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary blog/security-incident/status pages, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, Protos Labs, TechRadar, TechCrunch, SalesforceBen, CSO Online, Coverbase, Beazley Security, eSentire, Channel Insider, Neuracybintel, AppOmni, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, Klue Status rows showing no new Aug 1-10 incidents, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Coverbase, Beazley, eSentire, Channel Insider, Neuracybintel, AppOmni, and similar later/generic SaaS-control summaries were reviewed but not promoted because they did not materially improve confidence, attribution, victimology, timeline, technical detail, scoping, mitigation, or source deconfliction beyond retained Klue, Salesforce, Huntress, Datadog, ReliaQuest, victim-notice, and comparator sources. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 11-AUG-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary blog/news/security-incident pages, Salesforce Trust Status, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, Protos Labs, TechRadar, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, Gainsight/Salesforce OAuth comparator material, direct customer notices and trust/status mirrors including Insurity and Thinkproject status pages, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Insurity's July 9 continuing-investigation/eDiscovery status text and Thinkproject's ongoing-monitoring status text were reviewed but not promoted because prior direct-notice scope, product-boundary, active-secret, and UAT-CRM findings are already represented and the newer visible text did not materially improve confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Mallory.ai, NHI Mgmt Group, AppOmni, Shadow Tier, Rescana, SalesforceBen, TechRadar, and similar later summaries were reviewed as secondary/comparator/generic-control material and not retained as analytic deltas. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 10-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary blog/news/security-incident pages, Salesforce Trust Status, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, Protos Labs, TechRadar, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Protos Labs' July 8 report was reviewed but not promoted because its useful claims and indicators are already retained through primary Klue, Salesforce, FINRA, ZeroFox, SecurityWeek, victim-notice, and practitioner sources. TechRadar's later second-actor recap was reviewed but did not improve the already caveated TechCrunch/SecurityWeek extortion-status handling. Rescana's Salesloft Drift/UNC6395/Icarus phrasing was again not promoted because it conflates comparator labels without stronger source-backed attribution. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 09-AUG-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary blog/news/security-incident pages, Salesforce Trust Status, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, BankInfoSecurity, Cyberpress, Mitiga, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, Instagram/Threads/social posts, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Rescana's Salesloft Drift/UNC6395/Icarus phrasing was not promoted because it conflates comparator labels without stronger source-backed attribution. OneTrust IsDown/status aggregation and Cyberpress LastPass reporting were not promoted because the relevant direct-notice and closure/scoping facts are already retained. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 08-AUG-2026 02:00 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary blog/news/security-incident pages, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, Rescana, BankInfoSecurity, Delinea August 2026 SaaS/OAuth explainer, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust centers, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, page-sidebar date noise, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. Delinea's August 2026 explainer was not promoted because it did not add source-backed confidence, attribution, victimology, timeline, technical detail, scoping, mitigation, or deconfliction beyond retained Klue, ReliaQuest, victim-notice, and comparator reporting, and it did not show a visible day-level publication timestamp in search/result text. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 07-AUG-2026 02:05 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary blog and security-incident pages, TechCrunch, Dark Reading, RH-ISAC, ThreatLocker, Rescana, CybelAngel, BankInfoSecurity, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust centers, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, page-sidebar date noise, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 06-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary blog and security-incident pages, Jamf and Recorded Future direct notices, TechCrunch, Dark Reading, SecurityWeek, RH-ISAC, ThreatLocker, Rescana, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, SOCRadar Icarus ransomware profile, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. SOCRadar's Aug 4 profile was not promoted because it did not add source-backed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction beyond the current brief and included leak-site-style victim/IOC material unsuitable for this static public product. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 05-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary pages and blog index, direct customer notices and trust centers, RH-ISAC, Dark Reading, TechRadar, ThreatLocker, Rescana, CybelAngel, Infosecurity Magazine, Field Effect, HackRead, Microsoft ShinyHunters OAuth / Storm-3138, Cloud Security Alliance, Hard2bit, UNC6395, Salesloft Drift, Gainsight comparator context, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 04-AUG-2026 02:04 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary pages and blog index, direct customer notices and trust centers, Coverbase non-human-identity/OAuth report, Unosecur non-human-identity commentary, CybelAngel LastPass/Klue recap, ThreatLocker Klue recap, RH-ISAC, Dark Reading, The Next Web, TechRadar, Tech Insider, Rescana, UNC6395, Salesloft Drift, Gainsight comparator context, Microsoft ShinyHunters OAuth / Storm-3138, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 03-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary pages and blog index, direct customer notices and trust centers, BankInfoSecurity Klue reporting, Dark Reading, CSO, Cloud Security Alliance ShinyHunters OAuth/SaaS note, Hard2bit Salesforce OAuth commentary, RH-ISAC, Rescana, FINRA Klue and Salesloft Drift alerts, UNC6395, Salesloft Drift, Gainsight comparator context, Microsoft ShinyHunters OAuth / Storm-3138, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 02-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary updates including the July 27 restored-integrations update and July 31 CTO security-lessons post, Salesforce platform-boundary messaging, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, Hard2bit Salesforce OAuth commentary, RH-ISAC, Rescana, UNC6395, Salesloft Drift, Gainsight comparator context, FINRA Salesloft Drift comparator guidance, generic SaaS/OAuth control commentary, social/search rewrites, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, duplicate summaries, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 01-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | 01-Aug-2026 · Freshly reported (<24h) | Freshly reported (<24h): Klue's July 31, 2026 CTO post was published July 31, 2026 at 6:50 PM ET and retrieved August 1, 2026 at 02:02 AM ET. It adds primary engineering precision to the Icarus/Klue mechanism: GitHub PAT access enabled source-code download, discovery of an additional PAT, credential testing, unauthorized build/deployment-path abuse, a tampered production workload, stored OAuth-token access, June 12 containment, CrowdStrike's no-post-containment-activity finding, and durable control lessons for GitHub/CI-CD, short-lived credentials, workload identity, default-deny deployment networking, OAuth refresh-token rotation or idle expiration, IP-range allow-listing, least-privilege integration accounts, and distributed incident evidence. Freshness label: Freshly reported (<24h). [51] | BLUF, Executive Summary, Timeline, How The Campaign Works, IR Playbook, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Contributors, Citations, Version Change Log, PANDA index timestamp | Use this as root-cause and vendor-control precision; keep actor attribution, victimology, and Salesforce platform-vulnerability boundaries unchanged. |
| 01-AUG-2026 02:02 AM ET | Icarus AI Monitoring Agent | 01-Aug-2026 · Qualified | Freshness labels for this run: Klue What a Security Incident Taught Us About Securing a Modern SaaS Platform, published July 31, 2026 6:50 PM ET = Freshly reported (<24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary updates, the July 27 restored-integrations update, the July 31 CTO lessons-learned post, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, Hard2bit July 30/31 generic Salesforce OAuth commentary, RH-ISAC, Rescana, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources were checked. Duplicates, SEO rewrites, secondary summaries, leak-site-only claims, social posts, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating engineering root-cause precision from customer-specific exposure closure. |
| 31-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary updates including the July 27 restoration notice, Salesforce platform-boundary messaging, direct customer notices, Obsidian's July 24 SaaS/OAuth update, Microsoft ShinyHunters OAuth / Storm-3138, RH-ISAC, Rescana, Hard2bit same-day generic Salesforce OAuth summary, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older source-backed findings already represented on-page, same-day generic OAuth commentary that did not change Icarus/Klue analysis, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 30-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | 30-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Klue's July 27, 2026 primary update says Salesforce and Gong reinstated Klue integrations in their marketplaces and all Klue integrations were again available for customer enablement after CrowdStrike's independent review of response and remediation. Klue also states that all outbound Klue traffic now routes through static egress IPs allow-listed by Salesforce and Gong, PKCE is required platform-wide, OAuth token lifecycle policies were tightened, GitHub PATs were eliminated in favor of short-lived automatically expiring credentials, centralized monitoring and detection were added, and runtime network filtering plus allowlist controls were implemented across deployment pipelines. Source publication timestamp/date: July 27, 2026; retrieval/run timestamp: July 30, 2026 02:01 AM ET. Freshness label: Newly retained (>24h). [50] | BLUF, Executive Summary, Timeline, How The Campaign Works, IR Playbook, Source Summary & Confidence, Source Deconfliction, Source Weighting, About Contributors, Citations, Version Change Log, PANDA index timestamp | Use the update as a remediation/restoration milestone only; do not weaken per-customer scoping, notification, or historical exposure requirements. |
| 30-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | 30-Jul-2026 · Qualified | Freshness labels for this run: Klue Integrations Restored: Salesforce and Gong Reconnected, July 27, 2026 = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer trust centers, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources were checked. Duplicate reporting, SEO rewrites, secondary summaries, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating restored integration availability from confirmed incident closure for individual downstream victims. |
| 29-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary updates, Salesforce platform-boundary messaging, direct customer trust centers, LastPass, Jamf, Huntress, Datadog Security Labs, RH-ISAC, Obsidian, Field Effect, Rescana, Beazley Security, Kudelski Security, ThreatLocker, Tech Insider, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older direct notices and practitioner findings already represented on-page, advisory-style duplicate summaries, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 28-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary updates, Salesforce platform-boundary messaging, direct customer trust centers, LastPass, Jamf, Huntress, Datadog Security Labs, RH-ISAC, Obsidian, Field Effect, Rescana Salesforce/OAuth summaries, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older direct notices and practitioner findings already represented on-page, LastPass related-post date noise without a Klue incident-body update, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 27-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Klue primary updates, Salesforce platform-boundary messaging, direct customer trust centers, Commvault Trust Center, Lucanet Trust Center, Snyk Trust Center, Blackbaud Trust Center, Microsoft ShinyHunters OAuth / Storm-3138, RH-ISAC, Obsidian, Field Effect, Rescana Salesforce/OAuth summaries, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older direct notices and practitioner findings already represented on-page, JavaScript-only or app-shell trust-center bodies without stable inspectable incident text, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 26-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | 26-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Blackbaud's public Trust Center announcement updated July 22, 2026 at 20:05 UTC / 4:05 PM ET was newly used by this run. Blackbaud says Klue notified it of the incident, its investigation remains ongoing with no substantive update as of July 22, and there is no known impact to Blackbaud products, business operations, or ability to serve customers. Source publication timestamp/date: July 22, 2026 20:05 UTC / 4:05 PM ET; retrieval/run timestamp: July 26, 2026 02:03 AM ET. Freshness label: Newly retained (>24h). [49] | AI Agent Delta Updates, Public Victim / Disclosure Matrix, Executive Summary, Source Summary & Confidence, Source Weighting / Relevance, Real World Examples, Citations, Version Change Log, PANDA index timestamp | Use Blackbaud as an organization-specific direct notice; do not treat the ongoing-investigation or no-product-impact language as a boundary for other victims. |
| 25-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, RH-ISAC, Obsidian, Field Effect, ScruteX, Tech Insider, Rescana Salesforce/OAuth summaries, Microsoft-derived summaries, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older direct notices and practitioner findings already represented on-page, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, weekly brief roundups, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, subscriber alert, or notification was sent under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 24-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, RH-ISAC, Obsidian, Field Effect, ScruteX, Tech Insider, Rescana Salesforce/OAuth summaries, Camunda Trust Center metadata updated July 23, Snyk status history, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older direct notices and practitioner findings already represented on-page, Camunda trust-center profile metadata without accessible Klue-specific incident-text change, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, subscriber alert, or notification was sent under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 23-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Salesforce MFA/control updates, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, The Hacker News Microsoft summary, TechRadar Microsoft summary, Rescana Salesforce/OAuth summaries, Mitiga ShinyHunters/UNC6395/Salesloft Drift comparator analysis updated July 22, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found older direct notices already represented on-page, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, subscriber alert, or notification was sent under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 22-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Salesforce MFA/control updates, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, The Hacker News Microsoft summary, TechRadar Microsoft summary, Rescana Salesforce/OAuth summaries, Mitiga ShinyHunters/UNC6395/Salesloft Drift comparator analysis, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, subscriber alert, or notification was sent under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 21-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, Salesforce MFA/control updates, direct customer notices, Microsoft ShinyHunters OAuth / Storm-3138, The Hacker News Microsoft summary, TechRadar Microsoft summary, Rescana Salesforce/OAuth summaries, Mitiga ShinyHunters/UNC6395/Salesloft Drift comparator analysis, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. No external email, subscriber alert, or notification was sent under the automation no-email policy. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 19-JUL-2026 02:04 AM ET | Icarus AI Monitoring Agent | 19-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): OneTrust's July 10 update to its Klue Security Incident notice was newly used by this run. OneTrust says its technical investigation is complete, scope and impacted data have been validated, containment and remediation are finalized, the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment following June 12 containment measures, and post-incident governance/compliance processes remain ongoing. Source publication timestamp/date: July 10, 2026; retrieval/run timestamp: July 19, 2026 02:04 AM ET. Freshness label: Newly retained (>24h). [38] | AI Agent Delta Updates, Executive Summary, Timeline, Victim Matrix, Source Summary, Source Deconfliction, Real World Examples, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use OneTrust as an organization-specific investigation-closure example; do not generalize its containment, scope validation, or regulatory-review status across other victims. |
| 18-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, The Hacker News, TechRadar, SC World, Rescana, Microsoft ShinyHunters OAuth, Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, and related Salesforce/OAuth comparator sources. Search results found Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 17-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, OneTrust, Microsoft ShinyHunters OAuth, The Hacker News, TechRadar, Mitiga UNC6395/Salesloft Drift, UNC6395, Salesloft Drift, and related Salesforce/OAuth comparator sources. Search results found Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift analysis, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 16-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Microsoft ShinyHunters OAuth, UNC6395, Salesloft Drift, The Hacker News, TechRadar, and related Salesforce/OAuth comparator sources. Search results found Microsoft-derived secondary rewrites, older direct notices already represented on-page, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 15-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | 15-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Microsoft's July 13 research on ShinyHunters-associated Salesforce OAuth abuse was added as an expansion/deconfliction source. It identifies the June 2026 Klue incident as Storm-3138 activity, places it in a broader pattern of trusted OAuth relationship abuse, preserves that the activity was not caused by a Salesforce platform vulnerability, and adds connected-app attribution, Salesforce RTEM, high-privilege/unused-app posture, risk-score, and hunting guidance. [48] | BLUF, Executive Summary, Timeline, Associated Campaigns, Forensic Indicators, IR Playbook, MITRE Mapping, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use Storm-3138 as Microsoft-specific source nomenclature; do not merge Icarus with UNC6395, Salesloft Drift, or ShinyHunters solely from this source. |
| 15-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | 15-Jul-2026 · Qualified | Freshness label for this run: Microsoft Security Blog, July 13, 2026 = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Microsoft ShinyHunters OAuth, UNC6395, Salesloft Drift, Salesforce OAuth comparator, and related SaaS/OAuth governance sources were checked. Duplicates, older direct notices already represented on-page, SEO rewrites, social posts, leak-site-only claims, and unsupported actor-label conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating Microsoft Storm-3138 nomenclature, Icarus public extortion labeling, and UNC6395/Salesloft Drift comparator attribution. |
| 13-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Camunda Trust Center, Tanium, Cresta Trust Center, RH-ISAC, Dark Reading, TechCrunch, Rescana, CybersecurityDive, SC World, UNC6395, Salesloft Drift, and related Salesforce/OAuth comparator sources. Search results found duplicates, older direct notices already represented on-page, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, access-controlled or JavaScript-only trust-center shells, and unsupported Icarus/UNC6395/Salesloft Drift conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 12-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 12-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Camunda's machine-readable Trust Center now exposes Klue/Salesforce investigation updates, including a final July 1 update stating external validation supported limiting exfiltrated data to standard business-contact and account information in Salesforce CRM and excluding support data. Tanium's June 18 direct notice was also retained to move Tanium from aggregate victimology into direct scoping: Salesforce CRM sales-account and business-contact data may have been compromised, while support information, passwords, customer security data, products, and cloud infrastructure were excluded. [46, 47] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Summary, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use Camunda and Tanium as organization-specific direct notices; do not generalize their support-data, password, product, or cloud-infrastructure exclusions across other victims. |
| 12-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 12-Jul-2026 · Qualified | Freshness labels for this run: Camunda Trust Center Klue/Salesforce Security Breach - Investigation Update, final update July 1, 2026 and trust-center profile update July 10, 2026 08:44 UTC = Newly retained (>24h); Tanium Security Update, June 18, 2026 = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Camunda Trust Center, Tanium, Lucanet Trust Center, Snyk Trust Center, SentinelOne/Secure ISS, UNC6395, Salesloft Drift, and related Salesforce/OAuth comparator sources were checked. CybersecurityNews, Supplier Shield, Rescana, social posts, SEO rewrites, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue retaining only direct notices or reliable analysis that improves victimology, scoping, mitigation, attribution, or deconfliction. |
| 11-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, OneTrust, Snyk Status, SentinelOne/Secure ISS, UNC6395, Salesloft Drift, and related Salesforce/OAuth comparator sources. Search results found duplicates, older direct notices already represented on-page, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, access-controlled or JavaScript-only status shells, and unsupported Icarus/UNC6395/Salesloft Drift conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 10-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 10-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Secure ISS published a July 9 public write-up sharing SentinelOne's Klue partner update. It says SentinelOne completed an independently verified forensic investigation, impact was contained entirely within SentinelOne's Salesforce environment through the Klue API integration, there was no lateral movement into SentinelOne systems, and core products, cloud infrastructure, production environments, and services were not affected. SentinelOne's data analysis remains ongoing for any separate direct notifications. [45] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Summary, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use SentinelOne as an organization-specific scoping example; do not generalize its Salesforce-only containment or ongoing data-analysis status across other victims. |
| 10-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 10-Jul-2026 · Qualified | Freshness labels for this run: Secure ISS SentinelOne Confirms Klue Supply Chain Incident Contained to Salesforce, July 9, 2026 = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, Camunda Trust Center, NetDocuments TrustShare, SentinelOne/Secure ISS, Snyk Trust Center, UNC6395, and Salesloft Drift comparator results were checked. Camunda and NetDocuments incident details were not promoted because the accessible public pages did not expose enough source text for direct retention in this run. Duplicate reporting, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue retaining only sources that improve victimology, scoping, mitigation, attribution, or deconfliction. |
| 09-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 09-Jul-2026 · Freshly reported (<24h) | Freshly reported (<24h): Snyk's status page resolved the Klue incident on July 8, 2026 at 15:26 UTC / 11:26 AM ET, stating its Mandiant-assisted forensic investigation was complete, impact was limited to business CRM data, all impacted customers were directly notified, and no evidence of impact to the Snyk platform or sensitive data within it was found. [44] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Summary, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use Snyk as a direct customer closure example; do not generalize platform or sensitive-data exclusions across other victims. |
| 09-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 09-Jul-2026 · Qualified | Freshness labels for this run: Snyk Status Third-Party Vendor Security Incident (Klue), resolved July 8, 2026 15:26 UTC / 11:26 AM ET = Freshly reported (<24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, UNC6395, Salesloft Drift, Snyk Trust Center, and Snyk Status results were checked. Duplicate reporting, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue retaining only sources that improve victimology, scoping, mitigation, attribution, or deconfliction. |
| 08-JUL-2026 02:04 AM ET | Icarus AI Monitoring Agent | 08-Jul-2026 · Newly retained (>24h) 08-Jul-2026 · Newly retained; undated | Newly retained (>24h): OneTrust's June 24 direct notice, Tines' July 1 investigation update, and Thinkproject's June 26 status update add organization-specific Salesforce/CRM impact boundaries and response steps. Newly retained (publication date not visible): Cresta, AlertMedia, and ABBYY trust-center notices add direct customer-boundary evidence for Salesforce/CRM exposure, product/platform non-impact, and credential or integration response. [38, 39, 40, 41, 42, 43] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use these notices as organization-specific scoping evidence; do not generalize support-adjacent, sensitive-information, credential, or product-impact findings across other victims. |
| 08-JUL-2026 02:04 AM ET | Icarus AI Monitoring Agent | 08-Jul-2026 · Qualified | Freshness labels for this run: OneTrust Update From OneTrust on Klue Security Incident, June 24, 2026 = Newly retained (>24h); Tines The impact of the Klue breach on Tines and our customers, updated July 1, 2026 = Newly retained (>24h); Thinkproject status update, June 26, 2026 6:47 AM = Newly retained (>24h); Cresta Trust Center, AlertMedia Trust Center, and ABBYY Trust Center notices = Newly retained (publication date not visible). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, UNC6395, and Salesloft Drift comparator results were checked. Duplicate reporting, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue retaining only sources that improve victimology, scoping, mitigation, attribution, or deconfliction. |
| 07-JUL-2026 02:03 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer notices, UNC6395, Salesloft Drift, and related Salesforce/OAuth comparator sources. Search results found duplicates, older direct notices already represented on-page, syndicated rewrites, SEO summaries, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 06-JUL-2026 02:00 AM ET | Icarus AI Monitoring Agent | 06-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Deel's June 26 direct notice confirms unauthorized access to business contact and commercial CRM information through a compromised Klue connection, plus a very limited amount of personal data synced to CRM, while stating the Deel platform itself was not involved. Insurity's June 22 status notice confirms Salesforce/Klue suspicious activity, cloud/product/infrastructure non-impact, CRM business-contact exposure, and a very limited set of active credentials/secrets found within CRM data and proactively rotated or reset. [36, 37] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use Deel and Insurity as organization-specific direct notices; do not generalize limited personal-data or active-secret findings across other victims. |
| 06-JUL-2026 02:00 AM ET | Icarus AI Monitoring Agent | 06-Jul-2026 · Qualified | Freshness labels for this run: Deel Klue security incident - Deel impact, Last Update June 26, 2026 = Newly retained (>24h); Insurity Status Notification of Salesforce / Klue Security Incident, updated June 22, 2026 11:05 AM EDT = Newly retained (>24h). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer-notice, UNC6395, and Salesloft Drift comparator results were checked; no Freshly reported (<24h) source changed the analysis, and duplicate reporting, SEO rewrites, leak-site-only claims, and unsupported Icarus/UNC6395 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue retaining only sources that improve victimology, scoping, mitigation, attribution, or deconfliction. |
| 05-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | 05-Jul-2026 · Newly retained; undated | Newly retained (publication date not visible): Postman's Security & Trust Portal notice confirms customer contact and sales information was exfiltrated from Postman's Salesforce environment via the compromised Klue service account between June 11-12, while stating customer data was not accessed from Gong and Postman's core platform services remained secure and were not impacted. [35] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use Postman's notice as a direct customer-boundary example; do not generalize its Salesforce/Gong split or core-platform exclusion to other victims. |
| 05-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | 05-Jul-2026 · Qualified | Freshness labels for this run: Postman Security & Trust Portal Notice of Security Incident = Newly retained (publication date not visible). Public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, direct customer-notice, UNC6395, and Salesloft Drift comparator results were checked; duplicate reporting, SEO rewrites, leak-site-only claims, and unsupported Icarus/UNC6395 conflation were not promoted. Next scheduled run: Daily at 6:00 AM ET for 2 years. | AI Agent Delta Updates, Citations, Version Change Log | Continue adding only direct notices or source-backed analysis that improves victimology, scoping, timeline, mitigation, attribution, or deconfliction. |
| 04-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, RH-ISAC Klue, SalesforceBen Klue, FINRA Klue/Salesloft Drift, UNC6395, and Salesloft Drift comparator sources. Search results found duplicates, older direct notices already represented on-page, secondary rewrites, roundup/SEO summaries, leak-site-only claims, and unsupported Icarus/UNC6395 conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 03-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 03-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): Klue's July 1 CrowdStrike investigation summary adds root-cause and containment precision: a previously compromised GitHub PAT (personal access token) was used to introduce unauthorized code into Klue's integration service, collect third-party integration credentials including Salesforce OAuth access and refresh tokens, and trigger Salesforce's June 12 notification. Klue says it disabled affected GKE pods (Google Kubernetes Engine runtime workloads) and PATs, rotated OAuth credentials, CrowdStrike found no evidence of access outside integration-service systems, and found no Klue-environment threat-actor activity after June 12. [34] | BLUF, Executive Summary, Timeline, How The Campaign Works, Forensic Indicators, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use the new Klue/CrowdStrike details for root-cause, containment, and vendor-governance framing; do not change Icarus attribution or Salesforce platform-vulnerability boundaries. |
| 03-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 03-Jul-2026 · Qualified | Freshness labels for this run: Klue CrowdStrike Investigation Summary, July 1, 2026 = Newly retained (>24h). SalesforceBen's July 1 recap, RH-ISAC, Rescana, Cybersecurity Dive, CSO, Dark Reading, Field Effect, ThreatLocker, FINRA Salesloft Drift comparator material, current Salesforce/Klue/status pages, direct victim notices, leak-site-only claims, and UNC6395/Salesloft Drift results were checked but not promoted as separate Icarus deltas. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating primary vendor investigation updates from duplicate summaries, SEO rewrites, and comparator-only UNC6395 material. |
| 02-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 02-Jul-2026 · Newly retained (>24h) | Newly retained (>24h): LogicMonitor's June 26 notice confirms unauthorized access to Catchpoint's Salesforce environment and business relationship / sales activity data exposure while excluding LogicMonitor's primary Salesforce environment, customer monitoring data, production systems data, credentials, payment information, and operational customer data. 02-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible): Saviynt's Trust Portal notice confirms Saviynt was impacted, limits potential impact to certain sales data in Salesforce, and excludes Saviynt products, services, and customer data in Saviynt products. [32, 33] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use the two direct notices for organization-specific impact boundaries; do not generalize exposed fields or core-product impact across victims. |
| 02-JUL-2026 02:02 AM ET | Icarus AI Monitoring Agent | 02-Jul-2026 · Qualified | Freshness labels for this run: LogicMonitor June 26, 2026 = Newly retained (>24h); Saviynt Trust Portal = Newly retained (publication date not visible). SalesforceBen, SANS NewsBites, TechRadar, Salesforce/Klue/status pages, current BleepingComputer/SecurityWeek/TechCrunch rewrites, leak-site-only claims, and UNC6395/Salesloft Drift comparator results were checked but not promoted as independent deltas. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating direct customer notices from duplicate media summaries and claim-only actor chatter. |
| 01-JUL-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, FINRA Klue, ZeroFox Icarus, UNC6395, and Salesloft Drift comparator sources. Search results found duplicates, older direct notices already represented on-page, secondary rewrites, and unsupported comparator conflation. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 30-JUN-2026 02:01 AM ET | Icarus AI Monitoring Agent | 30-Jun-2026 · Newly retained (>24h) | Newly retained (>24h): FINRA's June 26 alert adds financial-sector guidance, expanded connected-platform exposure context, suspicious IP and sender-domain indicators, and the "mr bean" extortion alias. ZeroFox's June 26 profile adds first-observed timing, financially motivated R&DE assessment, DLS/direct-email tradecraft, suspicious user-agent indicators, and a caveated possible SLH association that remains unconfirmed by Icarus. [30, 31] | BLUF, Executive Summary, Timeline, Profile, Associated Campaigns, Forensic Indicators, IOCs, IR Playbook, Source Deconfliction, Source Weighting, Citations, Version Change Log, PANDA index timestamp | Use the added indicators as hunting leads and preserve the SLH link as circumstantial until independently corroborated. |
| 30-JUN-2026 02:01 AM ET | Icarus AI Monitoring Agent | 30-Jun-2026 · Qualified | Freshness labels for this run: FINRA June 26, 2026 = Newly retained (>24h); ZeroFox June 26, 2026 4:25 PM ET, modified June 29, 2026 9:18 AM ET = Newly retained (>24h). OneTrust/GMS/NoPass direct-notice leads, current Salesforce/Klue/status pages, TechCrunch/SecurityWeek/BleepingComputer rewrites, leak-site-only claims, and UNC6395/Salesloft Drift comparator results were checked but not promoted as separate deltas. | AI Agent Delta Updates, Citations, Version Change Log | Continue separating newly retained source-backed detail from duplicate reporting and claim-only actor chatter. |
| 29-JUN-2026 02:01 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce status, UNC6395, and Salesloft Drift comparator sources. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 28-JUN-2026 02:00 AM ET | Icarus AI Monitoring Agent | No source-backed content delta | AI Monitoring Agent checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Huntress, LastPass, Jamf, Recorded Future, SecurityWeek, BleepingComputer, ReliaQuest, Datadog, Salesforce status, UNC6395, and Salesloft Drift comparator sources. No newly retained source changed confidence, victimology, timeline, technical detail, mitigation, attribution, or deconfliction. Freshness labels applied to retained sources: none. | AI Agent Delta Updates, Version Change Log, PANDA index timestamp | No analytic action; continue scheduled public-source monitoring. |
| 27-JUN-2026 02:02 AM ET | Icarus AI Monitoring Agent | 27-Jun-2026 · Freshly reported (<24h) | Freshly reported (<24h): SecurityWeek updated the public disclosure picture from roughly 15 emerging victims to roughly two dozen Klue customers that had notified customers of incident impact, and named additional organizations including AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. Autodesk was retained as a non-impact caveat because it may not have used the Salesforce integration. [28] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Deconfliction, Source Weighting, Citations, Version Change Log | Treat the expanded list as disclosed-victimology context, not a uniform data-field or materiality finding. |
| 27-JUN-2026 02:02 AM ET | Icarus AI Monitoring Agent | 27-Jun-2026 · Newly retained (>24h) | Newly retained (>24h): Link11 published a direct notice confirming certain Salesforce CRM data was affected through the Klue integration while excluding core systems, products, operational security infrastructure, and customer systems. Jamf's June 26 update further narrowed Jamf impact to Salesforce data accessed through Klue credentials, with no lateral movement or other system/credential access found. [18, 29] | Victim Matrix, Real World Examples, Source Weighting, Citations, Version Change Log | Use direct notices for organization-specific impact boundaries; keep SecurityWeek for scale and cross-notice synthesis. |
| 27-JUN-2026 02:02 AM ET | Icarus AI Monitoring Agent | 27-Jun-2026 · Qualified | Freshness labels for this run: SecurityWeek June 26, 2026 11:01 AM ET = Freshly reported (<24h); Link11 June 25, 2026 and Jamf June 26 date-only update = Newly retained (>24h). TechRadar, TNW, Security Boulevard commentary, Field Effect, Nudge Security, Tines, and older BleepingComputer/THN/ReliaQuest/Salesforce comparator results were checked but not promoted as independent deltas. | AI Agent Delta Updates, Citations, Version Change Log | Continue withholding freshness labels from duplicate rewrites and claim-only leak-site amplification. |
| 26-JUN-2026 02:01 AM ET | Icarus AI Monitoring Agent | 26-Jun-2026 · Freshly reported (<24h) | Freshly reported (<24h): TechCrunch reported a customer-update-based status change: Klue said it remained in contact with Icarus, Icarus said it was taking steps to delete data, the Icarus site appeared down, and a second unnamed actor claimed to have samples for a subset of customers while pursuing direct extortion. Payment, operator-identity, total-customer-count, and full data-possession claims remain unverified or claim-only. [27] | Executive Summary, Timeline, Associated Campaigns, Source Deconfliction, Real World Examples, Citations, Version Change Log | Treat the status as a live extortion-process update, not confirmation that data is fully deleted or that the second actor holds the complete dataset. |
| 26-JUN-2026 02:01 AM ET | Icarus AI Monitoring Agent | 26-Jun-2026 · Newly retained (>24h) | Newly retained (>24h): Obsidian Security added practitioner support for stale SaaS integration risk, OAuth app inventory, risky-scope review, blast-radius mapping, centralized token revocation, and checks for persistence such as new OAuth apps, admin accounts, or webhooks. [26] | BLUF, How The Campaign Works, Forensic Indicators, Source Weighting, Citations, Version Change Log | Use the added practitioner source to strengthen defensive scoping; do not treat vendor product guidance as proof of a different actor or a Salesforce platform exploit. |
| 26-JUN-2026 02:01 AM ET | Icarus AI Monitoring Agent | 26-Jun-2026 · Qualified | Freshness labels for this run: TechCrunch = Freshly reported (<24h); Obsidian Security = Newly retained (>24h) because the source exposed a publication date but no exact publication time, so the monitor did not call it fresh. Duplicate rewrites from TNW, TechRadar, THN weekly roundup, Paubox, RH-ISAC, Dark Reading, and SEO/newsletter summaries were checked but not promoted. | AI Agent Delta Updates, Citations, Version Change Log | Continue applying exact freshness labels per source on future runs. |
| 25-JUN-2026 02:03 AM ET | Icarus AI Monitoring Agent | 25-Jun-2026 · Added | The monitor newly retained direct victim notices and an 8x8 SEC filing that were previously represented mostly through media aggregation. These sources strengthened the downstream-victim evidence for HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8. [20, 21, 22, 23, 24, 25] | BLUF, Executive Summary, Timeline, Victim Matrix, Real World Examples, Source Weighting, Citations | Use each direct notice as the controlling source for that organization's exact impact boundary; do not generalize one victim's exposed fields to all victims. |
| 25-JUN-2026 02:03 AM ET | Icarus AI Monitoring Agent | 25-Jun-2026 · Qualified | Freshness was explicitly qualified: HackerOne, BeyondTrust, Pendo, and 8x8 were newly retained >24h after publication; Sprout Social and LastPass were newly retained with no visible page-publication date. No added source was labeled freshly reported (<24h). | AI Agent Delta Updates, Citations, Version Change Log | Keep the freshness distinction visible during future monitoring runs: Freshly reported (<24h), Newly retained (>24h), or Newly retained (publication date not visible). |
| 25-JUN-2026 02:03 AM ET | Icarus AI Monitoring Agent | 25-Jun-2026 · Qualified | No reliable source merged Icarus with UNC6395, and no source changed Salesforce's platform-vulnerability boundary. The update preserved Icarus/Klue as the subject and UNC6395/Salesloft Drift as comparator context. [2, 10, 11] | Source Deconfliction, Q&A, Associated Campaigns, Executive Summary | Continue treating UNC6395 as adjacent Salesforce/OAuth tradecraft unless a reliable source explicitly merges the actor labels. |
30-Version Change Log
| Version | Date | Changes |
|---|---|---|
| v1.0 | 24-JUN-2026 | Initial static Actor / Tool / Campaign Snapshot for Icarus. |
| v1.1 | 24-JUN-2026 | Added Icarus/UNC6395 deconfliction, richer named-victim examples, OAuth/Salesforce API mechanics, support-data scoping, expanded MITRE mapping, and extortion-vs-ransomware boundary. |
| v1.2 | 24-JUN-2026 | Added complete Tier 0 through Tier 8 source coverage, public activity timeline, victim/disclosure matrix, and associated-campaigns table. |
| v1.3 | 24-JUN-2026 | Rebuilt source deconfliction as agreement/difference analysis, added separate Q&A, added FortiBleed-style cards, inserted header metadata/traffic-light classification, and prepared daily AI Monitoring Agent schedule. |
| v1.4 | 25-JUN-2026 02:03 AM ET | 25-Jun-2026 · AddedAI Monitoring Agent found a source-backed source-quality delta: added newly retained direct notices for HackerOne, BeyondTrust, Sprout Social, Pendo, LastPass, and 8x8's SEC 8-K; updated victim matrix, timeline, real-world examples, source weighting, citations, and source coverage counts. No subtractions. 25-Jun-2026 · QualifiedFreshness was qualified as newly retained rather than freshly reported. |
| v1.5 | 26-JUN-2026 02:01 AM ET | 26-Jun-2026 · Freshly reported (<24h)AI Monitoring Agent added TechCrunch's fresh extortion-status reporting: Icarus deletion/site-down claims and a second unnamed actor's direct-extortion claims, with payment, operator identity, complete data possession, customer-count, and deletion assertions explicitly qualified. 26-Jun-2026 · Newly retained (>24h)Added Obsidian Security's practitioner analysis for OAuth app governance, risky-scope review, blast-radius mapping, token revocation, and persistence checks. No subtractions; source coverage increased to 28 checked / 27 used. |
| v1.6 | 27-JUN-2026 02:02 AM ET | 27-Jun-2026 · Freshly reported (<24h)AI Monitoring Agent added SecurityWeek's June 26 victimology update: roughly two dozen public notifications, additional named organizations, Salesforce Klue-integration-not-yet-reenabled status, and Autodesk non-impact caveat. 27-Jun-2026 · Newly retained (>24h)Newly retained Link11 direct notice and Jamf June 26 date-only investigation update for direct impact-boundary precision. No subtractions; duplicate TechRadar/TNW rewrites, Security Boulevard commentary, Tines trust-center signal, and older comparator results were checked but not promoted. Source coverage increased to 34 checked / 29 used. |
| v1.6 | 28-JUN-2026 02:00 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. PANDA index date updated to Updated Jun 28, 2026. |
| v1.6 | 29-JUN-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. PANDA index date updated to Updated Jun 29, 2026. |
| v1.7 | 30-JUN-2026 02:01 AM ET | 30-Jun-2026 · Newly retained (>24h)AI Monitoring Agent newly retained FINRA's June 26 Klue OAuth/Salesforce alert and ZeroFox's June 26 Icarus intelligence profile. Added financial-sector guidance, public IP/sender-domain/user-agent hunting leads, "mr bean" alias corroboration, late-April / early-May first-observed timing, operational-maturity caveats, and SLH association deconfliction. No freshly reported (<24h) sources. No subtractions; no change to Salesforce platform-vulnerability boundary or UNC6395 comparator treatment. PANDA index date updated to Updated Jun 30, 2026. |
| v1.7 | 01-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, previously retained direct notices, leak-site-only claims, and unsupported UNC6395/Salesloft Drift conflation were not promoted. PANDA index date updated to Updated Jul 1, 2026. |
| v1.8 | 02-JUL-2026 02:02 AM ET | 02-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained LogicMonitor's June 26 Catchpoint/Klue notice and 02-Jul-2026 · Newly retained; undatedSaviynt's Trust Portal notice with no visible page-publication date. Added direct customer-notice precision for Salesforce sales/CRM data exposure and product, primary-Salesforce, production, monitoring, credential, payment, and operational-data exclusions. No freshly reported (<24h) sources; no subtractions; no change to Salesforce platform-vulnerability boundary or UNC6395 comparator treatment. PANDA index date updated to Updated Jul 2, 2026. |
| v1.9 | 03-JUL-2026 02:02 AM ET | 03-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Klue's July 1 CrowdStrike investigation summary. Added primary vendor root-cause and containment precision for the compromised GitHub PAT, unauthorized integration-service code, Salesforce OAuth access and refresh token collection, affected GKE pod/PAT disablement, OAuth credential rotation, no identified access outside integration-service systems, no Klue-environment threat-actor activity after June 12, and vendor hardening actions. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395 comparator treatment. PANDA index date updated to Updated Jul 3, 2026. |
| v1.9 | 04-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, roundup/SEO summaries, previously retained direct notices, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 4, 2026. |
| v2.0 | 05-JUL-2026 02:01 AM ET | 05-Jul-2026 · Newly retained; undatedAI Monitoring Agent newly retained Postman's Security & Trust Portal notice as Newly retained (publication date not visible). Added direct customer-notice precision for Salesforce customer contact and sales-information exfiltration through the compromised Klue service account between June 11-12, Postman's Gong customer-data non-access caveat, and Postman core-platform-services non-impact boundary. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395 comparator treatment. PANDA index date updated to Updated Jul 5, 2026. |
| v2.1 | 06-JUL-2026 02:00 AM ET | 06-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Deel's June 26 direct notice and Insurity's June 22 status notice as Newly retained (>24h). Added direct customer-notice precision for Deel business-contact/commercial CRM exposure, limited personal-data-in-CRM caveat, vendor access and token/session response, Insurity CRM business-contact exposure, limited active credentials/secrets found within CRM data and rotated/reset, and product/platform/cloud/infrastructure non-impact boundaries. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395 comparator treatment. PANDA index date updated to Updated Jul 6, 2026. |
| v2.1 | 07-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, syndicated rewrites, SEO summaries, social posts, older direct notices already represented on-page, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 7, 2026. |
| v2.2 | 08-JUL-2026 02:04 AM ET | 08-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained OneTrust's June 24 direct notice, Tines' July 1 investigation update, and Thinkproject's June 26 status update as Newly retained (>24h). 08-Jul-2026 · Newly retained; undatedNewly retained (publication date not visible): Cresta, AlertMedia, and ABBYY trust-center notices. Added direct customer-notice precision for Salesforce/CRM, support-adjacent, UAT CRM, sensitive-information, product/platform/customer-environment, network/product/technology, and credential/integration response boundaries. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395/Salesloft Drift comparator treatment. PANDA index date updated to Updated Jul 8, 2026. |
| v2.3 | 09-JUL-2026 02:02 AM ET | 09-Jul-2026 · Freshly reported (<24h)AI Monitoring Agent freshly retained Snyk's July 8 status resolution as Freshly reported (<24h). Added direct customer forensic-closure precision: Mandiant-assisted investigation complete, impact limited to business CRM data, all impacted customers directly notified, no evidence of Snyk platform or sensitive-data impact, and Klue/Salesforce integration response context. No subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395/Salesloft Drift comparator treatment. PANDA index date updated to Updated Jul 9, 2026. |
| v2.4 | 10-JUL-2026 02:02 AM ET | 10-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Secure ISS's July 9 public write-up sharing SentinelOne's Klue partner update as Newly retained (>24h). Added SentinelOne-specific public scoping: completed independently verified forensic investigation, impact contained to Salesforce through the Klue API integration, no lateral movement into SentinelOne systems, no core product, cloud infrastructure, production-environment, or service impact, and ongoing data-analysis/direct-notification caveat. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395/Salesloft Drift comparator treatment. PANDA index date updated to Updated Jul 10, 2026. |
| v2.4 | 11-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, older direct notices already represented on-page, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, access-controlled or JavaScript-only status shells, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 11, 2026. |
| v2.5 | 12-JUL-2026 02:02 AM ET | 12-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Camunda Trust Center and Tanium direct notices as Newly retained (>24h). Added Camunda-specific final scoping for standard business-contact/account information in Salesforce CRM with support-data exclusion, and Tanium-specific scoping for Salesforce sales-account/business-contact information with support-information, password, customer-security-data, product, and cloud-infrastructure exclusions. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, or UNC6395/Salesloft Drift comparator treatment. PANDA index date updated to Updated Jul 12, 2026. |
| v2.5 | 13-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, older direct notices already represented on-page, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, access-controlled or JavaScript-only trust-center shells, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 13, 2026. |
| v2.6 | 15-JUL-2026 02:01 AM ET | 15-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Microsoft's July 13 ShinyHunters OAuth abuse research as Newly retained (>24h). Added Storm-3138 source-specific nomenclature for Klue, broader ShinyHunters-associated Salesforce OAuth abuse context, connected-app attribution and RTEM guidance, high-privilege/unused-app posture, app risk-scoring, and CloudAppEvents hunting pivots. Modified BLUF, Executive Summary, Timeline, Associated Campaigns, How The Campaign Works, Forensic Indicators, IR Playbook, MITRE Mapping, Source Deconfliction, Source Weighting, Contributors, Citations, and AI Agent Delta Updates. No findings subtracted; no change to Salesforce platform-vulnerability boundary; no merger of Icarus with UNC6395/Salesloft Drift or ShinyHunters. PANDA index date updated to Updated Jul 15, 2026. |
| v2.6 | 16-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Microsoft-derived secondary rewrites, older direct notices already represented on-page, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 16, 2026. |
| v2.6 | 17-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift analysis, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 17, 2026. |
| v2.6 | 18-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth commentary, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 18, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.7 | 19-JUL-2026 02:04 AM ET | 19-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained OneTrust's July 10 Klue Security Incident completion update as Newly retained (>24h). Added OneTrust-specific completed technical investigation status, validated scope and impacted data, finalized containment/remediation, independent forensic finding of no exposure beyond OneTrust's Salesforce environment after June 12 containment, and ongoing governance/compliance review. Modified BLUF, Executive Summary, Timeline, Victim Matrix, Source Summary, Source Deconfliction, Real World Examples, Source Weighting, Contributors, Citations, and AI Agent Delta Updates. No findings subtracted; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, or Microsoft Storm-3138 deconfliction. Search also checked Klue, Salesforce, Huntress, LastPass, Jamf, Recorded Future, SecurityWeek, BleepingComputer, ReliaQuest, Datadog, RH-ISAC, The Hacker News, TechRadar, Mitiga UNC6395/Salesloft Drift, Microsoft ShinyHunters OAuth, Salesforce/OAuth comparator, direct customer notices, social/search rewrites, and leak-site-only claims; duplicates, SEO rewrites, secondary summaries, and unsupported actor-label conflation were not promoted. PANDA index date updated to Updated Jul 19, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.7 | 21-JUL-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 21, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.7 | 22-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Microsoft-derived secondary rewrites, older direct notices already represented on-page, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic Salesforce/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 22, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.7 | 23-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older direct notices already represented on-page, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis including Mitiga's July 22 updated Salesloft/UNC6395 post, generic Salesforce/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 23, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.7 | 24-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older direct notices and practitioner findings already represented on-page, Camunda trust-center profile metadata without accessible Klue-specific incident-text change, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 24, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.7 | 25-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older direct notices and practitioner findings already represented on-page, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, weekly brief roundups, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 25, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.8 | 26-JUL-2026 02:03 AM ET | 26-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Blackbaud's July 22 public Trust Center update as Newly retained (>24h). Added Blackbaud-specific direct-notice scoping: investigation ongoing, no substantive public update as of July 22, no known Blackbaud product impact, and no business-operations or customer-service impact. No freshly reported (<24h) sources; no subtractions; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, or Microsoft Storm-3138 deconfliction. Search also checked Klue, Salesforce, Huntress, LastPass, Jamf, Recorded Future, SecurityWeek, BleepingComputer, ReliaQuest, Datadog, RH-ISAC, The Hacker News, TechRadar, Microsoft ShinyHunters OAuth, Salesforce/OAuth comparator, Blackbaud Trust Center, direct customer notices, social/search rewrites, and leak-site-only claims; duplicates, SEO rewrites, secondary summaries, and unsupported actor-label conflation were not promoted. PANDA index date updated to Updated Jul 26, 2026. No external email, subscriber alert, or notification was sent under the automation no-email policy. |
| v2.8 | 27-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older direct notices and practitioner findings already represented on-page, JavaScript-only or app-shell trust-center bodies without stable inspectable incident text, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 27, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v2.8 | 28-JUL-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older direct notices and practitioner findings already represented on-page, LastPass related-post date noise without a Klue incident-body update, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 28, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v2.8 | 29-JUL-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older direct notices and practitioner findings already represented on-page, advisory-style duplicate summaries, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, generic SaaS/OAuth control updates, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 29, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v2.9 | 30-JUL-2026 02:01 AM ET | 30-Jul-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Klue's July 27 primary restoration update as Newly retained (>24h). Added current integration-status and remediation-control precision: Salesforce and Gong integrations reinstated after CrowdStrike-supported remediation review; all Klue integrations again available for customer enablement; static egress IP allowlisting, platform-wide PKCE, tightened OAuth token lifecycle policy, PAT elimination, centralized monitoring/detection, runtime network filtering, and deployment-pipeline allowlist controls added. Modified BLUF, Executive Summary, Timeline, How The Campaign Works, IR Playbook, Source Summary, Source Deconfliction, Source Weighting, Contributors, Citations, and AI Agent Delta Updates. No findings subtracted; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, Microsoft Storm-3138 deconfliction, or per-victim historical exposure boundaries. Duplicate reporting, SEO rewrites, secondary summaries, social posts, leak-site-only claims, and unsupported actor-label conflation were not promoted. PANDA index date updated to Updated Jul 30, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v2.9 | 31-JUL-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, same-day generic OAuth commentary, Microsoft-derived secondary rewrites, comparator-only UNC6395/Salesloft Drift/Gainsight analysis, SEO rewrites, social posts, leak-site-only claims, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 31, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 01-AUG-2026 02:02 AM ET | 01-Aug-2026 · Freshly reported (<24h)AI Monitoring Agent freshly retained Klue's July 31 CTO security-lessons post as Freshly reported (<24h). Added primary engineering precision for GitHub PAT access, source-code download, second PAT discovery, credential testing, unauthorized build/deployment-path abuse, tampered production workload, stored OAuth-token access, June 12 containment, CrowdStrike no-post-containment-activity finding, and durable GitHub/CI-CD, short-lived credential, workload identity, default-deny network, OAuth refresh-token rotation or idle expiration, IP-range allow-listing, least-privilege integration-account, and distributed-evidence lessons. Modified BLUF, Executive Summary, Timeline, Associated Campaigns, How The Campaign Works, IR Playbook, Source Summary, Source Deconfliction, Real World Examples, Source Weighting, Contributors, Citations, and AI Agent Delta Updates. No findings subtracted; no new victimology; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, Microsoft Storm-3138 deconfliction, or per-victim historical exposure boundaries. Search also checked Klue July 27 restored-integrations update, Salesforce status, Huntress, LastPass, Jamf, Recorded Future, SecurityWeek, BleepingComputer, ReliaQuest, Datadog, Obsidian, Microsoft ShinyHunters OAuth / Storm-3138, Hard2bit July 30/31 generic OAuth commentary, RH-ISAC, Rescana, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices, SEO rewrites, social posts, and leak-site-only claims; duplicates, secondary summaries, and unsupported actor-label conflation were not promoted. PANDA index date updated to Updated Aug 1, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 02-AUG-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, generic SaaS/OAuth control commentary, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 2, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 03-AUG-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, generic SaaS/OAuth control commentary, CSA/Hard2bit/Microsoft-derived OAuth summaries, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 3, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 04-AUG-2026 02:04 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, non-human-identity/OAuth commentary that did not change Icarus analysis, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 4, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 05-AUG-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, CSA/Hard2bit/Microsoft-derived OAuth summaries, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 5, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 06-AUG-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, SOCRadar Icarus ransomware aggregation without sufficient source-backed uplift, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 6, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 07-AUG-2026 02:05 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, page-sidebar date noise, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, CybelAngel/BankInfoSecurity/TechJack/BrightDefense recap or index material without analytic uplift, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 7, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 08-AUG-2026 02:00 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, social posts, page-sidebar date noise, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, Delinea August 2026 SaaS/OAuth explainer without source-backed analytic uplift or visible day-level publication timestamp, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 8, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 09-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, Instagram/Threads/social posts, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Rescana Salesloft Drift/UNC6395/Icarus conflation, OneTrust IsDown/status aggregation, and Cyberpress LastPass duplicate reporting were reviewed but not retained as material deltas. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 9, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 10-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Protos Labs' July 8 report, TechRadar's second-actor recap, Mitiga's July 22 Salesloft/UNC6395 comparator update, and Rescana Salesloft Drift/UNC6395/Icarus conflation were reviewed but not retained as material deltas. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 10, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 11-AUG-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, later secondary/generic-control summaries, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Insurity July 9 continuing-investigation/eDiscovery status text and Thinkproject ongoing-monitoring status text were reviewed but did not materially improve existing direct-notice scoping. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 11, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 12-AUG-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, Klue Status no-new-incident rows, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, later secondary/generic SaaS-control summaries, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Coverbase, Beazley, eSentire, Channel Insider, Neuracybintel, AppOmni, SalesforceBen, and Rescana comparator/conflation material were reviewed but did not materially improve the retained primary Klue/Salesforce/Huntress/Datadog/ReliaQuest/victim-notice analysis. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 12, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 13-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, SOCRadar Icarus aggregation, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. BleepingComputer's City-Forum Salesforce/ServiceNow report was reviewed as checked-but-not-retained comparator material: published Aug 12, 2026 07:07 PM ET; retrieved Aug 13, 2026 02:01 AM ET; freshness label Freshly reported (<24h). It was not promoted because it concerns Salesforce Experience Cloud and ServiceNow guest-user exposure rather than Klue OAuth-token theft, Icarus attribution, or a Salesforce platform vulnerability. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 13, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 14-AUG-2026 02:03 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, SOCRadar Icarus ransomware/leak-site aggregation, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Klue's public article index showed no newer security-incident update after the retained July 31 CTO post; the newest visible Klue item was an Aug 12, 2026 win-loss article. Neuracybintel's Aug 14, 2026 Trezor shipping-partner article was reviewed as checked-but-not-retained background with freshness label Freshly reported (<24h), but it only referenced Klue as SaaS/supply-chain context and did not change the Icarus brief. FINRA Salesloft Drift and Gainsight alerts were treated as comparator material and did not alter actor-label deconfliction. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 14, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.0 | 15-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate summaries, vendor-analysis rewrites, SEO rewrites, page-sidebar/date noise, third-party status aggregation without primary incident-body uplift, leak-site-only claims, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Klue's public article index showed no newer security-incident update after the retained July 31 CTO post; the newest visible Klue item was an Aug 12, 2026 win-loss clips article. Wiz's Klue incident row was reviewed as checked-but-not-retained aggregation with freshness label Newly retained (>24h). Neuracybintel's RingCentral/ShinyHunters article was reviewed as checked-but-not-retained comparator/background material with freshness label Freshly reported (<24h), but it only referenced Klue as SaaS/OAuth history and did not change the Icarus brief. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 15, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.1 | 16-AUG-2026 02:01 AM ET | 16-Aug-2026 · Newly retained (>24h)AI Monitoring Agent newly retained the Massachusetts Attorney General Data Breach Notification Portal / Betterment 2026-1291 - Betterment PDF as Newly retained (>24h), published August 5, 2026 and retrieved August 16, 2026 at 02:01 AM ET for this Icarus snapshot. Added Betterment-specific public notice-letter victimology and scoping: Klue Labs Inc. was a sales-team vendor with access to a Salesforce database containing Betterment data, unauthorized access involved a file containing name and Social Security number, Betterment computer systems were not accessed, and two years of Kroll identity monitoring were offered. Modified BLUF, Public Victim / Disclosure Matrix, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Contributors, Citations, and AI Agent Delta Updates. No findings subtracted; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, Microsoft Storm-3138 deconfliction, or per-victim notice-control rule. Search also checked Klue article/security-incident/status pages, Klue public article index, Salesforce status/trust updates, Betterment/Mass.gov/Dapeer legal recap leads, Security Arsenal RingCentral/ShinyHunters SaaS/OAuth comparator, Huntress, LastPass, Jamf, Recorded Future, SecurityWeek, BleepingComputer, ReliaQuest, Datadog, Wiz, Rescana, SOCRadar, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct notices, SEO rewrites, social posts, leak-site-only claims, and unsupported actor-label conflation. Security Arsenal's Aug 15 RingCentral/ShinyHunters article was checked as Freshly reported (<24h) comparator-only material but not retained. PANDA index date updated to Updated Aug 16, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.1 | 17-AUG-2026 02:00 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate legal/SEO recaps, vendor-analysis rewrites, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Betterment remained represented by the retained Mass.gov primary PDF; Obsidian's July 24 update had already been reviewed by the July 24 monitor note; SOCRadar's Aug 11 profile update remained aggregation/leak-site material without stronger source-backed uplift. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 17, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.2 | 18-AUG-2026 02:04 AM ET | 18-Aug-2026 · Newly retained (>24h)AI Monitoring Agent newly retained Thinkproject's August 12 status-history closure update as Newly retained (>24h), retrieved August 18, 2026 at 02:04 AM ET. Added Thinkproject-specific investigation-concluded, no-known-misuse, and continued-monitoring language to BLUF, Executive Summary, Timeline, Public Victim / Disclosure Matrix, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Citations, and AI Agent Delta Updates. No findings subtracted; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, Microsoft Storm-3138 deconfliction, or per-victim notice-control rule. Search also checked Klue article/security-incident/status pages, Klue public article index, Salesforce status/trust updates, Betterment/Mass.gov notice leads, SOCRadar Icarus ransomware profile, Bright Defense, Huntress support, TechJack, Cybersecurity Dive, Dark Reading, RH-ISAC, ThreatLocker, TechRadar, TechCrunch, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct notices, SEO rewrites, social posts, leak-site-only claims, and unsupported actor-label conflation. SOCRadar's August 15 profile update was checked but not retained as a public content delta because it remained aggregation/leak-site material without stronger source-backed uplift. PANDA index date updated to Updated Aug 18, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.2 | 19-AUG-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, duplicate legal/SEO recaps, vendor-analysis rewrites, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/City-Forum material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Betterment remained represented by the retained Mass.gov primary PDF; Thinkproject remained represented by the retained August 12 status-history closure; SOCRadar's recent profile freshness remained checked-but-not-retained aggregation/leak-site material; ClaimDepot and Dapeer did not add primary notice detail. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 19, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.3 | 20-AUG-2026 02:01 AM ET | 20-Aug-2026 · Newly retained (>24h)AI Monitoring Agent newly retained ControlUp's June 26 Klue Third-Party Cybersecurity Incident notice, updated June 27, 2026 and retrieved August 20, 2026 at 02:01 AM ET, as Newly retained (>24h). Added ControlUp-specific public notice scoping for unauthorized access to certain business data in ControlUp's Salesforce environment through Klue's integration, while preserving ControlUp's product, production-environment, and infrastructure non-impact language. Modified BLUF, Timeline, Public Victim / Disclosure Matrix, Source Summary & Confidence, Source Deconfliction, Real World Examples, Source Weighting, Contributors, Citations, and AI Agent Delta Updates. No findings subtracted; no change to Icarus attribution, Salesforce platform-vulnerability boundary, UNC6395/Salesloft Drift comparator treatment, Microsoft Storm-3138 deconfliction, or the per-victim notice-control rule. Search also checked public Icarus, Klue, Klue Salesforce breach, Klue OAuth, Salesforce OAuth extortion, CRM data theft, Icarus leak-site, Icarus hackers, Icarus extortion group, Huntress Klue, LastPass Klue, Jamf Klue, Recorded Future Klue, SecurityWeek Klue, BleepingComputer Icarus Klue, ReliaQuest Klue, Datadog Klue, Salesforce Trust Status, Klue primary article/security-incident/status pages, Klue public article index, Lucanet, Betterment/Mass.gov legal notice leads, SOCRadar/BreachSense Icarus ransomware profiles, Delinea August 2026 SaaS/OAuth explainer, BankInfoSecurity, RH-ISAC, ThreatLocker, Cybersecurity Dive, Dark Reading, TechRadar, TechCrunch, Rescana, Gblock, SalesforceBen, Microsoft ShinyHunters OAuth / Storm-3138, UNC6395, Salesloft Drift, Gainsight comparator context, direct customer notices and trust/status mirrors, social/search rewrites, and leak-site-only claims. Duplicate reporting, SEO rewrites, sidebar/date noise, third-party aggregation without primary incident-body uplift, leak-site-only aggregation, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. PANDA index date updated to Updated Aug 20, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.3 | 21-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF; BleepingComputer's newest Salesforce tag item remained the August 12 City-Forum comparator story already checked but not retained. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 21, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.3 | 22-AUG-2026 02:00 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, Klue product/blog updates that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF; BleepingComputer's newest Salesforce tag item remained the August 12 City-Forum comparator story already checked but not retained; Klue's newest visible public blog item was an August 20 product/Claude connector article, not an incident update. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 22, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.3 | 23-AUG-2026 02:02 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, product/blog updates and secondary recaps that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. ControlUp remained represented by the retained June 26 notice updated June 27; Thinkproject remained represented by the retained August 12 status-history closure; Betterment remained represented by the retained Mass.gov primary PDF; BleepingComputer's Klue/Icarus coverage remained the June 18 and June 19 incident reporting already cited; Salesforce's Klue Battlecards advisory remained the June 17 platform-boundary notice already cited. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 23, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.3 | 24-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, Klue product/blog updates that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Klue's latest retained incident updates remain the July 27 restored-integrations post and July 31 CTO security-lessons post; Salesforce's Klue Battlecards advisory remained the June 17 platform-boundary notice already cited; ControlUp, Thinkproject, and Betterment remained represented by their retained direct or regulator-hosted notices. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 24, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
| v3.3 | 25-AUG-2026 02:01 AM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Older source-backed findings already represented on-page, Klue's August 24 product/AI deal-support article that did not change the incident analysis, older commentary and practitioner-control guidance without Icarus-specific analytic uplift, duplicate legal/SEO recaps, crawler/sidebar date noise, third-party aggregation without primary incident-body uplift, leak-site-only claims, social posts, comparator-only UNC6395/Salesloft Drift/Gainsight/ShinyHunters material, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters/Storm-3138 conflation were not promoted. Klue's latest retained incident updates remain the July 27 restored-integrations post and July 31 CTO security-lessons post; Salesforce's Klue Battlecards advisory remained the June 17 platform-boundary notice already cited; ControlUp, Thinkproject, and Betterment remained represented by their retained direct or regulator-hosted notices. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Aug 25, 2026. No external email, Gmail, SMTP, Postmark, subscriber-delivery, retry workflow, or notification was used under the automation no-email policy. |
31-Citations
Topic Sources
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 1 | An Update on the Recent Klue Security Incident | Klue | June 2026 | Primary vendor disclosure confirming unauthorized activity in Klue integration infrastructure, legacy credential access, OAuth token theft, and connected-platform data access. |
| 2 | Salesforce General Message 20000257 | Salesforce Status | June 2026 | Authoritative Salesforce statement that the issue was limited to Klue's app connection and did not arise from a Salesforce platform vulnerability. |
| 3 | Klue Integration Abused in Salesforce Data Theft | ReliaQuest | June 2026 | High-value practitioner reporting on OAuth-token abuse, automated Salesforce REST API queries, Python-urllib user agents, query volume, and attribution uncertainty. |
| 4 | Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress | June 2026 | Victim/practitioner disclosure on Huntress impact, extortion communications, Icarus attribution assessment, and CRM-data boundaries. |
| 5 | Detecting the Klue Supply Chain Attack in Salesforce Instances | Datadog Security Labs | June 2026 | Detection-focused research on the Klue attack chain, Salesforce logs, OAuth tokens, Gong/Salesforce context, and Icarus activity timeline. |
| 6 | Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks | BleepingComputer | June 18, 2026 | Security-media source linking Klue OAuth abuse to the Icarus extortion campaign and Salesforce CRM theft. |
| 7 | LastPass confirms data breach in Klue supply chain attack | BleepingComputer | June 23, 2026 | Confirmed real-world victim example showing downstream customer-data exposure while distinguishing LastPass vaults and core products from CRM data. |
| 8 | Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data | The Hacker News | June 19, 2026 | Corroborates Klue, Salesforce, Huntress, ReliaQuest, Icarus, and response context in one consolidated public report. |
| 9 | Klue OAuth breach victim list grows as Icarus hackers claim attack | BleepingComputer | June 19, 2026 | Follow-up source for Icarus public-claim context, additional named downstream notices, Klue's legacy-credential statement, OAuth-token theft, Salesforce API activity, and follow-on phishing/social-engineering risk. |
| 12 | T1199 - Trusted Relationship | MITRE ATT&CK | Living framework | Maps abuse of a trusted SaaS integration relationship. |
| 13 | T1528 - Steal Application Access Token | MITRE ATT&CK | Living framework | Maps OAuth/application token theft and reuse. |
| 14 | T1567 - Exfiltration Over Web Service | MITRE ATT&CK | Living framework | Maps cloud/API-based data extraction from SaaS platforms. |
| 15 | BeyondTrust, LastPass Impacted by Klue-Salesforce Incident | SecurityWeek | June 24, 2026 | Expansion source for additional named downstream disclosures, approximately 15 publicly emerging victims, Tor leak-site context, and boundaries around internal-system impact. |
| 16 | T1078 - Valid Accounts | MITRE ATT&CK | Living framework | Maps trusted account or token-backed access paths used through legitimate SaaS APIs and connected applications. |
| 17 | T1119 - Automated Collection | MITRE ATT&CK | Living framework | Maps automated collection behavior where observed scripts enumerate Salesforce objects and pull records at scale. |
| 18 | Klue Third-Party Cybersecurity Incident | Jamf | June 18, 2026; updated June 26, 2026 | 27-Jun-2026 · Newly retained (>24h)Newly retained (>24h): June 26 Jamf update newly used by this run. Direct customer notice describing unauthorized access to Jamf Salesforce instance data through Klue's integration, disabled integration response, product-impact boundary, phishing-risk warning, and a June 26 investigation update that activity was isolated to Salesforce data accessed through Klue credentials. |
| 19 | The Klue Security Incident and Its Impact on Recorded Future | Recorded Future | June 18, 2026 | Direct customer disclosure explaining Klue integration-layer impact, Salesforce OAuth-token exposure, affected business data fields, response steps, and core-platform impact boundary. |
| 20 | Security Advisory: HackerOne's Response to the Klue Breach | HackerOne | Last updated June 19, 2026 | 25-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice confirming Klue OAuth integration access to HackerOne Salesforce CRM data while preserving the boundary that products, infrastructure, and vulnerability data were not impacted. |
| 21 | Klue Security Incident | BeyondTrust | June 18, 2026, 11:00 PM ET | 25-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer advisory confirming business-contact and sales-related Salesforce CRM exposure through Klue while excluding employee accounts, infrastructure, network, products, product cloud environments, software code, and customer instances. |
| 22 | Klue Security Incident - June 2026 | Sprout Social | No visible page publication date; incident window June 11-12, 2026; retrieved June 25, 2026, 02:03 AM ET | 25-Jun-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer support notice confirming Sprout Social Salesforce CRM access through Klue and product/platform boundary language. |
| 23 | Security update: Klue breach and impact on Pendo | Pendo | June 22, 2026 | 25-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice confirming Pendo Salesforce CRM business/contact data access and excluding customer product data, authentication credentials, technical data, and product platform impact. |
| 24 | Klue Supply Chain Incident & LastPass Response | LastPass | No visible page publication date; public reporting available June 23, 2026; retrieved June 25, 2026, 02:03 AM ET | 25-Jun-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer response confirming LastPass Salesforce CRM/support data exposure through Klue and preserving the vault, product, service, infrastructure, and Gong-data boundaries. |
| 25 | Form 8-K Current Report - Material Cyber Security Incident | 8x8 / SEC 8-K | Accepted by SEC EDGAR June 23, 2026, 5:10 PM ET | 25-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Direct regulatory disclosure confirming 8x8 Salesforce CRM data exfiltration through the Klue integration, affected data categories, isolation to Salesforce data accessible through Klue, and no expected material operational or financial impact based on investigation to date. |
| 26 | Technical Analysis of the Klue Attack: OAuth Abuse, Stale Integrations, and Salesforce Exfiltration | Obsidian Security | Published June 25, 2026; retrieved June 26, 2026, 02:01 AM ET | 26-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Practitioner analysis newly retained in the June 26 monitor run for SaaS-to-SaaS OAuth blast-radius framing, stale integration risk, connected-app governance, token revocation, and post-incident persistence checks. |
| 27 | Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats | TechCrunch | June 25, 2026, 9:40 AM PDT / 12:40 PM ET; retrieved June 26, 2026, 02:01 AM ET | 26-Jun-2026 · Freshly reported (<24h)Freshly reported (<24h): Freshly reported source on Klue customer-update status, Icarus site-down/deletion claims, a second actor's claimed extortion attempt, and explicit caveats around unverified payment, operator, and data-possession claims. |
| 28 | More Klue Breach Victims Identified as Hackers Get Hacked | SecurityWeek | June 26, 2026, 11:01 AM ET; retrieved June 27, 2026, 02:02 AM ET | 27-Jun-2026 · Freshly reported (<24h)Freshly reported (<24h): Freshly reported source updating disclosed-victim scale to roughly two dozen companies, naming additional organizations with notices, preserving Autodesk non-impact context, and keeping the second-actor extortion claims caveated. |
| 29 | Security Incident at Third-Party Provider Klue: Certain Link11 CRM Data Affected | Link11 | June 25, 2026; retrieved June 27, 2026, 02:02 AM ET | 27-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained for Link11-specific Salesforce CRM impact, business-contact and sales-related CRM data categories, product/customer-system boundary, token revocation, and regulatory-response context. |
| 30 | Cybersecurity Alert: Klue OAuth Breach and Salesforce Data Exfiltration | FINRA | June 26, 2026; retrieved June 30, 2026, 02:01 AM ET | 30-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Newly retained financial-sector alert adding broader connected-platform exposure context, suspicious IP and sender-domain indicators, 'mr bean' extortion-alias reporting, and FINRA member-firm mitigation guidance. |
| 31 | ZeroFox Intelligence Profile - ICARUS | ZeroFox Intelligence | June 26, 2026, 4:25 PM ET; modified June 29, 2026, 9:18 AM ET; retrieved June 30, 2026, 02:01 AM ET | 30-Jun-2026 · Newly retained (>24h)Newly retained (>24h): Newly retained threat-actor profile supporting first-observed timing, financially motivated extortion assessment, DLS and direct-email tradecraft, 'mr bean' alias corroboration, suspicious user agents, and caveated SLH-affiliation context. |
| 32 | Security Update - Klue Third-Party Cybersecurity Incident | Saviynt Trust Portal | No visible page publication date; retrieved July 2, 2026, 02:02 AM ET | 02-Jul-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer notice newly retained in the July 2 monitor run for Saviynt-specific impact boundaries: limited Salesforce sales-data exposure and no impact to Saviynt products, services, or customer data in Saviynt products. |
| 33 | Security Advisory: Third-Party Security Incident Involving Klue | LogicMonitor | June 26, 2026; retrieved July 2, 2026, 02:02 AM ET | 02-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained in the July 2 monitor run for Catchpoint/LogicMonitor impact boundaries: confirmed unauthorized access to Catchpoint's Salesforce environment, business relationship and sales activity data exposure, LogicMonitor primary Salesforce non-impact, and production/customer monitoring data exclusion. |
| 34 | CrowdStrike Investigation Summary and Security Improvements | Klue | July 1, 2026; retrieved July 3, 2026, 02:02 AM ET | 03-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Primary vendor follow-up newly retained in the July 3 monitor run summarizing CrowdStrike's completed investigation: compromised GitHub PAT, unauthorized code in Klue's integration service, collection of third-party integration credentials including Salesforce OAuth tokens, GKE pod/PAT containment, token rotation, no identified access beyond integration-service systems, and no evidence of Klue-environment threat-actor activity after June 12. |
| 35 | Notice of Security Incident | Postman Security & Trust Portal | No visible page publication date; retrieved July 5, 2026, 02:01 AM ET | 05-Jul-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer notice newly retained in the July 5 monitor run for Postman-specific impact boundaries: Salesforce customer contact and sales information exfiltration via the compromised Klue service account between June 11-12, no customer-data access from Gong, and no Postman core-platform-services impact. |
| 36 | Klue security incident - Deel impact | Deel | Last Update June 26, 2026; retrieved July 6, 2026, 02:00 AM ET | 06-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained in the July 6 monitor run for Deel-specific impact boundaries: CRM access through a compromised Klue connection, business contact and commercial information exposure, a very limited amount of personal data synced to CRM, vendor access removal, token/session response, and platform non-impact. |
| 37 | Notification of Salesforce / Klue Security Incident | Insurity Status | Updated June 22, 2026, 11:05 AM EDT; initial notice June 18, 2026, 6:01 PM EDT; retrieved July 6, 2026, 02:00 AM ET | 06-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer status notice newly retained in the July 6 monitor run for Insurity-specific boundaries: suspicious Klue connected-app activity, cloud/product/infrastructure non-impact, CRM business-contact exposure, limited active credentials/secrets found within CRM data, and customer-specific direct-notification guidance. |
| 38 | Update From OneTrust on Klue Security Incident | OneTrust | June 24, 2026; updated July 10, 2026; July 10 update retrieved July 19, 2026, 02:04 AM ET | 19-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained in the July 8 monitor run for OneTrust-specific impact boundaries, with the July 10 completion update newly retained in the July 19 monitor run for completed technical investigation status, validated scope, finalized containment and remediation, no evidence of exposure beyond OneTrust's Salesforce environment after June 12 containment, and ongoing governance/compliance review. |
| 39 | The impact of the Klue breach on Tines and our customers | Tines | Published June 18, 2026; updated July 1, 2026; retrieved July 8, 2026, 02:04 AM ET | 08-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained in the July 8 monitor run for Tines-specific boundaries: completed investigation, Salesforce-only impact, CRM business/contact/opportunity/commercial communications exposure, limited support-adjacent information, no customer environments/workflows/credentials/secrets/tokens impact, and additional public IP and user-agent leads. |
| 40 | Klue Breach that Allowed Data Exfiltration from Salesforce | Thinkproject Status | Updated August 12, 2026, 2:01 PM; prior update June 26, 2026, 6:47 AM; initial notice June 19, 2026, 4:13 PM; August 12 closure retrieved August 18, 2026, 02:04 AM ET | 08-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer status notice retained for Thinkproject-specific boundaries: UAT CRM environment access through a Klue integration, business-contact and commercial-information exposure, product/platform non-impact, phishing/payment-change social-engineering warning, and the August 12 final update stating the investigation concluded with no known misuse of affected data. |
| 41 | Klue incident update | Cresta Trust Center | No visible page publication date; retrieved July 8, 2026, 02:04 AM ET | 08-Jul-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer trust-center notice newly retained in the July 8 monitor run for Cresta-specific boundaries: impacted Salesforce instance, possible exposure of business contact information, contractual information, and email correspondence, and no indication of product or infrastructure impact. |
| 42 | Security Advisory: Klue Third-Party Application Incident | AlertMedia Trust Center | No visible page publication date; retrieved July 8, 2026, 02:04 AM ET | 08-Jul-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer trust-center notice newly retained in the July 8 monitor run for AlertMedia-specific boundaries: Klue OAuth-token CRM export, AlertMedia inclusion among affected Klue customers, product/supporting-system customer-data non-impact, Klue access revocation, third-party Salesforce credential rotation, and phishing warning. |
| 43 | A message to our customers about the Klue security incident | ABBYY Trust Center | No visible page publication date; retrieved July 8, 2026, 02:04 AM ET | 08-Jul-2026 · Newly retained (publication date not visible)Newly retained (publication date not visible): Direct customer trust-center notice newly retained in the July 8 monitor run for ABBYY-specific boundaries: Salesforce data accessed through Klue integration, ABBYY network/product/technology non-impact, credential revocation, integration disablement, and security-review completion. |
| 44 | Third-Party Vendor Security Incident (Klue) | Snyk Status | Initial notice June 19, 2026, 23:15 UTC; monitoring update June 22, 2026, 22:12 UTC; resolved July 8, 2026, 15:26 UTC / 11:26 AM ET; retrieved July 9, 2026, 02:02 AM ET | 09-Jul-2026 · Freshly reported (<24h)Freshly reported (<24h): Direct customer status notice freshly retained in the July 9 monitor run for Snyk-specific Mandiant-assisted forensic closure: impact limited to business CRM data, all impacted customers directly notified, no evidence of impact to the Snyk platform or sensitive data within it, and Salesforce/Klue integration containment. |
| 45 | SentinelOne Confirms Klue Supply Chain Incident Contained to Salesforce | Secure ISS | July 9, 2026; retrieved July 10, 2026, 02:02 AM ET | 10-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Public third-party write-up sharing SentinelOne's Klue partner update, newly retained in the July 10 monitor run for SentinelOne-specific forensic scope: completed independently verified investigation, impact contained to Salesforce via the Klue API integration, no lateral movement into SentinelOne systems, and no core product, cloud infrastructure, or production-environment impact. |
| 46 | Klue/Salesforce Security Breach - Investigation Update | Camunda Trust Center | Final update published July 1, 2026 22:00 UTC; trust-center profile published July 10, 2026 08:32 UTC and last updated July 10, 2026 08:44 UTC; retrieved July 12, 2026, 02:02 AM ET | 12-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer trust-center update newly retained in the July 12 monitor run for Camunda-specific Salesforce CRM impact boundaries: final external-validation-supported update says exfiltrated data was limited to standard business-contact and account information in Salesforce CRM and did not include support data. |
| 47 | Security Update: Tanium's Response to the Klue Breach that Allowed Data Exfiltration from Salesforce | Tanium | June 18, 2026 18:36 UTC; modified June 18, 2026 20:02 UTC; retrieved July 12, 2026, 02:02 AM ET | 12-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained in the July 12 monitor run for Tanium-specific Salesforce CRM impact boundaries: sales account data and business-contact information may have been compromised while support information, passwords, customer security data, products, and cloud infrastructure were excluded. |
| 49 | Klue Security Incident Update | Blackbaud Trust Center | July 22, 2026, 20:05 UTC / 4:05 PM ET; retrieved July 26, 2026, 02:03 AM ET | Direct customer trust-center update newly retained in the July 26 monitor run for Blackbaud-specific public scoping: investigation remains ongoing, no substantive update as of July 22, no known product impact, and no business-operations or customer-service impact. |
| 50 | Integrations Restored: Salesforce and Gong Reconnected | Klue | July 27, 2026; retrieved July 30, 2026, 02:01 AM ET | 30-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Primary vendor follow-up newly retained in the July 30 monitor run for restored Salesforce and Gong integration availability, CrowdStrike-supported remediation validation, static egress IP allowlisting, platform-wide PKCE, tightened OAuth token lifecycle policies, PAT elimination, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlist controls. |
| 51 | What a Security Incident Taught Us About Securing a Modern SaaS Platform | Klue | July 31, 2026, 6:50 PM ET; retrieved August 1, 2026, 02:02 AM ET | 01-Aug-2026 · Freshly reported (<24h)Freshly reported (<24h): Primary Klue CTO post freshly retained in the August 1 monitor run for two-phase GitHub PAT and CI/CD intrusion detail, source-code download, second PAT discovery, credential testing, unauthorized build/deployment path, tampered production workload, stored OAuth-token access, June 12 containment, CrowdStrike no-post-containment-activity finding, and durable controls around GitHub Apps or workload identity, default-deny deployment networking, refresh-token rotation or idle expiration, IP-range allow-listing, integration least privilege, and distributed incident evidence. |
| 52 | 2026-1291 - Betterment | Massachusetts Attorney General Data Breach Notification Portal / Betterment | August 5, 2026; retrieved August 16, 2026, 02:01 AM ET for this Icarus snapshot | 16-Aug-2026 · Newly retained (>24h)Newly retained (>24h): Direct regulator-hosted notice letter newly retained in the August 16 Icarus monitor run: Klue Labs Inc. was a vendor used by Betterment's sales team with access to a Salesforce database containing Betterment data; unauthorized access involved a file containing name and Social Security number; Betterment's computer systems were not accessed; and Betterment offered two years of Kroll identity monitoring. |
| 53 | Klue Third-Party Cybersecurity Incident | ControlUp | June 26, 2026; updated June 27, 2026; retrieved August 20, 2026, 02:01 AM ET | 20-Aug-2026 · Newly retained (>24h)Newly retained (>24h): Direct customer notice newly retained in the August 20 monitor run for ControlUp-specific impact boundaries: unauthorized access to certain business data in ControlUp's Salesforce environment through Klue's integration, product, production-environment, and infrastructure non-impact, and customer-specific notice language. |
Expansion Research Sources
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 10 | Widespread Data Theft Targets Salesforce Instances via Salesloft Drift | Google Cloud / GTIG | August 26, 2025 | Expansion comparator for UNC6395/Salesloft Drift OAuth-token theft, used to distinguish source-backed UNC6395 attribution from the newer Icarus/Klue actor label. |
| 11 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Platforms | FBI / IC3 | September 12, 2025 | Government expansion source tying UNC6395 to compromised Salesloft Drift OAuth tokens and Salesforce data theft, used for attribution deconfliction. |
| 48 | Defending SaaS-based applications against ShinyHunters OAuth abuse | Microsoft Security Blog | July 13, 2026; retrieved July 15, 2026, 02:01 AM ET | 15-Jul-2026 · Newly retained (>24h)Newly retained (>24h): Expansion and deconfliction source newly retained in the July 15 monitor run: Microsoft groups Salesforce abuse activity with ShinyHunters-associated overlapping tradecraft, identifies the Klue incident as Storm-3138 activity, preserves the no-Salesforce-platform-vulnerability boundary, and adds connected-app telemetry and governance guidance. |
