IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Klue

Supply Chain Attack

SalesforceCRM integrationOAuth exposure
Published
23-Jun-2026
Brief Version
v1.29
Updated
57x via AI Monitoring Agents
Next AI Monitor
Daily at 1:30 AM ET for 12 months
Brief ID
PANDA-FTIB-KLUE-2026-001
Template
Flash Threat Brief Template v2.0

Research Framing

Klue Exposure Snapshot

1-Topic

Klue is a competitive enablement and market-intelligence SaaS platform whose Salesforce integration can sit close to customer and prospect CRM records. The public incident is best framed as a trusted SaaS integration and OAuth-token exposure path, not as a confirmed Salesforce platform vulnerability. 1,2,5,6

The operational question for downstream customers is whether Klue or Klue Battlecards had token-backed access into their Salesforce environment, which objects were reachable, and whether Salesforce API activity indicates customer, prospect, support, or commercial data access. 3,5,6,7,30

Public customer notices now make this a concrete disclosure-pattern issue as well as a technical one: responders should preserve Salesforce logs, revoke and rotate integration tokens, scope CRM objects, and keep product-system compromise language separate from Salesforce business-data exposure. 11,12,32,33,34,35,38,39,40,41,42,43

2-Persona / Audience Lens

3-BLUF

  • Klue is a competitive enablement SaaS provider with Salesforce integration paths; the incident matters because attackers can abuse that trusted integration relationship to reach downstream customer CRM data. 1,5,6
  • LastPass publicly confirmed a Klue-linked customer-data incident while stating its product systems, services, infrastructure, and vaults were not compromised. 3,4,30
  • The strongest technical framing is OAuth/connected-app abuse: compromised Klue integration access produced token-backed Salesforce API activity, not a Salesforce core-platform exploit. 1,2,5,6
  • Responder priority is to revoke and rotate Klue/Salesforce integration tokens and credentials, preserve Salesforce logs, scope CRM data queried or exported, and notify legal/privacy teams where customer or prospect data was accessed. 1,5,6,7
  • 29-Jun-2026 · Newly retained (>24h) Icarus remains the public actor label tied to the Klue extortion/data-theft activity in this source set. FINRA and ZeroFox reinforce Icarus/ICARUS naming and mitigation priorities, while ZeroFox also notes Underground Uwu / Scattered Lapsus$ Hunters claims that remain caveated. No reliable source merged Klue with UNC6395/Salesloft Drift. 5,6,36,37,53,54
  • 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Salesforce/CRM sales or business data exposure. 30-Jun-2026 · Newly retained (publication date not visible)ABBYY adds an undated trust-center boundary. These sources expand public victimology but do not change the Salesforce platform-vulnerability boundary or actor attribution. 55,56,57,58
  • 02-Jul-2026 · Freshly reported (<24h) Klue's primary CrowdStrike update revises the mechanism from generic legacy-credential compromise to a GitHub PAT (personal access token) and unauthorized integration-service code path, while stating CrowdStrike found no evidence of threat-actor access outside integration-service-related systems or activity after June 12. 59
  • 04-Jul-2026 · Newly retained (publication date not visible) Postman adds a direct public customer-disclosure boundary: Salesforce customer contact and sales information was exfiltrated via the compromised Klue service account, customer data was not accessed from Gong, and Postman core platform services were not impacted. 60
  • 05-Jul-2026 · Newly retained (>24h) Automox adds a useful no-impact disclosure boundary: after Klue/Salesforce review, it reported no anomalous or malicious Salesforce activity and said Klue had no indication Automox data or customer data was affected. Treat this as leak-list deconfliction, not a confirmed data-theft victim row. 61
  • 07-Jul-2026 · Newly retained (>24h) eSentire adds a narrow direct customer-disclosure boundary: Salesforce data was accessed through Klue, exposure was described as minimal due to restricted OAuth permissions and a limited connected-app footprint, and eSentire reported no identified customer-service risk from the incident. 62
  • 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific customer-disclosure boundary: the Klue-linked access involved Salesforce/CRM business-contact and commercial information, while Thinkproject states its products and services were not affected and its CRM system is separate from the customer product platform. 16-Aug-2026 · Newly retained (>24h) Thinkproject's Aug. 12 status resolution adds that its investigation concluded, it is not aware of misuse of the affected data, and monitoring continues. 63
  • 09-Jul-2026 · Newly retained (>24h) Snyk now closes its Klue/Salesforce status incident after a Mandiant-assisted forensic investigation, preserving a business-CRM-data-only boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary: Salesforce-environment-only impact through the Klue API integration, no lateral movement, and no core-product, cloud-infrastructure, or production-environment impact reported. 64,65
  • 11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation and narrows the public boundary: containment and remediation are complete, and the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment. Governance, compliance, and notification review remain ongoing. 44
  • 13-Jul-2026 · Freshly reported (<24h) Microsoft places Klue in a broader Salesforce/SaaS OAuth-abuse tradecraft discussion associated with ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system access path; preserve Icarus/ICARUS as the Klue-specific public extortion/operator label unless stronger evidence merges or replaces that attribution. 66
  • 14-Jul-2026 · Newly retained (publication date not visible) Sisense adds another direct public customer-disclosure boundary: Sisense says the Klue incident was limited to certain business and sales-related data in its Salesforce CRM application and did not impact the Sisense product platform or product-platform data. 67
  • 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer-disclosure boundaries: both tie Klue to Salesforce access and preserve product/platform exclusions, while Splashtop notes its investigation remained ongoing. 68,69
  • 23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct Conveyor trust-center disclosure boundaries. Greenhouse limits accessible data to business contact information in sales/customer relationship systems and excludes product, hiring, candidate, infrastructure, modification, and deletion impact. Blackbaud states its investigation remains ongoing with no substantive update, no known Blackbaud product impact, and no business-operations/customer-service impact. 70,71
  • 24-Jul-2026 · Newly retained (publication date not visible) Confluent adds another direct trust-center boundary: copied data was limited to Confluent business information in its CRM system, while Confluent states product-processed customer data was not involved or impacted and that there is no indication its products, platform, or infrastructure were affected. 72
  • 28-Jul-2026 · Newly retained (>24h) Autodesk adds a direct no-impact deconfliction boundary: it says Klue notified Autodesk on June 16, Autodesk did not use the Salesforce or Gong integrations for Klue, and Autodesk identified no direct impact to Autodesk products, services, or systems. 73
  • 30-Jul-2026 · Newly retained (>24h) Klue adds a primary restoration milestone: Salesforce and Gong reinstated Klue integrations in their marketplaces, all Klue integrations are available for customer re-enablement, and Klue says restoration followed CrowdStrike review plus controls for static egress IPs, platform-wide PKCE, OAuth-token lifecycle tightening, GitHub PAT elimination, centralized monitoring, runtime network filtering, and deployment-pipeline allowlisting. 74
  • 31-Jul-2026 · Freshly reported (<24h) Klue's CTO adds a primary engineering lesson learned: treat GitHub and CI/CD as part of the production security boundary, reduce long-lived credential reliance, bind remaining credentials to workload, identity, network context, and least privilege, and review OAuth scopes with the authorizing account's effective privileges. 75
  • 02-Aug-2026 · Newly retained; undated Yext adds a direct undated SafeBase disclosure boundary: read-only queries hit Yext's internal Salesforce CRM for roughly 17 hours on June 11-12 through stolen Klue-held credentials, exposing business contact details for customers and prospects while excluding Yext platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, and Slack impact. 76
  • 03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add two older rendered public disclosure boundaries. Commvault limits accessed data to Salesforce business relationship and sales activity information while excluding customer data, solutions/services, customer backup data, product metadata, and logs. NetDocuments says Klue impact was limited to internal Gong-user staff-list data and excludes customer data, prospective customer data, Customer Repository Data, and NetDocuments Service impact. 77,78
  • 04-Aug-2026 · Newly retained (>24h) Neon One adds a direct public notice-letter boundary: a Klue incident involving Neon One's Salesforce CRM integration service resulted in unauthorized access to some personal information between June 11-12; Neon One says the incident was contained and no further impact was identified. 79
  • 10-Aug-2026 · Newly retained (>24h) Betterment adds a regulator-hosted public notice-letter boundary: the Mass.gov PDF says Klue Labs Inc. was a vendor used by Betterment's sales team and had access to a Salesforce database containing Betterment data. 11-Aug-2026 · Newly retained (>24h) PDF text re-review clarifies that the accessed file contained name and Social Security number, Betterment's computer systems were not accessed, and two years of Kroll identity monitoring were offered. Do not infer Betterment product-system, brokerage, bank, account-access, or credential compromise from the notice. 80

4-Executive Summary

Klue is a competitive enablement and market-intelligence SaaS platform used by sales teams to synchronize battlecards, win/loss context, and competitive intelligence with CRM workflows. That business role matters: a Klue integration can sit close to sensitive Salesforce data such as accounts, contacts, leads, opportunities, notes, and customer relationship context. Public reporting and Klue's own statement describe unauthorized activity affecting part of Klue's integration infrastructure, with a compromised legacy integration credential used to obtain OAuth tokens that connected Klue to Salesforce. 02-Jul-2026 · Freshly reported (<24h) Klue's later CrowdStrike summary refines that mechanism: a previously compromised GitHub PAT was used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. 1,5,6,59

This is a supply-chain attack because downstream customers may be exposed through a trusted third-party application rather than through a direct compromise of their own infrastructure first. LastPass publicly confirmed a Klue-linked customer-data incident and said its LastPass product systems and vaults were not compromised. That distinction is important for executives and counsel: the event may still trigger CRM data, privacy, and notification analysis even where core product systems, password vaults, or endpoint infrastructure were not breached. 3,4

26-Jun-2026 · Newly retained (>24h) LastPass's detailed response adds useful scoping language for counsel and customer communications: the company describes Salesforce and Gong integration context, token rotation, discontinued Klue access, law-enforcement cooperation, customer anti-phishing guidance, published IOCs, and a product/vault boundary. 30 26-Jun-2026 · Freshly reported (<24h) TechCrunch adds a second-wave extortion concern: Klue reportedly told customers the original criminals were deleting stolen data while another group had begun making threats. 31

26-Jun-2026 · Freshly reported (<24h) SecurityWeek now reports roughly two dozen public Klue-Salesforce impact disclosures and names an expanded set of customer-notice examples. 36 26-Jun-2026 · Newly retained (>24h) Obsidian adds tenant-forensics detail across impacted organizations, including Global Describe reconnaissance, QueryMore pagination, API-version deviation, user-agent deviation, and broad object harvest patterns. 37

27-Jun-2026 · Newly retained (>24h) LogicMonitor/Catchpoint and Tanium add direct customer-disclosure boundaries: both tie the incident to Salesforce data exposure through Klue while separating that exposure from core product, production, monitoring, or cloud-infrastructure compromise. 41,43 27-Jun-2026 · Newly retained (publication date not visible) Tines adds a trust-center boundary that Klue credentials were used to access Salesforce data, with no evidence of unauthorized access to the Tines platform or customer environments. 42

28-Jun-2026 · Newly retained (>24h) OneTrust, Gong, and Insurity add three direct public-disclosure boundaries: OneTrust ties the event to Klue Battlecards/Salesforce CRM-related data without evidence of customer-tenant exposure; Gong scopes impact to customers who connected Klue with Gong and says call recordings/transcripts were not directly impacted; Insurity says a limited set of active credentials found in exposed CRM data were rotated or reset and that Insurity products were not involved. 44,45,46

29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-page resolution timestamp while retaining the older June 22 monitoring context for its Klue-Salesforce integration incident. 47 29-Jun-2026 · Newly retained (>24h) Link11 adds a direct CRM-data notice, while FINRA and ZeroFox add sector guidance, Icarus/ICARUS reinforcement, limited IOCs, and a caveat that Underground Uwu / Scattered Lapsus$ Hunters claims should not be collapsed into UNC6395/Salesloft Drift. 48,53,54 29-Jun-2026 · Newly retained (publication date not visible) AlertMedia, Cresta, and Lucanet add undated trust-center disclosures that improve public victim boundary coverage without creating a universal impact model; Camunda is now handled separately because its latest trust-center update provides a dated source-specific boundary revision. 49,50,51,52

30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Klue-linked Salesforce, CRM, sales, or business-contact data exposure while separating that exposure from their respective product, production, infrastructure, or product-customer-data environments. 55,56,57 30-Jun-2026 · Newly retained (publication date not visible) ABBYY adds an undated trust-center disclosure stating Salesforce data accessed through Klue's integration was affected while ABBYY's network, products, and technology were not affected. 58

04-Aug-2026 · Newly retained (>24h) Neon One adds a direct public notice-letter boundary: Klue provided an integration service for Neon One's Salesforce customer relationship management software, and the Klue incident resulted in unauthorized access to some personal information between June 11 and June 12. Neon One says the incident was contained and no further impact was identified. 79

02-Jul-2026 · Freshly reported (<24h) Klue says CrowdStrike completed its investigation on June 30, found no evidence of threat-actor access outside systems related to the integration service, found no evidence of threat-actor activity in the Klue environment after June 12, and that Klue deployed CrowdStrike Falcon monitoring. 59 02-Jul-2026 · Newly retained (>24h) Camunda's latest trust-center update narrows Camunda's own impact boundary: exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. 50

04-Jul-2026 · Newly retained (publication date not visible) Postman's Security & Trust Portal adds a direct public customer-disclosure boundary: Postman says customer contact data and sales information were exfiltrated from its Salesforce environment via the compromised Klue service account between June 11-12, customer data was not accessed from Gong, and Postman's core platform services remain secure and were not impacted. 60

07-Jul-2026 · Newly retained (>24h) eSentire adds another direct public customer-disclosure boundary: eSentire says it uses Klue, was among the organizations whose Salesforce data was accessed, and describes the exposure as minimal because the integration was tightly scoped with restricted OAuth permissions and a limited connected-app footprint. It reports no identified risk to customers from eSentire's services and excludes customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. 62

08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific public customer boundary: Klue had authorized software-integration access to that CRM environment, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. 63

09-Jul-2026 · Newly retained (>24h) Snyk's July 8 status resolution adds investigation-closure confidence: Snyk says its Klue/Salesforce forensic investigation, conducted with Mandiant, is complete; the impact remained limited to business CRM data; and no Snyk platform or sensitive platform-data impact was found. 64 09-Jul-2026 · Freshly reported (<24h) Secure ISS's July 9 advisory relays a SentinelOne partner-notification boundary: the Klue impact was contained to SentinelOne's Salesforce environment through the Klue API integration, with no lateral movement and no core-product, cloud-infrastructure, or production-environment impact reported. Treat it as a qualified public advisory because the direct SentinelOne portal reference is access-controlled and data analysis remains ongoing. 65

11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation, validates scope, and finalizes containment and remediation. OneTrust says the independent forensic investigation found no evidence of exposure beyond its Salesforce environment, while governance, compliance, and notification review remain ongoing. 44

13-Jul-2026 · Freshly reported (<24h) Microsoft's July 13 research adds a fresh campaign-deconfliction layer: it groups Salesforce and SaaS OAuth-abuse activity observed from mid-2025 to mid-2026 as tradecraft commonly associated with ShinyHunters and includes Klue integration activity in that broader discussion. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system-access path. Use this to strengthen OAuth/connected-app hunting and activity-cluster deconfliction while preserving Icarus/ICARUS as the Klue-specific public extortion/operator label unless a reliable source directly merges or replaces that attribution. 66

14-Jul-2026 · Newly retained (publication date not visible) Sisense adds another direct public customer-disclosure boundary: its Trust Center says Sisense was one of many affected organizations and that the incident was limited to certain business and sales-related data in Sisense's Salesforce CRM application. Sisense states the product platform and data stored within the product platform were not impacted, and says it disconnected certain third-party integrations, rotated credentials and tokens to Klue and Salesforce, and is monitoring access logs. 67

16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add two older direct public disclosure boundaries. Qualtrics says the Klue application connected to Salesforce for internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised. Splashtop says Klue OAuth tokens were used to access certain Salesforce data, it disabled the Klue Salesforce integration and revoked access, the investigation remained ongoing, and Splashtop products and services were not impacted. 68,69

23-Jul-2026 · Newly retained (>24h) Greenhouse and Blackbaud add direct Conveyor trust-center boundaries. Greenhouse says attackers obtained Klue credentials used to connect to certain Greenhouse business systems; access occurred on June 11, was scoped to Klue's integration, did not involve Greenhouse infrastructure, and was limited to business contact information in sales/customer relationship systems. Blackbaud's July 22 update says its investigation remains ongoing with no substantive update, no known impact to Blackbaud products, and no impact to business operations or customer-service ability. 70,71

30-Jul-2026 · Newly retained (>24h) Klue's July 27 restoration update changes the operational posture from disabled integrations only to controlled re-enablement. Klue says Salesforce and Gong reinstated Klue integrations in their marketplaces, all Klue integrations are again available for customers to enable, and Klue added controls including static egress IPs allow-listed by Salesforce and Gong, platform-wide PKCE, tightened OAuth token lifecycle policies, elimination of GitHub personal access tokens, centralized monitoring and detection, runtime network filtering, and deployment-pipeline allowlisting. 74

31-Jul-2026 · Freshly reported (<24h) Klue's CTO post adds the freshest primary engineering detail: the intrusion unfolded from GitHub PAT access into source-code download, additional PAT discovery, credential testing, build/deployment-path abuse, and a tampered production workload that enabled stored OAuth-token access. It reinforces CI/CD as a production security boundary and calls out durable controls around GitHub Apps or workload identity, default-deny network controls, refresh-token rotation or idle expiration, IP-range allow-listing, and low-privilege integration accounts where supported. 75

02-Aug-2026 · Newly retained; undated Yext adds a direct SafeBase trust-center boundary: Yext says stolen Klue-held credentials were used to run read-only queries against Yext's internal Salesforce CRM for roughly 17 hours on June 11-12, exposing business contact details for customers and prospects. Yext excludes platform, product, infrastructure, customer-content, customer-facing-system, end-user-data, payment-card, Google Workspace, and Slack impact. 76

03-Aug-2026 · Newly retained (>24h) Commvault and NetDocuments add older rendered public disclosure boundaries that improve customer-impact scoping without changing the upstream Klue/Salesforce OAuth mechanism. Commvault limits accessed data to Salesforce business relationship and sales activity information and excludes customer data, Commvault solutions/services, customer backup data, product metadata, and logs. NetDocuments says the NetDocuments Service was not impacted and limits the Klue-related impact to internal Gong-user staff-list data, while excluding customer data, prospective customer data, and Customer Repository Data. 77,78

The best technical framing is OAuth/connected-app abuse in the Salesforce ecosystem. Klue says it revoked credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, and notified law enforcement. ReliaQuest and Datadog add the operational layer: token-backed access, automated Salesforce REST API queries, OAuth refresh-token evidence, connected-app identification, and object-level scoping are the artifacts defenders should examine. 1,5,6

For responders, the first question is not "did we patch Salesforce?" It is "did we use Klue or Klue Battlecards, what Salesforce data did that integration reach, and did token-backed API activity occur in our tenant?" The near-term response is to preserve Salesforce logs, identify Klue connected apps, revoke and rotate tokens and integration secrets, scope CRM objects queried or exported, and coordinate legal, privacy, and client communications around confirmed data access rather than speculative actor claims.

Expansion Research Add
Salesforce's own public guidance and researcher reporting support the same boundary: this should not be treated as a Salesforce platform vulnerability unless new primary evidence changes that status. The control plane is third-party application trust, OAuth tokens, connected apps, and Salesforce API visibility. 2,5,6,13

The closest public comparator is the Salesloft Drift campaign: Google Cloud, FBI/IC3, Unit 42, Arctic Wolf, BleepingComputer, and FINRA all describe a trusted SaaS integration/OAuth-token path into downstream Salesforce environments. That prior campaign is why Klue should be scoped as a SaaS integration supply-chain event, not as an isolated vendor notice. 18,19,20,21,22,24

5-AI Agent Delta Updates

6-Why It Matters

7-Timeline

8-Incident Response Playbook Ideas

9-Term Glossary

10-TTPs

11-Common Questions Q&A

12-CVE / Vulnerability References

13-IOCs / Observables

14-Threat Actor Glossary

15-Talking Points

16-Decision Ready Actions

17-Exploitable Technology Risks

18-Social Media / Community Signals

19-Tier 0 Through Tier 8 Source Summary

20-Source Reconciliation

21-About the Contributors

22-Real World Examples

23-Public Victims / Disclosure Matrix

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

26-Source Weighting / Relevance

27-Additional IntelliOS Threat Intel Products on This Topic

28-Notes

29-Version Change Log

30-Citations