Klue
Supply Chain Attack
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Klue supply-chain attack; what is Klue, why is this a supply-chain attack, and what should downstream customers do first? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is Klue? What happened with its Salesforce integration? Why does this create downstream customer exposure? What did LastPass confirm? How should Salesforce, legal, privacy, IR, and vendor-risk teams scope impact? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Klue Exposure Snapshot
| Field | Assessment | Sources |
|---|---|---|
| What Klue is | A competitive enablement / market-intelligence SaaS platform used to sync sales battlecards, win/loss context, competitive positioning, and seller guidance with CRM systems such as Salesforce. | 5,6 |
| Why this is supply chain | The exposure flowed through a trusted third-party SaaS integration into downstream customer Salesforce environments, rather than through a direct breach of each customer first. | 1,3,5,6 |
| Reported mechanism | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary says a previously compromised GitHub PAT (personal access token) was used to introduce unauthorized code into the integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. | 1,5,6,59 |
| Not currently framed as | A Salesforce platform vulnerability, a CVE, or proof that every Klue customer experienced the same data exposure. | 1,2,6 |
1-Topic
Klue is a competitive enablement and market-intelligence SaaS platform whose Salesforce integration can sit close to customer and prospect CRM records. The public incident is best framed as a trusted SaaS integration and OAuth-token exposure path, not as a confirmed Salesforce platform vulnerability. 1,2,5,6
The operational question for downstream customers is whether Klue or Klue Battlecards had token-backed access into their Salesforce environment, which objects were reachable, and whether Salesforce API activity indicates customer, prospect, support, or commercial data access. 3,5,6,7,30
Public customer notices now make this a concrete disclosure-pattern issue as well as a technical one: responders should preserve Salesforce logs, revoke and rotate integration tokens, scope CRM objects, and keep product-system compromise language separate from Salesforce business-data exposure. 11,12,32,33,34,35,38,39,40,41,42,43
2-Persona / Audience Lens
This brief is written for CISOs, Salesforce administrators, SaaS owners, SOC/IR teams, breach counsel, privacy teams, client-facing cyber advisors, and vendor-risk leaders. It prioritizes evidence that can be validated quickly: Klue use, Salesforce connected-app state, OAuth/token revocation, CRM API activity, customer-data scoping, and which claims are official versus technically inferred.
3-BLUF
- Klue is a competitive enablement SaaS provider with Salesforce integration paths; the incident matters because attackers can abuse that trusted integration relationship to reach downstream customer CRM data. 1,5,6
- LastPass publicly confirmed a Klue-linked customer-data incident while stating its product systems, services, infrastructure, and vaults were not compromised. 3,4,30
- The strongest technical framing is OAuth/connected-app abuse: compromised Klue integration access produced token-backed Salesforce API activity, not a Salesforce core-platform exploit. 1,2,5,6
- Responder priority is to revoke and rotate Klue/Salesforce integration tokens and credentials, preserve Salesforce logs, scope CRM data queried or exported, and notify legal/privacy teams where customer or prospect data was accessed. 1,5,6,7
- 29-Jun-2026 · Newly retained (>24h) Icarus remains the public actor label tied to the Klue extortion/data-theft activity in this source set. FINRA and ZeroFox reinforce Icarus/ICARUS naming and mitigation priorities, while ZeroFox also notes Underground Uwu / Scattered Lapsus$ Hunters claims that remain caveated. No reliable source merged Klue with UNC6395/Salesloft Drift. 5,6,36,37,53,54
- 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Salesforce/CRM sales or business data exposure. 30-Jun-2026 · Newly retained; undatedABBYY adds an undated trust-center boundary. These sources expand public victimology but do not change the Salesforce platform-vulnerability boundary or actor attribution. 55,56,57,58
- 02-Jul-2026 · Freshly reported (<24h) Klue's primary CrowdStrike update revises the mechanism from generic legacy-credential compromise to a GitHub PAT (personal access token) and unauthorized integration-service code path, while stating CrowdStrike found no evidence of threat-actor access outside integration-service-related systems or activity after June 12. 59
- 04-Jul-2026 · Newly retained; undated Postman adds a direct public customer-disclosure boundary: Salesforce customer contact and sales information was exfiltrated via the compromised Klue service account, customer data was not accessed from Gong, and Postman core platform services were not impacted. 60
- 05-Jul-2026 · Newly retained (>24h) Automox adds a useful no-impact disclosure boundary: after Klue/Salesforce review, it reported no anomalous or malicious Salesforce activity and said Klue had no indication Automox data or customer data was affected. Treat this as leak-list deconfliction, not a confirmed data-theft victim row. 61
- 07-Jul-2026 · Newly retained (>24h) eSentire adds a narrow direct customer-disclosure boundary: Salesforce data was accessed through Klue, exposure was described as minimal due to restricted OAuth permissions and a limited connected-app footprint, and eSentire reported no identified customer-service risk from the incident. 62
- 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific customer-disclosure boundary: the Klue-linked access involved Salesforce/CRM business-contact and commercial information, while Thinkproject states its products and services were not affected and its CRM system is separate from the customer product platform. 63
- 09-Jul-2026 · Newly retained (>24h) Snyk now closes its Klue/Salesforce status incident after a Mandiant-assisted forensic investigation, preserving a business-CRM-data-only boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary: Salesforce-environment-only impact through the Klue API integration, no lateral movement, and no core-product, cloud-infrastructure, or production-environment impact reported. 64,65
- 11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation and narrows the public boundary: containment and remediation are complete, and the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment. Governance, compliance, and notification review remain ongoing. 44
- 13-Jul-2026 · Freshly reported (<24h) Microsoft places Klue in a broader Salesforce/SaaS OAuth-abuse tradecraft discussion associated with ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system access path; preserve Icarus/ICARUS as the Klue-specific public extortion/operator label unless stronger evidence merges or replaces that attribution. 66
- 14-Jul-2026 · Newly retained; undated Sisense adds another direct public customer-disclosure boundary: Sisense says the Klue incident was limited to certain business and sales-related data in its Salesforce CRM application and did not impact the Sisense product platform or product-platform data. 67
- 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer-disclosure boundaries: both tie Klue to Salesforce access and preserve product/platform exclusions, while Splashtop notes its investigation remained ongoing. 68,69
4-Executive Summary
Klue is a competitive enablement and market-intelligence SaaS platform used by sales teams to synchronize battlecards, win/loss context, and competitive intelligence with CRM workflows. That business role matters: a Klue integration can sit close to sensitive Salesforce data such as accounts, contacts, leads, opportunities, notes, and customer relationship context. Public reporting and Klue's own statement describe unauthorized activity affecting part of Klue's integration infrastructure, with a compromised legacy integration credential used to obtain OAuth tokens that connected Klue to Salesforce. 02-Jul-2026 · Freshly reported (<24h) Klue's later CrowdStrike summary refines that mechanism: a previously compromised GitHub PAT was used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. 1,5,6,59
This is a supply-chain attack because downstream customers may be exposed through a trusted third-party application rather than through a direct compromise of their own infrastructure first. LastPass publicly confirmed a Klue-linked customer-data incident and said its LastPass product systems and vaults were not compromised. That distinction is important for executives and counsel: the event may still trigger CRM data, privacy, and notification analysis even where core product systems, password vaults, or endpoint infrastructure were not breached. 3,4
26-Jun-2026 · Newly retained (>24h) LastPass's detailed response adds useful scoping language for counsel and customer communications: the company describes Salesforce and Gong integration context, token rotation, discontinued Klue access, law-enforcement cooperation, customer anti-phishing guidance, published IOCs, and a product/vault boundary. 30 26-Jun-2026 · Freshly reported (<24h) TechCrunch adds a second-wave extortion concern: Klue reportedly told customers the original criminals were deleting stolen data while another group had begun making threats. 31
26-Jun-2026 · Freshly reported (<24h) SecurityWeek now reports roughly two dozen public Klue-Salesforce impact disclosures and names an expanded set of customer-notice examples. 36 26-Jun-2026 · Newly retained (>24h) Obsidian adds tenant-forensics detail across impacted organizations, including Global Describe reconnaissance, QueryMore pagination, API-version deviation, user-agent deviation, and broad object harvest patterns. 37
27-Jun-2026 · Newly retained (>24h) LogicMonitor/Catchpoint and Tanium add direct customer-disclosure boundaries: both tie the incident to Salesforce data exposure through Klue while separating that exposure from core product, production, monitoring, or cloud-infrastructure compromise. 41,43 27-Jun-2026 · Newly retained; undated Tines adds a trust-center boundary that Klue credentials were used to access Salesforce data, with no evidence of unauthorized access to the Tines platform or customer environments. 42
28-Jun-2026 · Newly retained (>24h) OneTrust, Gong, and Insurity add three direct public-disclosure boundaries: OneTrust ties the event to Klue Battlecards/Salesforce CRM-related data without evidence of customer-tenant exposure; Gong scopes impact to customers who connected Klue with Gong and says call recordings/transcripts were not directly impacted; Insurity says a limited set of active credentials found in exposed CRM data were rotated or reset and that Insurity products were not involved. 44,45,46
29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-page resolution timestamp while retaining the older June 22 monitoring context for its Klue-Salesforce integration incident. 47 29-Jun-2026 · Newly retained (>24h) Link11 adds a direct CRM-data notice, while FINRA and ZeroFox add sector guidance, Icarus/ICARUS reinforcement, limited IOCs, and a caveat that Underground Uwu / Scattered Lapsus$ Hunters claims should not be collapsed into UNC6395/Salesloft Drift. 48,53,54 29-Jun-2026 · Newly retained; undated AlertMedia, Cresta, and Lucanet add undated trust-center disclosures that improve public victim boundary coverage without creating a universal impact model; Camunda is now handled separately because its latest trust-center update provides a dated source-specific boundary revision. 49,50,51,52
30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Klue-linked Salesforce, CRM, sales, or business-contact data exposure while separating that exposure from their respective product, production, infrastructure, or product-customer-data environments. 55,56,57 30-Jun-2026 · Newly retained; undated ABBYY adds an undated trust-center disclosure stating Salesforce data accessed through Klue's integration was affected while ABBYY's network, products, and technology were not affected. 58
02-Jul-2026 · Freshly reported (<24h) Klue says CrowdStrike completed its investigation on June 30, found no evidence of threat-actor access outside systems related to the integration service, found no evidence of threat-actor activity in the Klue environment after June 12, and that Klue deployed CrowdStrike Falcon monitoring. 59 02-Jul-2026 · Newly retained (>24h) Camunda's latest trust-center update narrows Camunda's own impact boundary: exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. 50
04-Jul-2026 · Newly retained; undated Postman's Security & Trust Portal adds a direct public customer-disclosure boundary: Postman says customer contact data and sales information were exfiltrated from its Salesforce environment via the compromised Klue service account between June 11-12, customer data was not accessed from Gong, and Postman's core platform services remain secure and were not impacted. 60
07-Jul-2026 · Newly retained (>24h) eSentire adds another direct public customer-disclosure boundary: eSentire says it uses Klue, was among the organizations whose Salesforce data was accessed, and describes the exposure as minimal because the integration was tightly scoped with restricted OAuth permissions and a limited connected-app footprint. It reports no identified risk to customers from eSentire's services and excludes customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. 62
08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific public customer boundary: Klue had authorized software-integration access to that CRM environment, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. 63
09-Jul-2026 · Newly retained (>24h) Snyk's July 8 status resolution adds investigation-closure confidence: Snyk says its Klue/Salesforce forensic investigation, conducted with Mandiant, is complete; the impact remained limited to business CRM data; and no Snyk platform or sensitive platform-data impact was found. 64 09-Jul-2026 · Freshly reported (<24h) Secure ISS's July 9 advisory relays a SentinelOne partner-notification boundary: the Klue impact was contained to SentinelOne's Salesforce environment through the Klue API integration, with no lateral movement and no core-product, cloud-infrastructure, or production-environment impact reported. Treat it as a qualified public advisory because the direct SentinelOne portal reference is access-controlled and data analysis remains ongoing. 65
11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation, validates scope, and finalizes containment and remediation. OneTrust says the independent forensic investigation found no evidence of exposure beyond its Salesforce environment, while governance, compliance, and notification review remain ongoing. 44
13-Jul-2026 · Freshly reported (<24h) Microsoft's July 13 research adds a fresh campaign-deconfliction layer: it groups Salesforce and SaaS OAuth-abuse activity observed from mid-2025 to mid-2026 as tradecraft commonly associated with ShinyHunters and includes Klue integration activity in that broader discussion. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system-access path. Use this to strengthen OAuth/connected-app hunting and activity-cluster deconfliction while preserving Icarus/ICARUS as the Klue-specific public extortion/operator label unless a reliable source directly merges or replaces that attribution. 66
14-Jul-2026 · Newly retained; undated Sisense adds another direct public customer-disclosure boundary: its Trust Center says Sisense was one of many affected organizations and that the incident was limited to certain business and sales-related data in Sisense's Salesforce CRM application. Sisense states the product platform and data stored within the product platform were not impacted, and says it disconnected certain third-party integrations, rotated credentials and tokens to Klue and Salesforce, and is monitoring access logs. 67
16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add two older direct public disclosure boundaries. Qualtrics says the Klue application connected to Salesforce for internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised. Splashtop says Klue OAuth tokens were used to access certain Salesforce data, it disabled the Klue Salesforce integration and revoked access, the investigation remained ongoing, and Splashtop products and services were not impacted. 68,69
The best technical framing is OAuth/connected-app abuse in the Salesforce ecosystem. Klue says it revoked credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, and notified law enforcement. ReliaQuest and Datadog add the operational layer: token-backed access, automated Salesforce REST API queries, OAuth refresh-token evidence, connected-app identification, and object-level scoping are the artifacts defenders should examine. 1,5,6
For responders, the first question is not "did we patch Salesforce?" It is "did we use Klue or Klue Battlecards, what Salesforce data did that integration reach, and did token-backed API activity occur in our tenant?" The near-term response is to preserve Salesforce logs, identify Klue connected apps, revoke and rotate tokens and integration secrets, scope CRM objects queried or exported, and coordinate legal, privacy, and client communications around confirmed data access rather than speculative actor claims.
The closest public comparator is the Salesloft Drift campaign: Google Cloud, FBI/IC3, Unit 42, Arctic Wolf, BleepingComputer, and FINRA all describe a trusted SaaS integration/OAuth-token path into downstream Salesforce environments. That prior campaign is why Klue should be scoped as a SaaS integration supply-chain event, not as an isolated vendor notice. 18,19,20,21,22,24
5-AI Agent Delta Updates
| Run / Schedule | Delta Status | Monitoring Scope | Next Action |
|---|---|---|---|
26-Jun-2026 · Monitoring setup Bootstrap run: 26-Jun-2026 9:08 AM ET | Source-backed bootstrap deltas incorporated. Added one freshly reported follow-on extortion source, newly retained customer/impact notices, and a primary LastPass response page with additional response and boundary detail. | Klue, LastPass, Salesforce, Huntress, Datadog, ReliaQuest, BleepingComputer, customer notices, public victim/disclosure updates, associated campaign names, OAuth/Salesforce forensic guidance, and Salesloft Drift comparator changes. | Daily monitor at 1:30 AM ET for 12 months. Notify configured active subscribers after every run, including no-change checks. |
26-Jun-2026 · Monitor run Run: 26-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Freshly reported (<24h): SecurityWeek, published 26-Jun-2026 11:01 AM ET. Newly retained (>24h): Obsidian, Pendo, and 8x8. Newly retained (publication date not visible): Recorded Future. | Searched Klue/Salesforce OAuth abuse, LastPass, Huntress, Datadog, ReliaQuest, SecurityWeek, public victim notices, Icarus/UNC6395 campaign naming, and Salesloft Drift comparator reporting. Public-victim/disclosure search found additional named disclosure examples. Associated-campaign search reinforced Icarus as the Klue label; no reliable source merged Klue with UNC6395. | Next scheduled monitor: 27-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
27-Jun-2026 · Monitor run Run: 27-Jun-2026 9:33 PM ET | Source-backed deltas incorporated. Newly retained (>24h): LogicMonitor/Catchpoint, published 26-Jun-2026, and Tanium, published 18-Jun-2026. Newly retained (publication date not visible): Tines Trust Center. No Freshly reported (<24h) source was retained in this run. | Searched Klue/Salesforce OAuth abuse, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, customer notices, public victim disclosures, Icarus/UNC6395 campaign naming, and Salesloft Drift comparator reporting. Public-victim/disclosure search found additional direct customer notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 28-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
28-Jun-2026 · Monitor run Run: 28-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Newly retained (>24h): OneTrust, published 24-Jun-2026; Gong, published 19-Jun-2026; and Insurity Status, published 18-Jun-2026 and updated 22-Jun-2026. No Freshly reported (<24h) source was retained in this run. | Searched Klue/Salesforce OAuth abuse, Klue Battlecards, LastPass, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, direct customer notices, named public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, and Salesloft Drift comparator reporting. Public-victim/disclosure search found additional direct OneTrust, Gong, and Insurity notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 29-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
29-Jun-2026 · Monitor run Run: 29-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Freshly reported (<24h): AudienceView status resolution, published/resolved 29-Jun-2026 with an initial 22-Jun-2026 monitoring record. Newly retained (>24h): Link11, FINRA, and ZeroFox. Newly retained (publication date not visible): AlertMedia, Camunda, Cresta, and Lucanet trust-center notices. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, public victim notices, Salesforce trust/status updates, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search reinforced Icarus/ICARUS and Underground Uwu/SLH caveats; no reliable source merged Klue with UNC6395/Salesloft Drift. | Next scheduled monitor: 30-Jun-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
30-Jun-2026 · Monitor run Run: 30-Jun-2026 9:31 PM ET | Source-backed deltas incorporated. Newly retained (>24h): ControlUp, published 26-Jun-2026; Deel, published 25-Jun-2026 and last updated 26-Jun-2026; and Saviynt, published 23-Jun-2026. Newly retained (publication date not visible): ABBYY Trust Center. No Freshly reported (<24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, public victim/customer notices, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 01-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
01-Jul-2026 · Monitor run Run: 01-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, public victim/customer notices, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 02-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
02-Jul-2026 · Monitor run Run: 02-Jul-2026 9:31 PM ET | Source-backed deltas incorporated. Freshly reported (<24h): Klue CrowdStrike Investigation Summary and Security Improvements, schema published 02-Jul-2026 12:02 AM ET with a visible 01-Jul-2026 byline. Newly retained (>24h): Camunda Trust Center 01-Jul-2026 investigation update narrowing its support-data boundary. Newly retained (publication date not visible): none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, public victim/customer notices, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found a source-backed Camunda boundary revision but no new named victim requiring a new row. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 03-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
04-Jul-2026 · Monitor run Run: 04-Jul-2026 9:31 PM ET | Source-backed deltas incorporated. Newly retained (publication date not visible): Postman Security & Trust Portal Notice of Security Incident, retrieved 04-Jul-2026 9:31 PM ET. No Freshly reported (<24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, direct customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Postman's direct customer notice and rejected duplicative SEO rewrites, leak-site-only claims, and inaccessible/truncated trust-center leads without enough boundary detail. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 05-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, new customer notices, and verified campaign-attribution changes. |
05-Jul-2026 · Monitor run Run: 05-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): Automox Trust Center Klue Security Incident, published 29-Jun-2026 and retrieved 05-Jul-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, direct customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Automox's direct no-impact trust-center notice and did not promote NetDocuments search-index-only text, duplicative SEO rewrites, social posts, leak-site-only claims, or unsupported speculation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 06-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
06-Jul-2026 · Monitor run Run: 06-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 07-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
07-Jul-2026 · Monitor run Run: 07-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): eSentire Responding to the Klue Incident, published 26-Jun-2026 and retrieved 07-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found eSentire's direct customer disclosure and did not promote NetDocuments sparse/search-index-only text, generic Salesforce OAuth recaps, LinkedIn/social posts, leak-site-only claims, or duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 08-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
08-Jul-2026 · Monitor run Run: 08-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, published 26-Jun-2026 6:47 AM and retrieved 08-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Thinkproject's direct status notice and did not promote duplicative summaries, generic Salesforce OAuth recaps, LinkedIn/social posts, leak-site-only claims, sparse status aggregators, or duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. | Next scheduled monitor: 09-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
09-Jul-2026 · Monitor run Run: 09-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed deltas incorporated. Newly retained (>24h): Snyk Status Third-Party Vendor Security Incident (Klue), resolved 08-Jul-2026 11:26 AM ET and retrieved 09-Jul-2026 9:31 PM ET. Freshly reported (<24h): Secure ISS SentinelOne Klue advisory, published 09-Jul-2026 and retrieved 09-Jul-2026 9:31 PM ET. Newly retained (publication date not visible): none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Snyk's investigation-closure notice and a qualified SentinelOne public advisory/partner-notification lead; it rejected NetDocuments JavaScript-only/search-index text, duplicative SEO recaps, generic OAuth commentary, leak-site-only claims, and unsupported Salesforce/OAuth attribution rewrites. | Next scheduled monitor: 10-Jul-2026 1:30 AM ET. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. |
10-Jul-2026 · Monitor run Run: 10-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; NetDocuments remained JavaScript-only/search-index text without a stable inspectable disclosure body. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 11-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
11-Jul-2026 · Monitor run Run: 11-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed customer-boundary delta incorporated. Newly retained (>24h): OneTrust Update From OneTrust on Klue Security Incident, updated 10-Jul-2026 and retrieved 11-Jul-2026 9:31 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus/UNC6395 activity-cluster naming, SaaS integration extortion, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found OneTrust's July 10 investigation-complete boundary update and rejected duplicate media recaps, social posts, leak-site-only claims, generic OAuth/Salesforce commentary, and unsupported Klue/Salesloft Drift conflation. | Next scheduled monitor: 12-Jul-2026 1:30 AM ET. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. |
12-Jul-2026 · Monitor run Run: 12-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, Icarus, UNC6395, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 13-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
13-Jul-2026 · Monitor run Run: 13-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed campaign-deconfliction delta incorporated. Freshly reported (<24h): Microsoft Security Research / Microsoft Defender Security Research Team, published 13-Jul-2026 and retrieved 13-Jul-2026 9:31 PM ET. Newly retained (>24h): none. Newly retained (publication date not visible): none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable named organization notice that changed the brief. Associated-campaign/activity-cluster search found Microsoft ShinyHunters-associated OAuth-abuse research that improves deconfliction but does not merge Klue/Icarus with UNC6395 or Salesloft Drift. | Next scheduled monitor: 14-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
14-Jul-2026 · Monitor run Run: 14-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed public customer-disclosure delta incorporated. Newly retained (publication date not visible): Sisense Trust Center Security Update: Klue Security Incident, retrieved 14-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (>24h) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Sisense's direct trust-center notice and rejected duplicate media recaps, SEO rewrites, leak-site-only claims, JavaScript-only NetDocuments text, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 15-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
15-Jul-2026 · Monitor run Run: 15-Jul-2026 9:31 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; NetDocuments and Commvault trust-center pages remained JavaScript-only or unavailable to stable public inspection. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Microsoft and RH-ISAC/TechRadar ShinyHunters OAuth coverage was already represented by the retained Microsoft source and was not promoted as a duplicate delta. | Next scheduled monitor: 16-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
16-Jul-2026 · Monitor run Run: 16-Jul-2026 9:32 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed public customer-disclosure deltas incorporated. Newly retained (>24h): Qualtrics XM Trust Center Klue Supply Chain Compromise response, published 25-Jun-2026 12:55 UTC and retrieved 16-Jul-2026 9:32 PM ET; Splashtop Security Update Regarding Third-Party Klue Incident, updated 30-Jun-2026 and retrieved 16-Jul-2026 9:32 PM ET. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found Qualtrics and Splashtop direct notices and rejected duplicate media recaps, VenariX aggregated victim tracking, NetDocuments and Commvault JavaScript-only trust-center shells without stable inspectable bodies, leak-site-only claims, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 17-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
18-Jul-2026 · Monitor run Run: 18-Jul-2026 9:31 PM ET DD-Mon-YYYY · Freshly reported (<24h)newly published source DD-Mon-YYYY · Newly retained (>24h)older source newly incorporated DD-Mon-YYYY · Revisedinterpretation or page logic changed | Source-backed campaign/activity-label clarification incorporated. Newly retained (>24h): existing Microsoft Security Research / Microsoft Defender Security Research Team source, published 13-Jul-2026 and re-reviewed 18-Jul-2026 9:31 PM ET, now explicitly retained for the Storm-3138 Klue system-access label. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained in this run. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Commvault remained a JavaScript-only trust-center shell without a stable inspectable body. Associated-campaign/activity-cluster search found Microsoft's Storm-3138 label already present in the retained Microsoft source and promoted it as a deconflicted activity-label clarification, not an actor merger. | Next scheduled monitor: 19-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. |
19-Jul-2026 · Monitor run Run: 19-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body. Insurity's July 9 status update remained represented by the retained Insurity citation and did not change the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. | Next scheduled monitor: 20-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
20-Jul-2026 · Monitor run Run: 20-Jul-2026 9:32 PM ET | No source-backed content delta. No version increment; no findings added, modified, subtracted, or newly qualified. Freshness labels applied to retained sources: none. | Searched Klue supply-chain attack, Klue Salesforce breach, OAuth token abuse, Klue Battlecards, LastPass Klue incident, Huntress, Datadog, ReliaQuest, BleepingComputer, Cybersecurity Dive, Help Net Security, The Hacker News, Jamf, Sprout Social, Salesforce status/trust updates, affected-customer notices, public victim disclosures, associated campaign/activity cluster names, Icarus, UNC6395, Storm-3138, ShinyHunters, SaaS integration extortion, Salesforce OAuth supply-chain attacks, CRM data theft, Salesforce API exfiltration, Salesforce connected-app abuse, and Salesloft Drift comparator updates. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix; Sprout Social, Jamf, LastPass, Huntress, Tanium, Recorded Future, Insurity, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Nudge Security, TechRadar, The Hacker News, SecurityBoulevard, and other recent or recrawled summaries were treated as duplicate or secondary coverage and not promoted. | Next scheduled monitor: 21-Jul-2026 1:30 AM ET. Continue watching for primary Klue/Salesforce updates, direct customer notices, and verified campaign-attribution changes. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
6-Why It Matters
This event matters because CRM integrations often become invisible trust bridges. A sales-enablement vendor may not look like a crown-jewel system, but its OAuth access can provide a route into customer contacts, accounts, opportunity data, competitive notes, and relationship metadata. That makes the incident relevant to breach response, privacy review, business-development exposure, sales operations, and vendor-risk governance.
Supply-chain blast radius
A single trusted SaaS integration can expose many downstream Salesforce tenants.
Token-first response
Password resets do not address OAuth refresh tokens, connected-app grants, or API access.
CRM impact
Exposed data may include customer/prospect contact details, account notes, and commercial context.
7-Timeline
| Date / Period | Event | Source-Backed Meaning | Source |
|---|---|---|---|
| June 11, 2026 | Datadog reports early anomalous Klue/Salesforce activity in monitored telemetry. | Suggested starting point for Salesforce log scoping where Klue was connected. | 6 |
| June 12, 2026 | Klue says it identified unauthorized activity affecting a portion of its integration infrastructure. | Primary vendor acknowledgement of the incident window. | 1 |
| June 13, 2026 | LastPass says Klue notified it of a security incident involving Salesforce data. | Confirmed downstream customer-notification path. | 3 |
| June 18, 2026 | Huntress publishes a victim/researcher account about Salesforce data impacted through Klue. | Public technical/customer signal that the blast radius is broader than one company. | 7 |
| June 20, 2026 | Security media report Klue investigating a supply-chain attack involving Salesforce integrations. | Public awareness broadens beyond direct customer notices. | 8 |
| June 22, 2026 | Klue publishes an update, LastPass publishes a detailed response page, and ReliaQuest publishes technical analysis of the Klue integration abuse. | Source set becomes strong enough for mechanism-level briefing and downstream-customer scoping. | 1,5,30 |
| June 23, 2026 | BleepingComputer reports LastPass confirmation and connects the incident to the Klue supply-chain attack. | Starter public article for this PANDA brief. | 4 |
| June 24, 2026 | SecurityWeek reports that over a dozen Klue customers had confirmed Salesforce-instance data theft and names BeyondTrust and LastPass among impacted organizations. | Expanded public victim/disclosure boundary beyond the initial LastPass/Huntress/Jamf/Sprout Social examples. | 32 |
| June 25, 2026 | Obsidian publishes analysis across impacted organizations, adding Global Describe reconnaissance, v59.0 API usage, QueryMore pagination, user-agent deviation, and object-harvest detail. | Improves Salesforce forensic scoping beyond generic REST API volume. | 37 |
| June 25, 2026 | TechCrunch reports Klue told customers that the original criminals were deleting stolen customer data while a second group had begun making threats. | Shifts scoping from one extortion channel to possible follow-on customer pressure and proof-validation questions. | 31 |
| June 26, 2026 | SecurityWeek reports roughly two dozen public Klue-Salesforce impact disclosures and names additional organizations with customer notices. | Expands the public victim/disclosure set while preserving customer-specific impact boundaries. | 36 |
| June 26, 2026 | 27-Jun-2026 · Newly retained (>24h) LogicMonitor publishes a direct Klue notice for the Catchpoint Salesforce environment. | Adds a primary customer disclosure that separates affected Salesforce data from LogicMonitor production, monitoring, and primary Salesforce systems. | 41 |
| June 28, 2026 monitor retrieval | 28-Jun-2026 · Newly retained (>24h) OneTrust, Gong, and Insurity direct notices are retained as first-party disclosure boundaries. | Adds customer/platform-specific limits for Salesforce CRM exposure, Gong integration exposure, credential rotation, and product/customer-tenant boundaries. | 44,45,46 |
| June 29, 2026 monitor retrieval | 29-Jun-2026 · Freshly reported (<24h) AudienceView status page is retained for its fresh resolution timestamp and organization-specific Klue-Salesforce boundary. 29-Jun-2026 · Newly retained (>24h) Link11, FINRA, and ZeroFox are retained as older source-backed additions. 29-Jun-2026 · Newly retained; undated AlertMedia, Camunda, Cresta, and Lucanet trust-center notices are retained as undated direct disclosures. | Adds primary customer-disclosure boundaries, sector guidance, Icarus/ICARUS deconfliction, and limited IOC coverage without changing the Salesforce-platform-vulnerability boundary. | 47,48,49,50,51,52,53,54 |
| June 30, 2026 monitor retrieval | 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt direct disclosures are retained as older source-backed public victim notices. 30-Jun-2026 · Newly retained; undated ABBYY is retained as an undated trust-center disclosure. | Expands direct public customer-disclosure coverage while preserving organization-specific Salesforce, CRM, product, infrastructure, and customer-data boundaries. | 55,56,57,58 |
| June 30, 2026 | 02-Jul-2026 · Freshly reported (<24h) CrowdStrike completes its Klue investigation, according to Klue's July 1/2 public summary. | Adds primary-source confidence around investigation scope, containment, and post-incident monitoring. | 59 |
| July 1, 2026 | 02-Jul-2026 · Newly retained (>24h) Camunda updates its trust-center notice to state exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. | Narrows one previously retained customer disclosure boundary rather than adding a new victim category. | 50 |
| July 1-2, 2026 | 02-Jul-2026 · Freshly reported (<24h) Klue publishes CrowdStrike findings: a compromised GitHub PAT introduced unauthorized code into the integration service and collected third-party credentials including Salesforce OAuth tokens. | Materially refines the root-cause and control-plane story from OAuth abuse alone to source-control, CI/CD, integration-service, and token-collection controls. | 59 |
| July 4, 2026 monitor retrieval | 04-Jul-2026 · Newly retained; undated Postman's Security & Trust Portal notice is retained as a direct public customer disclosure. | Adds a named Salesforce/Gong boundary: customer contact and sales information was exfiltrated from Salesforce through Klue, while customer data was not accessed from Gong and core platform services remained secure. | 60 |
| July 5, 2026 monitor retrieval | 05-Jul-2026 · Newly retained (>24h) Automox's June 29 trust-center notice is retained as a direct no-impact disclosure and leak-list deconfliction source. | Adds a named organization that reviewed Klue/Salesforce exposure, found no anomalous Salesforce activity, and says Klue had no indication Automox or customer data was affected. | 61 |
| July 7, 2026 monitor retrieval | 07-Jul-2026 · Newly retained (>24h) eSentire's June 26 blog is retained as a direct customer disclosure. | Adds a named Salesforce-impact boundary with minimal exposure, restricted OAuth-permission context, and explicit exclusions for customer communication/support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. | 62 |
| July 8, 2026 monitor retrieval | 08-Jul-2026 · Newly retained (>24h) Thinkproject's June 26 status notice is retained as a direct customer disclosure. | Adds a UAT CRM-specific boundary: possible business-contact and commercial-information exposure through Salesforce/Klue, with products, services, and customer product platform excluded. | 63 |
| July 8, 2026 | 09-Jul-2026 · Newly retained (>24h) Snyk resolves its Klue/Salesforce status incident after a Mandiant-assisted forensic investigation. | Closes the Snyk boundary as business CRM data only, with no evidence of Snyk platform or sensitive platform-data impact. | 64 |
| July 9, 2026 | 09-Jul-2026 · Freshly reported (<24h) Secure ISS publishes a SentinelOne Klue advisory based on a partner notification. | Adds a qualified SentinelOne public advisory boundary: impact contained to Salesforce through the Klue API integration, no lateral movement or core-product/cloud/production impact reported, with data analysis still ongoing. | 65 |
| July 10, 2026 | 11-Jul-2026 · Newly retained (>24h) OneTrust updates its Klue incident post to state that the technical investigation, scope validation, containment, and remediation are complete. | Narrows OneTrust's boundary to no evidence of exposure beyond its Salesforce environment while preserving ongoing governance, compliance, and notification review. | 44 |
| July 13, 2026 | 13-Jul-2026 · Freshly reported (<24h) Microsoft publishes Salesforce/SaaS OAuth-abuse research that includes Klue integration activity in a broader ShinyHunters-associated tradecraft discussion. 18-Jul-2026 · Newly retained (>24h) The AI Monitoring Agent now retains Microsoft's Storm-3138 activity label for the Klue system-access path. | Adds high-confidence deconfliction: Microsoft reinforces trusted OAuth abuse and supplies Klue IOC context, but does not by itself collapse the Klue-specific Icarus/ICARUS extortion label into UNC6395, Salesloft Drift, or a definitive ShinyHunters attribution. | 66 |
| July 14, 2026 monitor retrieval | 14-Jul-2026 · Newly retained; undated Sisense Trust Center notice is retained as an undated direct customer disclosure. | Adds a named public customer boundary: certain business and sales-related Salesforce CRM data, with Sisense product-platform and product-platform data excluded. | 67 |
| July 16, 2026 monitor retrieval | 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop direct customer notices are retained as older source-backed public disclosures. | Adds two organization-specific Salesforce/Klue boundaries: Qualtrics limits impact to a subset of Salesforce B2B identifiers and excludes Qualtrics platform customer data; Splashtop limits current belief to business data fields in Salesforce, excludes product/service impact, and keeps investigation ongoing. | 68,69 |
8-Incident Response Playbook Ideas
| Phase | Playbook Idea | Likely Owner | Sources |
|---|---|---|---|
| Immediate scoping | Identify whether Klue, Klue Battlecards, or related Klue Salesforce connected apps were installed, active, or previously authorized. | Salesforce Admin / SaaS Owner | 1,5,6,13 |
| Preserve evidence | Retain Salesforce Event Monitoring, LoginHistory, Connected App OAuth Usage, API logs, Setup Audit Trail, Klue notices, and CRM-object export evidence. | SOC / IR | 5,6 |
| Containment | Revoke Klue OAuth tokens, rotate integration credentials/secrets, disable unneeded Klue integrations, and re-authorize only after scope is understood. | IAM / Salesforce Admin | 1,5,6 |
| Impact analysis | Scope account, contact, lead, opportunity, notes, activity, and custom-object data queried through the connected app during the exposure window. | IR / Legal / Business App Owner | 5,6,7 |
| Notification planning | Separate customer-data exposure, product-system compromise, vault/secret compromise, and customer phishing/social-engineering risk in stakeholder messaging. | Legal / Privacy / Communications | 3,4,30 |
| Firm / sector notification hygiene | 29-Jun-2026 · Newly retained (>24h) For regulated financial-services or member-firm environments, align Klue/Salesforce containment with FINRA's sector guidance: revoke tokens, investigate Salesforce logs, rotate exposed secrets, monitor suspicious outreach, and brief privacy, legal, and vendor-risk owners. | Legal / Compliance / SOC | 53 |
| Vendor re-enablement evidence | 02-Jul-2026 · Freshly reported (<24h) Before restoring Klue integrations, request evidence for GitHub PAT disablement, OAuth credential rotation, integration-service code review, GKE pod containment (disabling affected Google Kubernetes Engine runtime workloads), CrowdStrike/EDR monitoring, SIEM logging, secret scanning, and CI/CD workflow hardening. | Vendor Risk / IAM / Salesforce Admin | 59 |
| Cross-campaign OAuth hardening | 13-Jul-2026 · Freshly reported (<24h) Use Microsoft's broader ShinyHunters-associated SaaS OAuth research to audit trusted connected apps beyond Klue: consent grants, app privileges, refresh-token persistence, Salesforce event monitoring, and guest-access paths. | IAM / Salesforce Admin / SOC | 66 |
Salesforce Forensic View For Klue Attribution
A Klue investigation should not stop at vendor notification. The strongest internal evidence is the convergence of Salesforce connected-app state, OAuth/token activity, EventLogFile records, API query behavior, and object-level access during the reported exposure window.
| Salesforce Evidence | What To Collect | Why It Matters For Klue Attribution | Sources |
|---|---|---|---|
| Connected app / OAuth inventory | Klue, Klue Battlecards, integration users, OAuth policies, authorized users, scopes, token state, last-used timestamps, and whether access was revoked or reauthorized. | This ties the investigation to the trusted Salesforce app path instead of treating the incident as generic account compromise. | 1,5,6,13 |
| EventLogFile / Event Monitoring | REST API, API Total Usage, Bulk API, Login, Report, Report Export, and permission-related event categories where licensed and retained. | EventLogFile is the main Salesforce telemetry path for API use, object access, reports, login behavior, and suspicious operational patterns. | 6,25,26 |
| REST API query evidence | URI, method, user, connected-app context, source IP, user agent, query/queryMore behavior, pagination, object names, and high-volume access to Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, or custom objects. | Klue attribution is strongest when the Klue app or token context lines up with abnormal Salesforce API activity during the incident window. | 5,6,25,26 |
| Global Describe / API-version deviation | 26-Jun-2026 · Newly retained (>24h) Salesforce Global Describe calls, REST API version shifts such as v64.0-to-v59.0 deviation, QueryMore pagination bursts, and user-agent changes from stable Klue baselines. | Obsidian reports these deviations across impacted organizations; they help separate normal integration behavior from reconnaissance and bulk export patterns. | 37 |
| Login History and Login Event data | Who logged in, when, from where, authentication method, failed/successful logins, and whether activity belongs to a human user, integration user, or app-backed session. | This separates direct user compromise from token-backed or connected-app activity and helps build the timeline. | 25,26,28 |
| Setup Audit Trail | Connected-app changes, OAuth policy changes, profile or permission changes, package changes, event-monitoring setting changes, and administrative activity around the exposure window. | Administrative changes can explain blast radius, cleanup actions, or attacker attempts to modify access. | 26,27 |
| Klue attribution test | Look for convergence: Klue connected app or token context, matching incident window, source infrastructure or user-agent clues from research, Salesforce API volume, and accessed CRM objects. | No single string proves Klue attribution; the strongest case is a correlated body of Salesforce and vendor evidence. | 1,5,6 |
| Vendor integration-service control plane | 02-Jul-2026 · Freshly reported (<24h) Klue/CrowdStrike evidence for compromised GitHub PATs, unauthorized integration-service code, affected GKE pods, OAuth credential rotation, EDR/Falcon coverage, SIEM integration, secret scanning, and GitHub Actions allowlisting. | Klue's primary update moves reauthorization due diligence beyond Salesforce logs alone and into the vendor's source-control, CI/CD, cloud-runtime, and monitoring controls. | 59 |
| Sector alert indicators | 29-Jun-2026 · Newly retained (>24h) FINRA-published suspicious IP and sender-domain leads associated with the Klue alert, treated as enrichment for Salesforce/Klue investigations rather than a universal blocklist. | FINRA adds sector-facing IOCs and response guidance; validate sightings against local connected-app, Salesforce API, and email telemetry before attribution. | 53 |
| OAuth-abuse cluster correlation | 13-Jul-2026 · Freshly reported (<24h) Microsoft-described Salesforce/SaaS OAuth-abuse patterns: trusted OAuth relationships, connected-app attribution, inherited application privileges, CRM enumeration/querying, and near-real-time event-monitoring visibility. | This helps teams hunt the broader playbook without over-attributing Klue to a different actor label solely because the tradecraft overlaps ShinyHunters-associated campaigns. | 66 |
9-Term Glossary
| Term | Meaning Here | Sources |
|---|---|---|
| Klue | A competitive enablement / market-intelligence SaaS platform with Salesforce integration use cases. | 5,6 |
| Competitive enablement | A sales and revenue-operations industry term for giving sellers structured competitor intelligence, positioning, objection handling, win/loss lessons, and deal guidance. It is not a formal cybersecurity standard term. | 5,6 |
| Battlecard | A short sales enablement artifact that helps a seller compete in a deal. It may include competitor comparisons, differentiators, pricing or feature notes, objection responses, talk tracks, and account strategy. In a Salesforce investigation, battlecard sync can matter because it may sit near account, opportunity, note, and customer/prospect context. | 5,6 |
| Win/loss analysis | A revenue-team process for documenting why deals were won or lost. It can contain customer feedback, competitor references, sales-stage notes, account strategy, pricing pressure, and relationship context that may be sensitive in a CRM exposure. | 5,6 |
| Connected app | A Salesforce application trust relationship that can use OAuth-style authorization and API access. | 13 |
| OAuth token / refresh token | Authorization material that can let an app access Salesforce resources without repeatedly asking for a password. Refresh-token use is especially important because it can preserve app-backed access until revoked or expired. | 1,5,6 |
| GitHub PAT | GitHub personal access token: a credential string used by a person, script, or integration to authenticate to GitHub without an interactive login. In this incident, Klue's CrowdStrike summary says a previously compromised PAT was used to introduce unauthorized integration-service code. | 59 |
| GKE pod containment | GKE means Google Kubernetes Engine. A pod is a running workload unit; containment means disabling affected runtime pods so suspect integration-service code could no longer run while credentials were rotated. | 59 |
| EventLogFile | Salesforce object used for Event Monitoring data. Forensicators use it to inspect event categories such as REST API, API usage, login, report, report export, and other operational activity depending on licensing and retention. | 25,26 |
| Setup Audit Trail | Salesforce administrative-change history. It can help identify connected-app, permission, profile, package, policy, and configuration changes around the exposure window. | 27 |
| Login History | Salesforce login metadata that helps separate human-user logins from integration or app-backed access patterns when correlated with OAuth and EventLogFile records. | 26,28 |
| CRM objects | Salesforce records such as Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, Events, and custom objects. These are the practical data-scoping targets after token-backed API activity. | 5,6,25,26 |
| Supply-chain attack | A downstream impact path through a trusted third party or integration rather than only a direct attack against the final victim. | 1,14 |
10-TTPs
| Technique / TTP | MITRE ATT&CK ID | Source-Backed Detail | Sources |
|---|---|---|---|
| Trusted third-party integration abuse | T1199: Trusted Relationship | Klue's trusted Salesforce integration created a downstream path into customer CRM environments. | 1,5,6,14 |
| OAuth token theft / reuse | T1528: Steal Application Access Token | Public technical reporting centers on OAuth tokens and refresh-token-backed access to connected Salesforce data. | 1,5,6,15 |
| Valid connected-app access | T1078: Valid Accounts | A trusted integration/service-account style path can make access look legitimate until API behavior or token use is reviewed. | 5,6,16 |
| Cloud application integration abuse | T1671: Cloud Application Integration | 13-Jul-2026 · Freshly reported (<24h) Microsoft maps similar Salesforce OAuth-abuse activity to connected-app integration abuse, reinforcing that SaaS app grants can become persistence and access paths. | 66 |
| Automated Salesforce collection | T1119: Automated Collection | Researchers describe automated Salesforce REST API queries and object access that should be validated against EventLogFile and API telemetry. | 5,6,29 |
| Cloud/API exfiltration | T1567.002: Exfiltration to Cloud Storage | Researchers describe automated Salesforce REST API queries and large-volume CRM data access; map exact behavior to local telemetry before labeling exfiltration. | 5,6,17 |
11-Common Questions Q&A
| Question | Answer | Sources |
|---|---|---|
| Was Salesforce itself exploited? | No source used here establishes a Salesforce platform vulnerability. The stronger framing is abuse of a trusted third-party connected app and OAuth relationship through Klue. | 1,2,5,6 |
| What should a customer check first? | Identify whether Klue or Klue Battlecards was connected to Salesforce, preserve relevant Salesforce logs, review connected-app state, revoke and rotate tokens, and scope object-level API access. | 1,5,6,25,26 |
| Does LastPass mean vault compromise? | No. LastPass described a Klue-linked customer-data incident while stating its product systems, services, infrastructure, and vault data were not compromised. | 3,4,30 |
| Can one victim notice define every impact? | No. Public notices are useful scoping examples, but exact data categories, product-system boundaries, and notification obligations differ by organization and must be tied to local Salesforce evidence. | 7,11,12,32,33,34,35,38,39,40,41,42,43 |
| Does Microsoft now attribute Klue to ShinyHunters or Storm-3138? | 13-Jul-2026 · Freshly reported (<24h) Not as a simple replacement label. Microsoft places Klue-related Salesforce/OAuth abuse in a broader ShinyHunters-associated tradecraft discussion. 18-Jul-2026 · Newly retained (>24h) It also names Storm-3138 for Klue system access, which improves detection and deconfliction, but the Klue brief should still keep Icarus/ICARUS as the Klue-specific public extortion/operator label unless a reliable source directly merges or replaces the activity. | 66 |
12-CVE / Vulnerability References
No CVE, KEV entry, or Salesforce platform vulnerability is established by this source set. The incident is best framed as third-party SaaS integration compromise and OAuth/connected-app abuse. If later sources publish a CVE, Salesforce platform advisory, or official KEV entry, this card should be revised. 1,2,5,6
13-IOCs / Observables
| IOC / Observable Type | Indicator / Lead | What To Hunt / Collect | Sources |
|---|---|---|---|
| Connected app | Klue / Klue Battlecards connected application, OAuth usage, or app-level access to Salesforce. | List connected apps, OAuth policies, refresh-token use, scopes, last-used timestamps, and authorized users. | 5,6,13 |
| OAuth token | OAuth refresh-token usage or new token activity tied to Klue integration accounts. | Review Salesforce OAuth usage events and revoke tokens before reauthorization. | 1,5,6 |
| API behavior | High-volume Salesforce REST API query or QueryMore behavior from connected-app context. | Correlate unusual query volume, object enumeration, large result pagination, and unfamiliar source IPs. | 5,6 |
| Salesforce reconnaissance / API behavior | 26-Jun-2026 · Newly retained (>24h) Global Describe object catalog queries, `/services/data/v59.0/query` and QueryMore pagination, API-version downgrade, and deviation from expected Klue infrastructure or user-agent baselines. | Pair these with Klue connected-app context and tenant-specific object access; do not treat any single string as deterministic without correlated Salesforce evidence. | 37 |
| FINRA sector-alert IOCs | 29-Jun-2026 · Newly retained (>24h) FINRA published suspicious IP addresses and sender-domain leads tied to its Klue alert; ZeroFox also published ICARUS-related indicators and infrastructure references. | Use as enrichment only. Do not publish raw victim data or infer universal applicability without Klue connected-app context, Salesforce evidence, and local email/network telemetry. | 53,54 |
| Microsoft Klue IOC context | 13-Jul-2026 · Freshly reported (<24h) Microsoft lists 138.226.246.94 as an IP address used by the Klue integration to call the Salesforce API for CRM queries on June 11, noting it was previously disclosed by Klue. | Treat this as corroborating enrichment. Correlate with Klue connected-app context, Salesforce API events, source IP, user agent, and object access before drawing customer-specific impact conclusions. | 66 |
| User agent | Python-style automation strings reported in technical analysis. | Treat as supporting signal only; correlate with Klue app, token use, API volume, and source infrastructure. | 5,6 |
| LastPass-published IOCs | LastPass published a small appendix of source IP addresses and email sender domains associated with its response. | Treat these as LastPass-context indicators: collect sightings, correlate with Salesforce/Klue evidence, and do not assume universal Klue applicability without local telemetry. | 30 |
| Boundary | This brief does not publish a stable blocklist of domains, hashes, or customer-specific record IDs. | Use environment-specific Salesforce logs and official Klue/customer notifications for deterministic scoping. | 1,6 |
14-Threat Actor Glossary
29-Jun-2026 · Newly retained (>24h) Icarus/ICARUS is the public actor label tied to the Klue-linked extortion/data-theft activity in this source set, but the evidence still does not support treating it as fully resolved attribution. FINRA and ZeroFox reinforce the label and add sector/actor context; ZeroFox also flags Underground Uwu / Scattered Lapsus$ Hunters claims as caveated context. Keep UNC6395 and Salesloft Drift as Salesforce OAuth-abuse comparator context unless a reliable source explicitly merges the Klue activity with that campaign.13-Jul-2026 · Freshly reported (<24h) Microsoft now adds a broader ShinyHunters-associated SaaS OAuth-abuse lens; use it for tradecraft and detection context, not as a standalone instruction to relabel Klue from Icarus to ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft's Storm-3138 label should be tracked as a source-backed activity label for Klue system access, not as a reason to erase the Icarus/ICARUS extortion/operator boundary. 5,6,36,37,53,54,66
| Actor / Activity Label | Meaning In This Brief | Attribution Boundary | Sources |
|---|---|---|---|
| Icarus / ICARUS | 29-Jun-2026 · Newly retained (>24h) Public actor label associated with Klue-linked data theft/extortion claims and Salesforce OAuth-abuse reporting; FINRA and ZeroFox reinforce the Icarus/ICARUS naming. | Use as the current Klue-linked label, not as a final attribution or proof of shared infrastructure with other Salesforce campaigns. | 5,6,36,37,53,54 |
| Underground Uwu / SLH claims | 29-Jun-2026 · Newly retained (>24h) ZeroFox notes public claims involving Underground Uwu and Scattered Lapsus$ Hunters in connection with ICARUS activity. | Use as caveated actor-claim context only. Do not collapse it into UNC6395/Salesloft Drift or customer-impact conclusions without stronger evidence. | 54 |
| Storm-3138 | 18-Jul-2026 · Newly retained (>24h) Microsoft names Storm-3138 as the activity label tied to Klue system access in its July 13 Salesforce/SaaS OAuth abuse research. | Use as Microsoft's activity label for the Klue system-access path. Do not treat it as proof that Klue/Icarus, UNC6395, Salesloft Drift, Gainsight, and ShinyHunters are one merged campaign. | 66 |
| ShinyHunters-associated SaaS OAuth abuse | 13-Jul-2026 · Freshly reported (<24h) Microsoft describes a series of Salesforce/SaaS campaigns observed from mid-2025 to mid-2026 with overlapping tradecraft commonly associated with ShinyHunters, including trusted OAuth relationship abuse, supply-chain compromise, and CRM querying. | Use as broader tradecraft and detection context. Do not use this row alone to collapse Klue/Icarus into UNC6395, Salesloft Drift, Gainsight, or a definitive ShinyHunters attribution. | 66 |
| UNC6395 / Salesloft Drift | Closest public Salesforce OAuth supply-chain comparator: stolen or abused SaaS integration tokens leading to downstream Salesforce data exposure. | Comparator only. Current Klue source set does not merge Klue/Icarus with UNC6395 or the Salesloft Drift campaign. | 18,19,20,21,22,23,24,37 |
15-Talking Points
| Audience | Talking Point | Memorizable Quote |
|---|---|---|
| Executive | This is a Salesforce-data supply-chain issue through a trusted SaaS integration. The question is not only whether Klue was breached; it is whether our Salesforce data was reachable through Klue's OAuth relationship. | “We should treat this like a cloud identity and vendor-access event. If Klue had token-backed access into our Salesforce org, we need to know what objects were reachable, what was queried, and whether customer or prospect data requires notification.” |
| Salesforce Admin | Focus on connected apps, OAuth tokens, REST API query volume, and Klue Battlecards activity. | “Our fastest path to clarity is Salesforce telemetry: connected-app usage, OAuth refresh-token events, REST API queries, source IPs, user agents, and object-level access during the Klue exposure window.” |
| Legal / Privacy | Separate confirmed product compromise from CRM data exposure. | “A downstream customer can be affected even if its own systems were not breached. The legal question is what Salesforce records were accessed through the vendor integration and whether those records include personal, customer, or confidential commercial data.” |
| Client / Claims Scoping | Ask whether the client used Klue or Klue Battlecards, not just whether they received a direct breach notice. | “For scoping, we should collect Klue notices, Salesforce connected-app inventory, token revocation evidence, and API logs. If the integration existed, we need to validate whether access occurred and whether the exposed data changes notification or fraud risk.” |
| Threat Intel | 13-Jul-2026 · Freshly reported (<24h) Microsoft adds ShinyHunters-associated OAuth-abuse tradecraft context, not a definitive replacement of the Klue/Icarus public actor label. | “We should use Microsoft’s research to broaden detection and deconfliction, while keeping Klue-specific attribution language disciplined: Icarus remains the public label in this brief unless direct evidence merges it with another cluster.” |
16-Decision Ready Actions
| Target Persona | Timeframe | Decision / Action | Evidence |
|---|---|---|---|
| Executives | Today | Treat this as SaaS supply-chain CRM exposure, not a password-only incident. | 1,3,4,5 |
| Salesforce owners | Today | Inventory Klue integrations, revoke tokens, and re-authorize only with least privilege and monitoring. | 1,5,6,13 |
| Legal / privacy | 24-48 hours | Determine whether Salesforce objects accessed contain personal data, customer contacts, commercial terms, notes, or regulated data. | 3,6,7 |
| SOC / IR | 24-48 hours | Preserve Salesforce logs and hunt for token/API activity before cleanup obscures timeline. | 5,6 |
| Vendor-risk teams | This week | Update SaaS integration inventories and require vendors to document token revocation, least privilege, and breach notification paths. | 1,2,5 |
| Threat intel / detection | This week | 13-Jul-2026 · Freshly reported (<24h) Track Klue as part of a broader Salesforce/SaaS OAuth-abuse playbook associated with ShinyHunters tradecraft. 18-Jul-2026 · Newly retained (>24h) Track Storm-3138 as Microsoft's Klue system-access activity label while keeping Icarus/ICARUS as the Klue-specific public extortion/operator label unless stronger evidence appears. | 66 |
17-Exploitable Technology Risks
| Technology / Trust Risk | Why It Matters | Defensive Priority | Sources |
|---|---|---|---|
| Over-permissioned connected apps | A third-party integration can access more Salesforce data than the business workflow actually needs. | Review scopes, user mappings, OAuth policies, and connected-app least privilege. | 5,6,13 |
| Long-lived OAuth refresh tokens | Tokens can persist beyond a single user login and provide durable API access. | Revoke tokens, shorten session/token policy where possible, and alert on unusual refresh-token usage. | 1,5,6 |
| CRM data concentration | Salesforce often contains prospects, customer contacts, commercial notes, account strategy, and opportunity data. | Classify high-risk objects and run object-level access/export scoping after integration abuse. | 5,6,7 |
| Third-party blast radius | A single SaaS vendor can create exposure across many customers when it holds trusted integration credentials. | Track critical SaaS vendors as privileged access paths, not just procurement records. | 1,5,6 |
| Reusable OAuth-abuse tradecraft | 13-Jul-2026 · Freshly reported (<24h) Microsoft describes trusted OAuth abuse across Salesforce/SaaS campaigns observed from mid-2025 to mid-2026, with overlap commonly associated with ShinyHunters. | Monitor connected-app attribution, app permissions, OAuth consent grants, CRM querying, and persistence signals across all high-trust SaaS integrations. | 66 |
19-Tier 0 Through Tier 8 Source Summary
| Tier | Trust Role | What This Tier Supports | Caveat | Sources |
|---|---|---|---|---|
| Tier 0 | Primary / official | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike update adds the strongest primary mechanism and containment evidence: compromised GitHub PAT (personal access token), unauthorized integration-service code, Salesforce OAuth token collection, GKE pod containment, no identified access outside integration-service-related systems, no activity after June 12, and CI/CD/security hardening. LastPass, Salesforce, and 8x8 provide downstream and platform boundaries. | Official sources do not publish every downstream customer, object count, or full actor attribution. | 1,2,3,30,40,59 |
| Tier 1 | Starter news | BleepingComputer ties LastPass confirmation to the Klue supply-chain story and gives broad public awareness context. | Secondary to primary notices for product-system and vault-status claims. | 4 |
| Tier 2 | Technical research | 29-Jun-2026 · Newly retained (>24h) ReliaQuest, Datadog, Huntress, Obsidian, and ZeroFox provide mechanism, timeline, OAuth/API hunting, Global Describe/API-version/user-agent deviations, Icarus/ICARUS context, and downstream impact context. 13-Jul-2026 · Freshly reported (<24h) Microsoft adds broader ShinyHunters-associated Salesforce/SaaS OAuth-abuse tradecraft, connected-app visibility guidance, and Klue IOC context. 18-Jul-2026 · Newly retained (>24h) Microsoft's Storm-3138 label is retained as an activity label for Klue system access. | Use local telemetry to confirm exact objects, records, indicators, and exposure per tenant. Microsoft strengthens tradecraft deconfliction but does not by itself replace the Klue-specific Icarus/ICARUS public extortion/operator label. | 5,6,7,37,54,66 |
| Tier 3-4 | Corroboration / customer signal | 29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-resolution timestamp. 02-Jul-2026 · Newly retained (>24h) Trade coverage and customer trust-center notices help show spread, downstream notification patterns, second-wave extortion pressure, and public customer disclosure boundaries; Camunda now narrows its own boundary to standard business-contact and account information, excluding support data. 04-Jul-2026 · Newly retained; undated AlertMedia, Cresta, Lucanet, ABBYY, and Postman add undated direct trust-center or trust-portal boundaries. 05-Jul-2026 · Newly retained (>24h) Automox adds a direct no-impact Salesforce/OAuth review boundary useful for deconflicting leak-list claims. 07-Jul-2026 · Newly retained (>24h) eSentire adds a direct minimal-exposure customer disclosure with restricted-OAuth and customer-service risk boundaries. 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific Salesforce/Klue customer boundary with product, service, and customer-platform exclusions. 09-Jul-2026 · Newly retained (>24h) Snyk adds a Mandiant-assisted investigation-closure boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary with Salesforce-only impact and no core-product/cloud/production impact reported. 11-Jul-2026 · Newly retained (>24h) OneTrust adds investigation closure, finalized containment/remediation, and no evidence of exposure beyond its Salesforce environment. 14-Jul-2026 · Newly retained; undated Sisense adds an undated direct trust-center boundary for business and sales-related Salesforce CRM data while excluding Sisense product-platform data. 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer boundaries for Salesforce data access while preserving platform/product exclusions. | Do not treat every named organization as having the same exposure without its own notice; SentinelOne is retained as a public advisory/partner-notification lead because the direct portal reference is access-controlled; OneTrust's governance, compliance, and notification review remains ongoing; Sisense has no visible publication date and should not be labeled fresh; Splashtop's investigation remained ongoing at publication. | 8,9,10,11,12,31,32,33,34,35,36,38,39,41,42,43,44,45,46,47,48,49,50,51,52,55,56,57,58,60,61,62,63,64,65,67,68,69 |
| Tier 5 | Framework / documentation | 29-Jun-2026 · Newly retained (>24h) Salesforce docs, MITRE ATT&CK, and FINRA sector guidance help explain connected-app trust, EventLogFile forensics, login/setup audit data, token theft, trusted relationships, valid-account behavior, automated collection, exfiltration mapping, IOCs, and response priorities. | Framework and sector guidance support scoping; they do not prove tenant impact. Salesforce log availability depends on edition, licensing, retention, and tenant configuration. | 13,14,15,16,17,25,26,27,28,29,53 |
| Tier 8 | Expansion research | Salesloft Drift sources provide the closest prior Salesforce OAuth supply-chain comparator: a trusted SaaS integration, stolen OAuth tokens, downstream Salesforce data theft, and tenant-specific revocation/scoping. | Drift is a comparator, not evidence that Klue and Drift share the same actor, infrastructure, or campaign window. | 18,19,20,21,22,23,24 |
20-Source Reconciliation
| Source Issue | Agreement / Difference | Tension or Contradiction | How To Use It |
|---|---|---|---|
| Salesforce platform boundary | No public source used here establishes a Salesforce platform vulnerability. The strongest framing is third-party OAuth/connected-app abuse through Klue. | A CRM data exposure can be misread as a Salesforce core exploit. | Focus teams on integration tokens, connected apps, Salesforce logs, and CRM scoping. 1,2,5,6 |
| Root-cause mechanism refinement | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary refines the path: a previously compromised GitHub PAT introduced unauthorized code into Klue's integration service, which collected third-party integration credentials including Salesforce OAuth access and refresh tokens. | Earlier shorthand about a legacy integration credential remains useful for token-exposure scoping but is no longer the most precise root-cause language. | Use the PAT/code path for root-cause and vendor-control discussions; use OAuth/connected-app language for downstream Salesforce tenant scoping. 1,5,6,59 |
| LastPass impact boundary | LastPass says its product systems, services, infrastructure, and vaults were not compromised; the issue was customer/CRM data tied to Klue/Salesforce. | Public headlines can overstate this into a LastPass vault compromise. | Separate CRM/customer-record exposure from password-vault or product-system compromise, while still treating exposed contact and support data as phishing/social-engineering risk. 3,4,30 |
| Salesloft Drift comparison | Drift is the strongest prior Salesforce OAuth supply-chain comparator: trusted SaaS integration access became the path to downstream Salesforce data. | The comparator can be mistaken for shared actor, infrastructure, or campaign timing. | Use Drift to guide scoping questions, not attribution. 18,19,20,21,22,24 |
| Actor identity | 29-Jun-2026 · Newly retained (>24h) Icarus/ICARUS is the public actor label tied to Klue in this source set; FINRA and ZeroFox reinforce the label, while ZeroFox caveats Underground Uwu / Scattered Lapsus$ Hunters references and Obsidian keeps Klue/Icarus separate from UNC6395/Salesloft Drift except as pattern comparison. 13-Jul-2026 · Freshly reported (<24h) Microsoft places Klue-adjacent OAuth abuse inside broader Salesforce/SaaS tradecraft commonly associated with ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft names Storm-3138 for the Klue system-access path, adding a source-backed activity label without proving that Icarus/ICARUS, UNC6395, Salesloft Drift, and ShinyHunters are one campaign. | Shared Salesforce OAuth-abuse tradecraft and public actor claims can be mistaken for shared operators or merged labels. | Use Storm-3138 as Microsoft's activity label for Klue system access, use Icarus/ICARUS for the Klue-linked extortion/data-theft label, keep Underground Uwu/SLH as caveated actor-claim context, keep UNC6395/Salesloft Drift as comparator context, and use Microsoft to broaden ShinyHunters-associated tradecraft hunting unless stronger attribution evidence appears. 5,6,36,37,53,54,66 |
| Affected-customer boundary | 28-Jun-2026 · Newly retained (>24h) Downstream customers using impacted Klue/Salesforce or Klue-connected integration paths may need to scope exposure; published notices vary by organization, and direct OneTrust, Gong, and Insurity notices reinforce that impact boundaries are organization-specific. 11-Jul-2026 · Newly retained (>24h) OneTrust now states its technical investigation, containment, and remediation are complete, with no evidence of exposure beyond its Salesforce environment. | Not every Klue customer necessarily had the same exposure or data access; investigation closure for one customer does not close another customer's scope. | Make customer-specific statements from notices and local Salesforce telemetry only. 1,7,11,12,32,33,34,35,36,38,39,40,41,42,43,44,45,46 |
| Follow-on extortion pressure | Fresh reporting says Klue told customers the original criminals were deleting stolen data while a second group was making threats. | Second-group possession, completeness, and proof may vary by customer and should not be assumed without direct evidence. | Treat follow-on contact as an extortion/scoping lead: preserve communications, demand proof before conclusions, and coordinate legal and law enforcement. 31 |
| Expanded public disclosures | 29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-resolution timestamp for a Klue-Salesforce integration notice. 02-Jul-2026 · Newly retained (>24h) Link11, ControlUp, Deel, Saviynt, and Camunda add or refine direct CRM, sales-data, Salesforce-data, or business-contact/account notice boundaries. 04-Jul-2026 · Newly retained; undated AlertMedia, Cresta, Lucanet, ABBYY, and Postman remain undated direct trust-center or trust-portal boundaries. 07-Jul-2026 · Newly retained (>24h) eSentire adds a dated direct customer disclosure with minimal Salesforce exposure and explicit exclusions for customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a dated direct status notice for a UAT CRM environment exposure boundary. 09-Jul-2026 · Newly retained (>24h) Snyk adds an investigation-complete boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS adds a public SentinelOne advisory lead. 11-Jul-2026 · Newly retained (>24h) OneTrust adds investigation-complete and Salesforce-only exposure-boundary language. 14-Jul-2026 · Newly retained; undated Sisense adds a direct undated trust-center boundary for business and sales-related Salesforce CRM data, excluding product-platform data. 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add direct older Salesforce/Klue notice boundaries with product/platform exclusions. | The exact data categories and business impact differ by organization; Camunda's latest notice narrows, rather than expands, its support-data boundary, Postman excludes customer data access from Gong while confirming Salesforce exfiltration, eSentire limits exposure to standard business contact and sales metadata fields, Thinkproject confines its public boundary to UAT CRM business-contact/commercial information, Snyk closes on business CRM data, SentinelOne data analysis remains ongoing, OneTrust's governance/compliance review remains ongoing, Sisense has no visible publication date, and Splashtop's investigation remained ongoing. | Use named notices as scoping examples, not as a universal victim impact template. Treat SentinelOne as qualified until a public direct notice is accessible; treat Sisense as newly retained undated, not fresh; treat Qualtrics and Splashtop as newly retained older disclosures. 32,33,34,35,36,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,55,56,57,58,60,62,63,64,65,67,68,69 |
| Leak-list and second-actor claims | 05-Jul-2026 · Newly retained (>24h) Automox says its name appeared on a second threat actor list, but its data was not in the sample, it did not receive Klue CEO outreach to impacted organizations, and Klue confirmed no indication Automox data or customer data was affected. | A named organization in a leak-list or second-actor claim is not the same as confirmed Salesforce exfiltration. | Treat Automox as a direct no-impact/deconfliction example: preserve the lead, validate against Salesforce logs and vendor notice facts, and avoid promoting leak-list-only claims as public victims. 61 |
21-About the Contributors
| Contributor | Who They Are / What They Do | Contribution & Why It Matters Here | Sources |
|---|---|---|---|
| Klue | Primary vendor / integration provider | 02-Jul-2026 · Freshly reported (<24h) Publishes the controlling vendor statements on unauthorized integration-infrastructure activity, the CrowdStrike-refined GitHub PAT and unauthorized integration-service code path, credential/token revocation, integration disabling, monitoring, and security hardening. | 1,59 |
| LastPass | Downstream customer | Confirms customer-data impact through Klue, identifies Salesforce/Gong integration context, describes token rotation and discontinued Klue access, and states LastPass product systems and vaults were not compromised. | 3,30 |
| Salesforce | Platform provider | Provides ecosystem framing that the activity is not a Salesforce platform vulnerability and that third-party application trust is central. | 2 |
| OneTrust | Downstream customer boundary update | 11-Jul-2026 · Newly retained (>24h) Adds a July 10 investigation-complete update: technical investigation, scope validation, containment, and remediation are complete; no evidence was found beyond OneTrust's Salesforce environment; governance, compliance, and notification review continue. | 44 |
| ReliaQuest / Datadog / Huntress / Obsidian | Technical researchers and affected defender signal | Add OAuth, REST API, token, timeline, Global Describe, QueryMore, API-version, user-agent, hunt, and downstream-impact detail that turns the story into an actionable IR scoping brief. | 5,6,7,37 |
| BleepingComputer, SecurityWeek, and trade press | Public corroboration | Translate the incident into accessible public risk language and confirm that LastPass and other organizations are responding publicly, including follow-on reporting about public disclosure volume and second-wave extortion pressure. | 4,8,9,10,31,32,36 |
| Postman | Downstream customer | 04-Jul-2026 · Newly retained; undated Adds a direct customer boundary for Salesforce customer contact/sales-data exfiltration via Klue, while excluding customer data access from Gong and core platform-services impact. | 60 |
| eSentire | Downstream customer | 07-Jul-2026 · Newly retained (>24h) Adds a direct minimal-exposure Salesforce boundary, restricted-OAuth/limited-connected-app context, customer-service no-risk statement, and exclusions for customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. | 62 |
| Thinkproject | Downstream customer | 08-Jul-2026 · Newly retained (>24h) Adds a direct UAT CRM exposure boundary, possible business-contact and commercial-information data categories, and exclusions for Thinkproject products, services, and the customer product platform. | 63 |
| Sisense | Downstream customer | 14-Jul-2026 · Newly retained; undated Adds a direct trust-center boundary for certain business and sales-related Salesforce CRM data, while excluding Sisense product-platform and product-platform data impact. | 67 |
| Qualtrics / Splashtop | Downstream customer boundary updates | 16-Jul-2026 · Newly retained (>24h) Qualtrics adds a direct Salesforce B2B-identifier boundary with Qualtrics platform customer-data exclusion. Splashtop adds a direct Klue/Salesforce OAuth notice with product/service exclusion and ongoing-investigation caveat. | 68,69 |
| Microsoft Security Research / Microsoft Defender Security Research Team | Technical research / campaign deconfliction | 13-Jul-2026 · Freshly reported (<24h) Adds broader ShinyHunters-associated Salesforce/SaaS OAuth-abuse tradecraft context, connected-app visibility guidance, MITRE technique mapping, and a Klue integration IP context note for June 11 Salesforce API CRM queries. 18-Jul-2026 · Newly retained (>24h) Adds the Storm-3138 activity label for the Klue system-access path while preserving Icarus/ICARUS as a separate public extortion/operator label. | 66 |
| Snyk / SentinelOne | Downstream customer boundary updates | 09-Jul-2026 · Newly retained (>24h) Snyk adds Mandiant-assisted investigation closure with business-CRM-data-only impact and no Snyk platform impact. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary: Salesforce-environment-only impact through Klue API integration, no lateral movement, no core-product/cloud/production impact, and ongoing data analysis. | 64,65 |
22-Real World Examples
| Example | What It Shows | Boundary | Sources |
|---|---|---|---|
| Klue integration infrastructure | Klue says unauthorized activity affected part of its integration infrastructure and involved a compromised legacy integration credential that exposed OAuth tokens used to connect Klue with Salesforce and other platforms. 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary adds that a previously compromised GitHub PAT introduced unauthorized code into the integration service and collected third-party integration credentials. | This is the upstream supply-chain path. Do not turn it into a Salesforce platform vulnerability or a finding that all Klue-hosted customer content was exposed. | 1,59 |
| LastPass | 26-Jun-2026 · Newly retained (>24h) LastPass is the clearest named downstream example in the starter source set: it confirmed a Klue-linked customer-data incident after Klue notified it of Salesforce-related exposure. The detailed response adds Salesforce and Gong integration context, token rotation, discontinued Klue access, customer anti-phishing guidance, published IOCs, and law-enforcement cooperation. | This should be described as customer/business data exposure through a vendor integration, not a LastPass vault compromise. LastPass stated its product systems, services, infrastructure, and vault data were not compromised. | 3,4,30 |
| Huntress | Huntress publicly identified itself as an impacted organization and described the Salesforce data categories that make this operationally meaningful: business contacts, price quotes, sales communications, and competitive reports. | Use Huntress as a concrete Salesforce-object scoping pattern. Do not assume every downstream customer had the same objects, volumes, or business impact. | 7 |
| CRM data impact model | The real-world value to an attacker is not limited to one record type. Salesforce CRM exposure can include Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, Events, custom objects, sales strategy, pricing context, and customer-support context. | For notification and counsel review, object-level access must be proven from local Salesforce logs and customer notices, not inferred from another victim's report. | 5,6,7,25,26 |
| Jamf / Sprout Social notices | Jamf and Sprout Social notices show the downstream notification ecosystem: organizations had to review whether Klue/Salesforce access created customer, prospect, or business-data exposure in their own environments. | Each notice should be read on its own facts. A named notice is useful for scoping examples, but it is not proof that every Klue customer had the same exposure. | 11,12 |
| BeyondTrust / Snyk / HackerOne | 26-Jun-2026 · Newly retained (>24h) Newly retained downstream notices and reporting expand the public customer-disclosure set and show how organizations are scoping Salesforce business data, support-case metadata, credential/log review, and Klue disconnection. | The organizations do not report identical impacts. Use each notice on its own facts and validate with local Salesforce logs before extrapolating. | 32,33,34,35 |
| SecurityWeek expanded disclosure set | 26-Jun-2026 · Freshly reported (<24h) SecurityWeek reports roughly two dozen public Klue-Salesforce impact disclosures and names additional notice examples including AlertMedia, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. | Use this as a public-disclosure count and discovery lead. Do not assign identical impact to every named organization without that organization's own notice or local Salesforce telemetry. | 36 |
| Pendo / Recorded Future / 8x8 | 26-Jun-2026 · Newly retained (>24h) Pendo and 8x8 directly disclosed Salesforce/CRM exposure through Klue with product or operational boundaries. 26-Jun-2026 · Newly retained; undated Newly retained (publication date not visible): Recorded Future directly disclosed Salesforce impact through a Klue OAuth token while preserving its core platform, Intelligence Graph, and infrastructure boundary. | Pendo, Recorded Future, and 8x8 each define different data categories and impact limits. Their notices support scoping patterns, not a universal victim template. | 38,39,40 |
| LogicMonitor/Catchpoint / Tines / Tanium | 27-Jun-2026 · Newly retained (>24h) LogicMonitor disclosed unauthorized access to the Catchpoint Salesforce environment through Klue, while stating LogicMonitor's primary Salesforce environment and production/monitoring systems were not impacted. Tanium disclosed Salesforce CRM data exfiltration through Klue while stating Tanium products and cloud infrastructure were not impacted. 27-Jun-2026 · Newly retained; undated Tines stated Klue credentials were used to access Salesforce data and that it found no evidence of unauthorized access to the Tines platform or customer environments. | These notices strengthen direct customer-disclosure coverage but do not create a universal impact model. Preserve each organization's Salesforce/product-system boundary. | 41,42,43 |
| OneTrust / Gong / Insurity | 28-Jun-2026 · Newly retained (>24h) OneTrust disclosed Klue Battlecards/Salesforce CRM-related data exposure and no evidence of customer-tenant exposure. Gong disclosed a Klue-originated issue for customers who connected Klue with Gong, while stating call recordings and transcripts were not directly impacted. Insurity disclosed Salesforce/Klue suspicious activity and a limited set of active credentials in exposed CRM data that it rotated or reset. 11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update says its technical investigation is complete, containment and remediation are finalized, and no exposure was found beyond its Salesforce environment. | These are first-party impact boundaries, not universal exposure statements. OneTrust's governance, compliance, and notification review remains ongoing. Treat Gong as a connected-platform disclosure rather than proof of broader Salesforce impact for every Klue customer. | 44,45,46 |
| AudienceView / Link11 / AlertMedia / Camunda / Cresta / Lucanet | 29-Jun-2026 · Freshly reported (<24h) AudienceView retained a fresh status-resolution timestamp for its Klue-Salesforce integration incident while preserving product, production-system, internal-system, and patron-data boundaries. 29-Jun-2026 · Newly retained (>24h) Link11 directly disclosed affected CRM data through its Klue OAuth-based Salesforce integration. 29-Jun-2026 · Newly retained; undated AlertMedia, Cresta, and Lucanet add undated trust-center notices with organization-specific Salesforce or product-boundary language. 02-Jul-2026 · Newly retained (>24h) Camunda's latest update narrows its boundary to standard business-contact and account information in Salesforce CRM and says support data was not included. | Use these as additional direct disclosure examples. AudienceView's fresh label applies to the status-resolution timestamp, not to the original June 22 monitoring context; Camunda's latest label applies only to Camunda's own revised impact boundary. | 47,48,49,50,51,52 |
| ControlUp / Deel / Saviynt / ABBYY | 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct notices for Salesforce, CRM, sales, or business-contact data exposure tied to Klue, with product and infrastructure boundaries. 30-Jun-2026 · Newly retained; undated ABBYY adds an undated trust-center boundary for affected Salesforce data accessed through Klue's integration. | These notices expand public victimology but do not change the actor/campaign analysis, create a Salesforce platform-vulnerability finding, or establish identical data categories across customers. | 55,56,57,58 |
| Postman | 04-Jul-2026 · Newly retained; undated Postman's Security & Trust Portal notice confirms customer contact data and sales information were exfiltrated from Salesforce via the compromised Klue service account between June 11-12. Postman says customer data was not accessed from Gong. | Preserve Postman's own boundary: the notice describes Salesforce customer contact/sales data exposure, not Gong customer-data access or a Postman core-platform compromise. | 60 |
| Automox | 05-Jul-2026 · Newly retained (>24h) Automox's Trust Center notice says Automox used Klue with Salesforce and reviewed internal logs, Salesforce Login History, Connected App OAuth usage, all API event types across the exposure period, Icarus malicious IPs, and Klue flagged egress addresses. Automox reported no anomalous or malicious activity. | Use Automox as a no-impact and leak-list deconfliction example. Automox says its data was not present in a second actor's sample and that Klue had no indication Automox data or customer data was affected. | 61 |
| eSentire | 07-Jul-2026 · Newly retained (>24h) eSentire's June 26 blog says eSentire uses Klue and was among organizations whose Salesforce data was accessed. eSentire describes the exposure as minimal because its Klue integration was tightly scoped, with restricted OAuth permissions and a limited connected-app footprint. | Preserve eSentire's own boundary: no customer-service risk was identified, and no customer communication or support interactions, threat intelligence, telemetry, credentials, passwords, or payment card data were affected. | 62 |
| Thinkproject | 08-Jul-2026 · Newly retained (>24h) Thinkproject's June 26 status notice says Klue had authorized access to Thinkproject's UAT CRM environment through a software integration and that exfiltrated data may include business-contact and commercial information. | Preserve Thinkproject's own boundary: no Thinkproject products or services were affected, and the CRM system is separate from the customer product platform. | 63 |
| Snyk / SentinelOne | 09-Jul-2026 · Newly retained (>24h) Snyk's July 8 status resolution says its Klue/Salesforce forensic investigation, conducted with Mandiant, is complete and confirmed business CRM data as the impact boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS's July 9 advisory relays a SentinelOne partner-notification boundary: Salesforce-only impact via the Klue API integration, no lateral movement, and no core-product, cloud-infrastructure, or production impact reported. | Preserve both boundaries separately: Snyk closes on business CRM data with no platform impact; SentinelOne is retained as a qualified public advisory/partner-notification lead because the direct portal reference is access-controlled and data analysis remains ongoing. | 64,65 |
| Follow-on extortion pressure | 26-Jun-2026 · Freshly reported (<24h) TechCrunch reports Klue told customers that the original criminals were deleting stolen data while a second group had begun making threats. | Treat second-wave contact as an extortion and evidence-preservation lead. Do not assume possession, completeness, or authenticity without source/customer-specific proof. | 31 |
| Microsoft ShinyHunters-associated OAuth abuse research | 13-Jul-2026 · Freshly reported (<24h) Microsoft groups Salesforce and SaaS OAuth-abuse campaigns observed from mid-2025 to mid-2026 as tradecraft commonly associated with ShinyHunters, and includes Klue integration Salesforce API activity as part of that broader defensive context. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system-access path. | Use this as tradecraft, activity-label, and detection enrichment. It does not add a named public victim row and should not override the Klue-specific Icarus/ICARUS extortion/operator boundary without direct corroboration. | 66 |
| Sisense | 14-Jul-2026 · Newly retained; undated Sisense's Trust Center says Sisense was one of many affected organizations and that the incident was limited to certain business and sales-related data in its Salesforce CRM application. | Preserve Sisense's own boundary: it states the Sisense product platform and data stored within the product platform were not impacted, and the notice has no visible publication date. | 67 |
| Qualtrics / Splashtop | 16-Jul-2026 · Newly retained (>24h) Qualtrics says the Klue application connected to Salesforce to support internal sales teams, unauthorized access was limited to a subset of Salesforce data, and impacted data included business-to-business identifiers. Splashtop says Klue OAuth tokens were used to access certain Salesforce data and that it disabled the Klue Salesforce integration and revoked associated access. | Preserve each organization's own boundary: Qualtrics excludes products, core infrastructure, services, and hosted platform customer data; Splashtop excludes product and service impact while noting its investigation remained ongoing. | 68,69 |
| Investigation takeaway | The practical lesson is that a trusted SaaS integration can create a downstream Salesforce breach path even when the downstream customer's own product systems were not initially compromised. | Scope the connected app, OAuth tokens, API activity, and exact CRM objects before writing executive, legal, or customer-notification language. | 1,3,5,6,7 |
23-Public Victims / Disclosure Matrix
Public Klue-related customer notices should be read as organization-specific Salesforce or CRM exposure statements. Do not turn one notice into a universal impact model; each row below preserves who disclosed the impact and the boundary that source stated.
| Victim / Organization | Confirmed? | Reported / Disclosed By | Impact Boundary |
|---|---|---|---|
| LastPass | Confirmed public customer statement | LastPass statement and BleepingComputer reporting 3,4,30 | Customer/business-data issue tied to Klue/Salesforce context; LastPass stated product systems, services, infrastructure, and vault data were not compromised. |
| Huntress | Confirmed public customer statement | Huntress disclosure 7 | Salesforce data categories were described publicly; use as an object-scoping example, not a universal exposure template. |
| Jamf / Sprout Social | Confirmed public notices | Customer trust-center notices 11,12 | Downstream notification examples showing customer/prospect/business-data review; each notice stands on its own facts. |
| BeyondTrust / Snyk / HackerOne | Publicly reported or noticed | Customer notices and reporting 32,33,34,35 | Useful for disclosure-pattern analysis; reported impacts and product-system boundaries differ by organization. |
| Pendo / Recorded Future / 8x8 | Confirmed public notices | Customer disclosures 38,39,40 | Salesforce/CRM exposure language is source-specific; several notices preserve explicit core-product or platform boundaries. |
| LogicMonitor/Catchpoint / Tines / Tanium | Confirmed public notices | Customer disclosures 41,42,43 | Each notice separates Salesforce or Klue-connected exposure from production, platform, or customer-environment boundaries. |
| OneTrust / Gong / Insurity | Confirmed public notices | 28-Jun-2026 · Newly retained (>24h) Customer and connected-platform disclosures 44,45,46 11-Jul-2026 · Newly retained (>24h) OneTrust investigation-complete update 44 | OneTrust now states its technical investigation, containment, and remediation are complete and that the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment; Gong limits direct impact away from call recordings and transcripts; Insurity limits product impact and says a small credential set was rotated or reset. |
| AudienceView / Link11 / AlertMedia / Camunda / Cresta / Lucanet | Confirmed public notices | 29-Jun-2026 · Freshly reported (<24h) AudienceView status notice 47 29-Jun-2026 · Newly retained (>24h) Link11 disclosure 48 29-Jun-2026 · Newly retained; undated AlertMedia, Cresta, and Lucanet trust-center notices 49,51,52 02-Jul-2026 · Newly retained (>24h) Camunda boundary revision 50 | AudienceView separates Klue-Salesforce integration impact from product, production, internal-system, and patron-data compromise; Link11 describes certain CRM data affected; Camunda now excludes support data and limits its disclosure to standard business-contact and account information in Salesforce CRM; AlertMedia, Cresta, and Lucanet each require their own trust-center boundary. |
| ControlUp / Deel / Saviynt / ABBYY | Confirmed public notices | 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt notices 55,56,57 30-Jun-2026 · Newly retained; undated ABBYY Trust Center notice 58 | ControlUp, Deel, and Saviynt separate Salesforce/CRM or sales-data exposure from product, production, infrastructure, service, or product-customer-data compromise; ABBYY states its network, products, and technology were not affected. |
| Postman | Confirmed public notice | 04-Jul-2026 · Newly retained; undated Postman Security & Trust Portal notice 60 | Postman confirms Salesforce customer contact and sales information exfiltration via Klue, excludes customer data access from Gong, and states core platform services remain secure and were not impacted. |
| Automox | Public no-impact notice | 05-Jul-2026 · Newly retained (>24h) Automox Trust Center notice 61 | Automox reports Klue/Salesforce exposure review, no anomalous or malicious Salesforce activity, no Automox data in a second actor sample, and Klue confirmation that it had no indication Automox data or customer data was affected. |
| eSentire | Confirmed public notice | 07-Jul-2026 · Newly retained (>24h) eSentire blog 62 | eSentire reports minimal Salesforce exposure due to restricted OAuth permissions and a limited connected-app footprint, no identified customer-service risk, and no affected customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, or payment-card data. |
| Thinkproject | Confirmed public status notice | 08-Jul-2026 · Newly retained (>24h) Thinkproject status notice 63 | Thinkproject reports Salesforce/Klue access to a UAT CRM environment, possible business-contact and commercial-information exposure, no product or service impact, and CRM separation from the customer product platform. |
| Snyk / SentinelOne | Snyk confirmed status resolution; SentinelOne qualified public advisory | 09-Jul-2026 · Newly retained (>24h) Snyk status resolution 64 09-Jul-2026 · Freshly reported (<24h) Secure ISS advisory relaying SentinelOne partner-notification details 65 | Snyk reports a completed Mandiant-assisted investigation, business CRM data only, and no Snyk platform or sensitive platform-data impact. Secure ISS reports SentinelOne impact contained to Salesforce via Klue API integration, with no lateral movement or core-product/cloud/production impact; SentinelOne data analysis remains ongoing. |
| Sisense | Confirmed public trust-center notice | 14-Jul-2026 · Newly retained; undated Sisense Trust Center notice 67 | Sisense reports impact limited to certain business and sales-related data stored in its Salesforce CRM application, with no impact to the Sisense product platform or product-platform data. The trust-center notice has no visible publication date. |
| Qualtrics / Splashtop | Confirmed public notices | 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop direct notices 68,69 | Qualtrics reports unauthorized access to a subset of Salesforce data, including business-to-business identifiers, while excluding products, core infrastructure, services, and hosted platform customer data. Splashtop reports certain Salesforce data access through Klue OAuth tokens, disabled/revoked Klue Salesforce access, no product or service impact, and an ongoing investigation. |
| Additional named public disclosure leads | Reported, verify per organization | SecurityWeek expanded disclosure reporting 36 | Use as discovery leads for public notices; do not treat every named organization as having identical data categories or impact. |
24-KEV and CVE Details
No CISA KEV or CVE entry is associated with the Klue incident in this source set. This is a supply-chain, token, and SaaS integration trust issue; response should not wait for CVE/KEV framing.
25-MITRE ATT&CK Lifecycle Mapping
| MITRE Tactic / Phase | Technique | Klue Incident Mapping | Defender Breakpoint | Sources |
|---|---|---|---|---|
| Initial Access | T1199: Trusted Relationship | 02-Jul-2026 · Freshly reported (<24h) Klue's CrowdStrike summary says a previously compromised GitHub PAT enabled unauthorized code in the integration service that collected third-party credentials, including Salesforce OAuth tokens. | Validate third-party connected apps, service accounts, token state, vendor source-control controls, integration-service runtime containment, and Klue reauthorization boundaries. | 1,5,14,59 |
| Credential Access | T1528: Steal Application Access Token | The useful access material is the Salesforce OAuth access/refresh-token relationship, not a normal user password reset problem. | Review OAuth usage, token revocation evidence, authorized users, app scopes, connected-app policy, and vendor evidence that OAuth credentials were rotated. | 1,5,6,15,59 |
| Persistence | T1671: Cloud Application Integration | 13-Jul-2026 · Freshly reported (<24h) Microsoft maps Salesforce OAuth abuse to connected-app integration leverage, reinforcing that trusted SaaS grants can become durable access paths. | Inventory authorized apps, review OAuth consent and app privileges, validate connected-app attribution, and alert on CRM querying from unexpected app or source contexts. | 66 |
| Defense Evasion | T1078: Valid Accounts | Token-backed app activity can look like authorized Salesforce integration use until EventLogFile and connected-app telemetry are reviewed. | Correlate connected-app identity, source IP, user agent, REST API events, Login History, and Setup Audit Trail. | 5,6,16,25,26,27,28 |
| Collection | T1119: Automated Collection | Researchers describe automated Salesforce REST API queries and object-level access patterns that require tenant-specific validation. | Review REST API, query/queryMore, API usage, report/report export, and object-specific access against Accounts, Contacts, Leads, Opportunities, Cases, Tasks, Notes, and custom objects. | 5,6,25,26,29 |
| Exfiltration | T1567.002: Exfiltration to Cloud Storage | Public reporting supports data access and exfiltration risk from connected Salesforce environments, but exact objects and counts vary by customer. | Scope exposed CRM records per tenant before notification conclusions. | 5,6,7,17 |
26-Source Weighting / Relevance
| Source Group | Contribution | Confidence | Caveat |
|---|---|---|---|
| Primary statements | 02-Jul-2026 · Freshly reported (<24h) Klue/CrowdStrike adds primary mechanism and containment detail: GitHub PAT (personal access token), unauthorized integration-service code, Salesforce OAuth token collection, GKE pod containment, no identified access outside integration-service-related systems, no activity after June 12, and hardening actions. 02-Jul-2026 · Newly retained (>24h) Camunda narrows its own customer-notice boundary to standard business-contact and account information. 04-Jul-2026 · Newly retained; undated Several trust-center notices, including Postman's direct Salesforce/Gong boundary, remain undated and should not be treated as fresh. 05-Jul-2026 · Newly retained (>24h) Automox adds a dated no-impact notice that is high value for source deconfliction, not victim expansion. 07-Jul-2026 · Newly retained (>24h) eSentire adds a dated direct minimal-exposure disclosure and customer-service boundary. 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a dated UAT CRM customer-disclosure boundary. 11-Jul-2026 · Newly retained (>24h) OneTrust adds a dated investigation-complete update with no exposure found beyond Salesforce. 14-Jul-2026 · Newly retained; undated Sisense adds an undated direct trust-center disclosure for Salesforce CRM business/sales data and product-platform exclusion. 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer-disclosure boundaries for Salesforce data access, product/platform exclusions, and Splashtop's ongoing-investigation caveat. | High | Not every detail of object-level exposure is public; no-impact, minimal-impact, UAT-specific, investigation-complete, ongoing-investigation, and undated trust-center notices should not be rewritten as universal outcomes for other customers. |
| Technical research | 13-Jul-2026 · Freshly reported (<24h) Microsoft adds ShinyHunters-associated SaaS OAuth-abuse tradecraft context, connected-app integration mapping, and Klue IOC enrichment. 18-Jul-2026 · Newly retained (>24h) Microsoft's Storm-3138 label is now retained as a Klue system-access activity label. ReliaQuest, Datadog, Huntress, Obsidian, and ZeroFox provide Klue-specific hunting and attack-flow detail. | Medium-High | Confirm exact indicators and objects locally. Do not treat Storm-3138 or shared OAuth-abuse tradecraft as definitive proof of a merged actor/campaign across Klue, Icarus/ICARUS, UNC6395, Salesloft Drift, Gainsight, and ShinyHunters. |
| Security media | BleepingComputer, TechCrunch, SecurityWeek, and trade press make the story visible, connect named downstream organizations, and flag follow-on extortion posture. | Medium | Do not let media summaries override primary notices. |
| MITRE / Salesforce docs | Framework and platform documentation explain why trusted apps, tokens, and connected apps are the right control layer. | High for definitions | Definitions do not prove impact. |
27-Additional IntelliOS Threat Intel Products on This Topic
Icarus Threat Actor Snapshot
Use the full intelligence product for Icarus attribution boundaries, OAuth-abuse tradecraft, victimology, response priorities, and the cumulative AI Agent assessment.
Icarus Actor Card
Open the canonical CARDS identity record for aliases, linked activity, source reconciliation, briefing points, and related campaigns.
Klue Salesforce OAuth Supply-Chain Attack
Open the canonical campaign card for the Klue incident, associated actors, OAuth mechanics, affected scope, defensive takeaways, and retained source boundaries.
Salesloft Drift OAuth Supply-Chain Attack
Use this as the closest Salesforce SaaS/OAuth supply-chain comparator: trusted integration tokens, downstream Salesforce exposure, token revocation, and CRM-object scoping.
28-Notes
Create an account and sign-in to use this card.
Record your personal notes and comments in this card related to this brief.
29-Citations
Baseline Sources Answering The Topic Question
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 1 | An Update on the Recent Klue Security Incident | Klue | June 22, 2026 | Primary vendor statement confirming unauthorized activity affecting part of Klue integration infrastructure, a compromised legacy integration credential, OAuth tokens used to connect Klue with Salesforce, customer-environment access, token revocation, integration disablement, and law-enforcement notification. |
| 2 | Update on Recent Salesforce Data Theft Incidents | Salesforce | June 2026 | Official Salesforce ecosystem context: malicious activity tied to third-party application connections and social-engineering/OAuth abuse, with no Salesforce platform vulnerability identified. |
| 3 | LastPass Update on Klue Customer Data Incident | LastPass | June 2026 | Primary downstream-customer notice: LastPass says Klue notified it of a Salesforce-related incident and states LastPass product systems and vaults were not compromised. |
| 4 | LastPass confirms data breach in Klue supply chain attack | BleepingComputer | June 23, 2026 | Starter public report connecting LastPass customer-data exposure to Klue as a third-party vendor and summarizing the supply-chain framing for a broad security audience. |
| 5 | Klue Integration Abused in Salesforce Data Theft | ReliaQuest | June 22, 2026 | Technical and operational reporting on Klue Battlecards integration abuse, OAuth tokens, Salesforce REST API queries, observed exfiltration, Python automation, attribution caveats, and response priorities. |
| 6 | Detecting the Klue supply chain attack in Salesforce instances | Datadog Security Labs | June 2026 | Detection-focused reporting on Klue/Salesforce activity, compromised connected application identification, OAuth refresh token usage, REST API query patterns, timelines, event types, and hunting logic. |
| 7 | Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress | June 18, 2026 | Victim/researcher account documenting downstream Salesforce impact, broad victim implications, OAuth-token abuse, and practical investigation guidance. |
| 8 | Klue investigates supply-chain attack involving Salesforce integrations | Cybersecurity Dive | June 20, 2026 | Security trade reporting on anomalous activity in Klue's Salesforce integration application, token revocation, and customer notification posture. |
| 9 | Third-Party OAuth Breach Exposes Customer Data | The Hacker News | June 2026 | Corroborating security-media coverage of third-party OAuth risk and downstream customer exposure in the Klue/Salesforce incident. |
| 10 | Klue Salesforce data breach impacts many downstream customers | Help Net Security | June 19, 2026 | Corroborating public reporting on downstream organizations and the broader Salesforce integration exposure narrative. |
| 11 | Klue Breach Impact on Jamf | Jamf Trust Center | June 2026 | Downstream customer signal used to show that Klue customers beyond LastPass published their own impact assessments. |
| 12 | Klue Security Incident | Sprout Social Trust Center | June 2026 | Downstream customer trust-center signal used to show notification and impact-scoping patterns among Klue customers. |
| 13 | Connected App Overview | Salesforce Help | Living documentation | Authoritative platform documentation for connected apps and OAuth-style trust relationships in Salesforce environments. |
| 14 | T1199 - Trusted Relationship | MITRE ATT&CK | Living framework | Framework mapping for adversary use of third-party trust relationships to reach a target environment. |
| 15 | T1528 - Steal Application Access Token | MITRE ATT&CK | Living framework | Framework mapping for stealing or abusing application access tokens. |
| 16 | T1078 - Valid Accounts | MITRE ATT&CK | Living framework | Framework mapping for continued access through valid account or service-account style authentication. |
| 17 | T1567.002 - Exfiltration to Cloud Storage | MITRE ATT&CK | Living framework | Framework-adjacent exfiltration mapping for cloud/API-mediated data movement where supported by local Salesforce telemetry. |
| 25 | EventLogFile | Object Reference for the Salesforce Platform | Salesforce Developers | Living documentation | Official Salesforce developer documentation for EventLogFile, the object used to access event monitoring data for Salesforce operational and security investigations. |
| 26 | EventLogFile Supported Event Types | Salesforce Developers | Living documentation | Official Salesforce reference for event types such as REST API, API Total Usage, Bulk API, Login, Report, Report Export, Permission Update, and related forensic event categories. |
| 27 | Monitor Setup Changes with Setup Audit Trail | Salesforce Help | Living documentation | Official Salesforce guidance for Setup Audit Trail, used to investigate administrative, connected-app, permission, and configuration changes during a Salesforce incident. |
| 28 | Monitor Login History | Salesforce Help | Living documentation | Official Salesforce guidance for reviewing login history, including who logged in, when, and from where. |
| 29 | T1119 - Automated Collection | MITRE ATT&CK | Living framework | Framework mapping for automated collection behavior, used where Salesforce API query volume and object enumeration support collection activity. |
| 30 | Klue Supply Chain Incident & LastPass Response | LastPass | June 22, 2026 | Newly retained (>24h) primary downstream-customer response clarifying LastPass's Salesforce and Gong integration context, OAuth-token exposure, impacted data categories, token rotation, discontinued Klue access, law-enforcement cooperation, customer anti-phishing guidance, published IOCs, and product/vault boundary. |
| 31 | Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats | TechCrunch | June 25, 2026 | Freshly reported (<24h) update that Klue said the original criminals were deleting stolen customer data while a second group was making threats, changing the extortion and customer-communications posture. |
| 32 | BeyondTrust, LastPass Impacted by Klue-Salesforce Incident | SecurityWeek | June 24, 2026 | Newly retained (>24h) reporting that over a dozen Klue customers had confirmed Salesforce-instance data theft and that BeyondTrust and LastPass were among impacted organizations. |
| 33 | When a vendor's breach becomes yours: lessons from the Klue incident | Snyk | June 23, 2026 | Newly retained (>24h) downstream-customer disclosure describing Salesforce business data impact and support-case title/description boundaries. |
| 34 | Security Advisory: HackerOne's Response to the Klue Breach | HackerOne | June 2026 | Newly retained (>24h) downstream-customer advisory describing Klue disconnection, Salesforce access disablement, credential/log review, and isolation of exposure to Salesforce. |
| 35 | Klue Security Incident | BeyondTrust | June 2026 | Newly retained (>24h) downstream-customer notice confirming Klue as a competitive intelligence vendor integrated with BeyondTrust's Salesforce CRM and describing access to business contact and general sales-related customer information. |
| 36 | More Klue Breach Victims Identified as Hackers Get Hacked | SecurityWeek | June 26, 2026, 11:01 AM ET | Freshly reported (<24h) follow-up naming additional public customer-notice examples, reporting roughly two dozen confirmed Klue-Salesforce impact disclosures, preserving Salesforce/Gong disablement context, and caveating second-actor possession claims. |
| 37 | Technical Analysis of the Klue Attack: OAuth Abuse, Stale Integrations, and Salesforce Exfiltration | Obsidian Security | June 25, 2026 | Newly retained (>24h) technical analysis across impacted organizations, adding Global Describe reconnaissance, QueryMore pagination, API-version downgrade, user-agent deviation, source-infrastructure deviation, object-harvest scope, and Icarus/UNC6395 deconfliction. |
| 38 | Security update: Klue breach and impact on Pendo | Pendo | June 22, 2026 | Newly retained (>24h) direct customer disclosure confirming Pendo Salesforce CRM access through Klue, affected business/contact data, product-platform boundary, response steps, and anti-phishing guidance. |
| 39 | The Klue Security Incident and Its Impact on Recorded Future | Recorded Future | Publication date not visible | Newly retained (publication date not visible) direct customer disclosure confirming Recorded Future Salesforce impact through a Klue OAuth token while preserving its core platform, Intelligence Graph, and infrastructure boundary. |
| 40 | Form 8-K for 8x8 Inc. filed 06/23/2026 | 8x8 | June 23, 2026 | Newly retained (>24h) regulatory disclosure confirming unauthorized access to 8x8 Salesforce through the Klue integration, June 11-12 access, customer/prospect commercial and contact data categories, containment, and operational-impact boundary. |
| 41 | Security Advisory: Third-Party Security Incident Involving Klue | LogicMonitor | June 26, 2026 | Newly retained (>24h); retrieved 27-Jun-2026 9:33 PM ET. Direct customer disclosure confirming unauthorized access to the Catchpoint Salesforce environment through Klue, while preserving the boundary that LogicMonitor's primary Salesforce environment and production/monitoring systems were not impacted. |
| 42 | Tines Trust Center - Klue Incident Notice | Tines Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 27-Jun-2026 9:33 PM ET. Direct customer trust-center notice stating Tines was notified that Klue credentials were used to access Salesforce data and that Tines found no evidence of unauthorized access to the Tines platform or customer environments. |
| 43 | Security Update: Tanium's Response to the Klue Breach that Allowed Data Exfiltration from Salesforce | Tanium | June 18, 2026 | Newly retained (>24h); retrieved 27-Jun-2026 9:33 PM ET. Direct customer disclosure describing Tanium Salesforce CRM data exfiltration through Klue and preserving the boundary that Tanium products and cloud infrastructure were not impacted. |
| 44 | Update From OneTrust on Klue Security Incident | OneTrust | June 24, 2026; updated July 10, 2026 | Newly retained (>24h); retrieved 28-Jun-2026 9:31 PM ET; July 10 update retrieved 11-Jul-2026 9:31 PM ET. Direct customer disclosure confirming Klue Battlecards/Salesforce CRM-related data exposure, June 11-12 activity, Salesforce API/log review, disabled Klue integration, no evidence of passwords, payment cards, customer tenant data, or customer-managed OneTrust environment exposure, and July 10 investigation completion with no evidence of exposure beyond OneTrust's Salesforce environment. |
| 45 | Klue Security Incident | Gong | June 19, 2026 | Newly retained (>24h); retrieved 28-Jun-2026 9:31 PM ET. Direct platform-provider disclosure stating the incident originated with Klue, affected customers were those who connected Klue with Gong, a subset may have had licensed-user business data accessed, and Gong found no direct impact to call recordings or customer transcripts. |
| 46 | Notification of Salesforce / Klue Security Incident | Insurity Status | June 18, 2026; updated June 22, 2026 | Newly retained (>24h); retrieved 28-Jun-2026 9:31 PM ET. Direct customer status notice confirming Salesforce notified Insurity of suspicious activity involving its Klue connected application, later identifying a very limited set of active credentials in exposed CRM data, rotating or resetting those secrets, and stating Insurity products were not involved. |
| 47 | Third-Party Security Incident - Klue-Salesforce Integration | AudienceView Status | June 29, 2026; initial monitoring June 22, 2026 | Freshly reported (<24h) status resolution; retrieved 29-Jun-2026 9:31 PM ET. Direct customer status notice confirming AudienceView impact through the Klue-Salesforce integration while preserving product, production-system, internal-system, and patron-data boundaries. |
| 48 | Security Incident at Third-Party Provider Klue: Certain Link11 CRM Data Affected | Link11 | June 25, 2026 | Newly retained (>24h); retrieved 29-Jun-2026 9:31 PM ET. Direct customer disclosure confirming Link11 used a Klue OAuth-based Salesforce CRM integration and that certain business contact and sales-related CRM data was affected. |
| 49 | AlertMedia Trust Center - Klue Incident Update | AlertMedia Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 29-Jun-2026 9:31 PM ET. Direct trust-center notice stating AlertMedia disabled Klue, revoked access, rotated third-party Salesforce integration credentials, and found no AlertMedia platform customer data or product-supporting systems impact. |
| 50 | Klue/Salesforce Security Breach - Investigation Update | Camunda Trust Center | July 1, 2026, 6:00 PM ET | Newly retained (>24h); retrieved 02-Jul-2026 9:31 PM ET. Direct trust-center update revising Camunda's Klue/Salesforce impact boundary: exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. |
| 51 | Cresta Trust Center - Klue Incident Update | Cresta Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 29-Jun-2026 9:31 PM ET. Direct trust-center notice confirming Cresta's Salesforce instance was impacted, possible exposure of business contact information, contractual information, and email correspondence, and no indication of Cresta product or infrastructure impact. |
| 52 | Lucanet Trust Center - Klue Incident Notice | Lucanet Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 29-Jun-2026 9:31 PM ET. Direct trust-center notice stating Lucanet's internally used Klue competitive-intelligence tool was affected, supporting Lucanet as a direct customer disclosure without expanding the impact beyond that notice. |
| 53 | Cybersecurity Alert: Klue OAuth Breach and Salesforce Data Exfiltration | FINRA | June 26, 2026 | Newly retained (>24h); retrieved 29-Jun-2026 9:31 PM ET. Sector-facing guidance naming Icarus, OAuth-token theft across Salesforce and other SaaS integrations, additional affected organizations, suspicious IPs and sender domains, and member-firm mitigation priorities. |
| 54 | ZeroFox Intelligence Profile - ICARUS | ZeroFox | June 26, 2026 | Newly retained (>24h); retrieved 29-Jun-2026 9:31 PM ET. Actor profile assessing ICARUS as a financially motivated extortion group active since late April or early May 2026, adding the Underground Uwu/SLH caveat, operational-maturity assessment, and Klue-linked victimology and IOCs. |
| 55 | Klue Third-Party Cybersecurity Incident | ControlUp | June 26, 2026 | Newly retained (>24h); retrieved 30-Jun-2026 9:31 PM ET. Direct customer disclosure confirming unauthorized access to certain ControlUp Salesforce business data through Klue's integration while preserving boundaries for ControlUp solutions, production environment, and infrastructure. |
| 56 | Klue security incident - Deel impact | Deel | June 25, 2026; last update June 26, 2026 | Newly retained (>24h); retrieved 30-Jun-2026 9:31 PM ET. Direct customer disclosure confirming unauthorized access to a portion of public, business-contact, and commercial information in Deel's CRM environment while excluding the Deel platform itself. |
| 57 | Security Update - Klue Third-Party Cybersecurity Incident | Saviynt Trust Portal | June 23, 2026 | Newly retained (>24h); retrieved 30-Jun-2026 9:31 PM ET. Direct trust-portal notice stating Saviynt was one of the impacted customers, potential impact was limited to certain sales data in Salesforce, and Saviynt products, services, and product customer data were not impacted. |
| 58 | A message to our customers about the Klue security incident | ABBYY Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 30-Jun-2026 9:31 PM ET. Direct trust-center notice stating Salesforce data accessed through Klue's integration was affected while ABBYY's network, products, and technology were not affected. |
| 59 | CrowdStrike Investigation Summary and Security Improvements | Klue | July 2, 2026, 12:02 AM ET (page byline July 1, 2026) | Freshly reported (<24h); retrieved 02-Jul-2026 9:31 PM ET. Primary Klue/CrowdStrike investigation summary stating a previously compromised GitHub personal access token introduced unauthorized code into Klue's integration service, collected third-party integration credentials including Salesforce OAuth access and refresh tokens, and adding containment, scope, monitoring, and CI/CD hardening details. |
| 60 | Notice of Security Incident | Postman Security & Trust Portal | Publication date not visible; incident confirmation dated June 17, 2026 | Newly retained (publication date not visible); retrieved 04-Jul-2026 9:31 PM ET. Direct trust-portal notice confirming Postman customer contact and sales information was exfiltrated from Salesforce via the compromised Klue service account between June 11-12, while customer data was not accessed from Gong and Postman's core platform services were not impacted. |
| 61 | Klue Security Incident | Automox Trust Center | June 29, 2026 | Newly retained (>24h); retrieved 05-Jul-2026 9:31 PM ET. Direct trust-center notice stating Automox used Klue with Salesforce, reviewed internal logs and Salesforce Login History/Connected App OAuth usage, found no anomalous or malicious activity, and says Klue confirmed it had no indication Automox data or customer data was affected. |
| 62 | Responding to the Klue Incident: Practical Steps to Audit and Harden Your Integrations | eSentire | June 26, 2026 | Newly retained (>24h); retrieved 07-Jul-2026 9:32 PM ET. Direct customer disclosure stating eSentire uses Klue, was among organizations whose Salesforce data was accessed, characterizes its exposure as minimal, and excludes customer-service risk, customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. |
| 63 | Klue Breach that Allowed Data Exfiltration from Salesforce | Thinkproject Status | June 26, 2026, 6:47 AM | Newly retained (>24h); retrieved 08-Jul-2026 9:32 PM ET. Direct customer status notice stating Klue had authorized access to Thinkproject's UAT CRM environment through a software integration, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. |
| 64 | Third-Party Vendor Security Incident (Klue) | Snyk Status | July 8, 2026, 11:26 AM ET | Newly retained (>24h); retrieved 09-Jul-2026 9:31 PM ET. Official Snyk status resolution stating its Mandiant-assisted forensic investigation into the Klue/Salesforce incident is complete, impact was limited to business CRM data, and no Snyk platform or sensitive platform data impact was found. |
| 65 | SentinelOne Confirms Klue Supply Chain Incident Contained to Salesforce | Secure ISS | July 9, 2026 | Freshly reported (<24h); retrieved 09-Jul-2026 9:31 PM ET. Public advisory relaying SentinelOne's partner notification that the Klue impact was contained to SentinelOne's Salesforce environment through the Klue API integration, with no lateral movement, core-product, cloud-infrastructure, or production-environment impact reported; data analysis remains ongoing. |
| 66 | Defending SaaS-based applications against ShinyHunters OAuth abuse | Microsoft Security Research / Microsoft Defender Security Research Team | July 13, 2026 | Freshly reported (<24h); retrieved 13-Jul-2026 9:31 PM ET. Microsoft research grouping mid-2025 to mid-2026 Salesforce/SaaS OAuth abuse tradecraft commonly associated with ShinyHunters, while including a Klue integration IP used for Salesforce API CRM queries on June 11 and reinforcing that trusted OAuth relationships, not a Salesforce platform vulnerability, drove the risk. |
| 67 | Security Update: Klue Security Incident | Sisense Trust Center | Publication date not visible | Newly retained (publication date not visible); retrieved 14-Jul-2026 9:32 PM ET. Direct trust-center notice stating Sisense was one of many affected organizations, limiting the incident to certain business and sales-related data in Sisense's Salesforce CRM application, excluding Sisense product-platform data, and noting credential/token rotation and access-log monitoring. |
| 68 | Klue Supply Chain Compromise: Qualtrics Response | Qualtrics XM Trust Center | June 25, 2026, 12:55 UTC | Newly retained (>24h); retrieved 16-Jul-2026 9:32 PM ET. Direct trust-center notice stating Klue connected to Salesforce for Qualtrics internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised. |
| 69 | Security Update Regarding Third-Party Klue Incident | Splashtop | Updated June 30, 2026 | Newly retained (>24h); retrieved 16-Jul-2026 9:32 PM ET. Direct customer update stating Klue's environment was compromised, OAuth tokens were used to access certain Salesforce data, Splashtop disabled the Klue Salesforce integration and revoked access, investigation remained ongoing, and Splashtop products, services, and customer-support ability were not impacted. |
Expansion Research Sources
These sources add the Salesloft Drift comparator: a prior Salesforce OAuth supply-chain campaign where a trusted SaaS integration and stolen OAuth tokens created downstream Salesforce exposure. AI Monitoring Agent additions are retained in the baseline set when they directly update the Klue event, customer notices, follow-on extortion posture, or Salesforce response guidance.
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 18 | Widespread Data Theft Targets Salesforce Instances via Salesloft Drift | Google Cloud / GTIG | August 26, 2025 | Expansion research comparator: authoritative threat-intelligence reporting on UNC6395, compromised Salesloft Drift OAuth tokens, Salesforce data theft, Drift Email scope expansion, and token/credential response actions. |
| 19 | Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks | BleepingComputer | August 26, 2025 | Expansion research comparator explaining Salesloft Drift, why OAuth/refresh tokens created downstream Salesforce exposure, and how the earlier Drift incident resembles the Klue supply-chain pattern. |
| 20 | Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens | Arctic Wolf | August 27, 2025 | Expansion research on Drift/Salesforce campaign details, no-Salesforce-platform-compromise caveat, impacted-customer outreach, and reauthentication guidance. |
| 21 | Threat Brief: Salesloft Drift Integration Used To Compromise Salesforce Instances | Unit 42 | September 2, 2025 | Expansion research on mass Salesforce data exfiltration, affected objects, credential/secret hunting, anti-forensics through query-job deletion, and hunting guidance. |
| 22 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Platforms | FBI / IC3 | September 12, 2025 | Government expansion source tying UNC6395 to compromised Salesloft Drift OAuth tokens, Salesforce data theft, extortion risk, and public indicators/tactics. |
| 23 | Drift App (Salesloft) Unauthorized Access Incident | Salesforce Help | May 4, 2026 | Official Salesforce reference for the Drift app unauthorized-access incident, used to separate the May 2026 publication/update date from the August 2025 campaign window. |
| 24 | Cybersecurity Alert - Salesloft Drift AI Supply Chain Attack | FINRA | September 2025 | Sector-facing expansion source explaining more than 700 impacted organizations, UNC6395/GRUB1 attribution, stolen OAuth authentication tokens, and downstream Salesforce/Google Workspace/Slack implications. |
30-Version Change Log
| Version | Date | Changes |
|---|---|---|
| v1.0 | June 23, 2026 | Initial static Klue Flash Threat Intel Brief covering Klue, LastPass downstream impact, Salesforce OAuth/token framing, and Salesloft Drift expansion research. |
| v1.1 | June 24, 2026 | Added deeper battlecard and competitive-enablement definitions, Salesforce forensic logging guidance, MITRE lifecycle remap, quoted talking points, Salesloft reciprocal link, and versioned change log. |
| v1.2 | June 26, 2026 | Created the Klue AI Monitoring Agent, added dated delta badge/legend support, and incorporated bootstrap monitor deltas: TechCrunch follow-on extortion reporting (Freshly reported (<24h)), plus newly retained LastPass, SecurityWeek, Snyk, HackerOne, and BeyondTrust sources (Newly retained (>24h)). Updated executive summary, AI Agent Delta Updates, timeline, IOCs/observables, source coverage, source summary, source deconfliction, real-world examples, citations, and PANDA index dates. |
| v1.3 | June 26, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed deltas: SecurityWeek's 26-Jun-2026 11:01 AM ET follow-up (Freshly reported (<24h)) expanded the public disclosure set to roughly two dozen customer notices; Obsidian, Pendo, and 8x8 were newly retained (Newly retained (>24h)); Recorded Future was Newly retained (publication date not visible). Added Salesforce forensic refinements for Global Describe, QueryMore, API-version/user-agent deviation, additional public-victim examples, and Icarus/UNC6395 deconfliction. No reliable source merged Klue with UNC6395/Salesloft Drift. |
| v1.4 | June 27, 2026, 9:33 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Added LogicMonitor/Catchpoint and Tanium as Newly retained (>24h), added Tines Trust Center as Newly retained (publication date not visible), and updated Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Source Summary, Source Deconfliction, Citations, and related PANDA index entries. Public victim/disclosure search found additional direct customer notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. |
| v1.5 | June 28, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer and connected-platform disclosure deltas. Added OneTrust, Gong, and Insurity as Newly retained (>24h), with retrieval timestamp 28-Jun-2026 9:31 PM ET. Updated Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. |
| v1.6 | June 29, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure, sector-guidance, and actor-context deltas. Freshly reported (<24h): AudienceView status-page resolution timestamp, with older initial monitoring context preserved. Newly retained (>24h): Link11, FINRA, and ZeroFox. Newly retained (publication date not visible): AlertMedia, Camunda, Cresta, and Lucanet trust-center notices. Updated Executive Summary, AI Agent Delta Updates, Timeline, Incident Response Playbook Ideas, Salesforce forensics guidance, IOCs/Observables, Threat Actor Glossary, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Citations, and related PANDA index entries. Public victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search reinforced Icarus/ICARUS and Underground Uwu/SLH caveats; no reliable source merged Klue with UNC6395/Salesloft Drift. |
| v1.7 | June 30, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Newly retained (>24h): ControlUp, Deel, and Saviynt. Newly retained (publication date not visible): ABBYY Trust Center. Updated Executive Summary, AI Agent Delta Updates, Timeline, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Citations, and related PANDA index entries. Public victim/disclosure search found additional direct notices. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. |
| v1.7 | July 1, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, previously retained direct notices, leak-site-only claims, aggregator pages, LinkedIn/social posts, and unsupported UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 1, 2026. |
| v1.8 | July 2, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed primary mechanism, containment, and customer-boundary deltas. Freshly reported (<24h): Klue CrowdStrike Investigation Summary and Security Improvements, schema published 02-Jul-2026 12:02 AM ET with a visible 01-Jul-2026 byline, adding the compromised GitHub PAT, unauthorized integration-service code, Salesforce OAuth access/refresh token collection, affected GKE pod containment, no identified access outside integration-service-related systems, no activity after June 12, CrowdStrike Falcon monitoring, and CI/CD/security hardening. Newly retained (>24h): Camunda Trust Center 01-Jul-2026 6:00 PM ET update narrowing Camunda's support-data boundary to standard business-contact and account information in Salesforce CRM. Updated Executive Summary, BLUF, Timeline, Incident Response Playbook Ideas, Salesforce forensics guidance, MITRE ATT&CK mapping, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found a Camunda boundary revision but no new named public victim row. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. |
| v1.9 | July 4, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (publication date not visible): Postman Security & Trust Portal Notice of Security Incident, retrieved 04-Jul-2026 9:31 PM ET, confirming Salesforce customer contact and sales-information exfiltration via the compromised Klue service account between June 11-12, while stating customer data was not accessed from Gong and Postman's core platform services remained secure and were not impacted. Updated Executive Summary, BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public-victim/disclosure search found Postman's direct notice. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) source was retained. PANDA index date updated to Updated Jul 4, 2026. |
| v1.10 | July 5, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed no-impact/deconfliction delta. Newly retained (>24h): Automox Trust Center Klue Security Incident, published 29-Jun-2026 and retrieved 05-Jul-2026 9:31 PM ET, stating Automox used Klue with Salesforce, reviewed internal logs and Salesforce Login History/Connected App OAuth usage, found no anomalous or malicious Salesforce activity, and said Klue had no indication Automox data or customer data was affected. Updated BLUF, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found Automox's direct no-impact notice and rejected NetDocuments search-index-only text, duplicative SEO rewrites, social posts, leak-site-only claims, and unsupported speculation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date updated to Updated Jul 5, 2026. |
| v1.10 | July 6, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, previously retained direct notices, leak-site-only claims, social posts, source-index/status aggregators, and unsupported UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 6, 2026. |
| v1.11 | July 7, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (>24h): eSentire Responding to the Klue Incident, published 26-Jun-2026 and retrieved 07-Jul-2026 9:32 PM ET, stating eSentire uses Klue, was among organizations whose Salesforce data was accessed, characterized exposure as minimal due to restricted OAuth permissions and a limited connected-app footprint, identified no customer-service risk, and excluded customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public-victim/disclosure search found eSentire's direct notice and rejected NetDocuments sparse/search-index-only text, generic OAuth/Salesforce recaps, social posts, leak-site-only claims, and duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date remained Updated Jul 7, 2026. |
| v1.12 | July 8, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (>24h): Thinkproject Status Klue Breach that Allowed Data Exfiltration from Salesforce, published 26-Jun-2026 6:47 AM and retrieved 08-Jul-2026 9:32 PM ET, stating Klue had authorized access to Thinkproject's UAT CRM environment through a software integration, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found Thinkproject's direct notice and rejected duplicative summaries, generic Salesforce OAuth recaps, social posts, leak-site-only claims, sparse status aggregators, and duplicate media rewrites. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date updated to Updated Jul 8, 2026. |
| v1.13 | July 9, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated source-backed customer-boundary deltas. Newly retained (>24h): Snyk Status Third-Party Vendor Security Incident (Klue), resolved 08-Jul-2026 11:26 AM ET and retrieved 09-Jul-2026 9:31 PM ET, stating Snyk's Mandiant-assisted Klue/Salesforce forensic investigation is complete, impact was limited to business CRM data, and no Snyk platform or sensitive platform-data impact was found. Freshly reported (<24h): Secure ISS SentinelOne Klue advisory, published 09-Jul-2026 and retrieved 09-Jul-2026 9:31 PM ET, relaying a SentinelOne partner-notification boundary that impact was contained to Salesforce through the Klue API integration, with no lateral movement and no core-product, cloud-infrastructure, or production-environment impact reported; data analysis remains ongoing and the direct SentinelOne portal reference is access-controlled. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, related PANDA index entries, and the AI Monitoring Agent directory. Public-victim/disclosure search found Snyk's status resolution and a qualified SentinelOne public advisory/partner-notification lead; NetDocuments JavaScript-only/search-index text, duplicative SEO recaps, generic OAuth commentary, leak-site-only claims, and unsupported Salesforce/OAuth attribution rewrites were not promoted. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Newly retained (publication date not visible) source was retained. PANDA index date updated to Updated Jul 9, 2026. |
| v1.13 | July 10, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, access-controlled portal references, JavaScript-only trust-center app shells, and unsupported UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. NetDocuments remained JavaScript-only/search-index text without a stable inspectable disclosure body. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 10, 2026. |
| v1.14 | July 11, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed customer-boundary delta. Newly retained (>24h): OneTrust Update From OneTrust on Klue Security Incident, updated 10-Jul-2026 and retrieved 11-Jul-2026 9:31 PM ET, stating OneTrust's technical investigation, scope validation, containment, and remediation are complete and that the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment while governance, compliance, and notification review continue. Updated BLUF, Timeline, Executive Summary, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index review status. Public-victim/disclosure search found OneTrust's direct investigation-complete update and rejected duplicate media recaps, social posts, leak-site-only claims, generic OAuth/Salesforce commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. PANDA index date remained Updated Jul 11, 2026. |
| v1.14 | July 12, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, access-controlled portal references, JavaScript-only trust-center app shells, and unsupported Icarus/UNC6395/Salesloft Drift conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 12, 2026. |
| v1.15 | July 13, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed campaign/activity-cluster deconfliction delta. Freshly reported (<24h): Microsoft Security Research / Microsoft Defender Security Research Team, published 13-Jul-2026 and retrieved 13-Jul-2026 9:31 PM ET, placing Klue-related Salesforce/SaaS OAuth abuse inside broader ShinyHunters-associated tradecraft context, adding connected-app visibility guidance, MITRE T1671 mapping, and Microsoft Klue IOC enrichment. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Incident Response Playbook Ideas, Salesforce forensics guidance, IOCs/Observables, Threat Actor Glossary, Talking Points, Decision Ready Actions, Real World Examples, MITRE ATT&CK Lifecycle Mapping, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found no new reliable named public organization notice requiring a victim/disclosure row. Associated-campaign/activity-cluster search found Microsoft ShinyHunters-associated OAuth-abuse research that improves deconfliction but does not merge Klue/Icarus with UNC6395 or Salesloft Drift. Freshness labels applied to retained sources: Freshly reported (<24h). PANDA index date updated to Updated Jul 13, 2026. |
| v1.16 | July 14, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated a source-backed direct customer-disclosure delta. Newly retained (publication date not visible): Sisense Trust Center Security Update: Klue Security Incident, retrieved 14-Jul-2026 9:32 PM ET, stating Sisense was one of many affected organizations, limiting impact to certain business and sales-related data in Sisense's Salesforce CRM application, excluding Sisense product-platform and product-platform data impact, and noting credential/token rotation and access-log monitoring. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, and related PANDA index entries. Public-victim/disclosure search found Sisense's direct trust-center notice and rejected duplicate media recaps, SEO rewrites, leak-site-only claims, JavaScript-only NetDocuments text, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (>24h) source was retained. PANDA index date updated to Updated Jul 14, 2026. |
| v1.16 | July 15, 2026, 9:31 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, secondary rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, JavaScript-only trust-center app shells, unavailable trust-center bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. Microsoft ShinyHunters OAuth coverage remained represented by the existing Microsoft source and did not create a new delta. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 15, 2026. |
| v1.17 | July 16, 2026, 9:32 PM ET | AI Monitoring Agent found and incorporated source-backed direct customer-disclosure deltas. Newly retained (>24h): Qualtrics XM Trust Center Klue Supply Chain Compromise response, published 25-Jun-2026 12:55 UTC and retrieved 16-Jul-2026 9:32 PM ET, stating Klue connected to Salesforce for internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised; Splashtop Security Update Regarding Third-Party Klue Incident, updated 30-Jun-2026 and retrieved 16-Jul-2026 9:32 PM ET, stating Klue OAuth tokens were used to access certain Salesforce data, Splashtop disabled the Klue Salesforce integration and revoked access, Splashtop products/services were not impacted, and investigation remained ongoing. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Real World Examples, Public Victims / Disclosure Matrix, Source Summary, Source Deconfliction, Source Weighting, Citations, Contributors, and related PANDA index entries. Public-victim/disclosure search found Qualtrics and Splashtop direct notices and rejected duplicate media recaps, VenariX aggregated victim tracking, NetDocuments and Commvault JavaScript-only trust-center shells without stable inspectable bodies, leak-site-only claims, generic Salesforce/OAuth commentary, and unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, or Klue/Salesloft Drift activity-cluster revision. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained sources: Newly retained (>24h). PANDA index date updated to Updated Jul 16, 2026. |
| v1.18 | July 18, 2026, 9:31 PM ET | AI Monitoring Agent found and incorporated a source-backed campaign/activity-label clarification from the already retained Microsoft Security Research / Microsoft Defender Security Research Team July 13 source. Newly retained (>24h): Microsoft's Storm-3138 label for the Klue system-access path, re-reviewed 18-Jul-2026 9:31 PM ET. Updated BLUF, Executive Summary, Timeline, AI Agent Delta Updates, Threat Actor Glossary, Common Questions Q&A, Decision Ready Actions, Real World Examples, Source Summary, Source Deconfliction, Source Weighting, Contributors, and related PANDA index entries. Public-victim/disclosure search found no new reliable public organization notice that changed the victim matrix and did not promote Commvault's JavaScript-only trust-center shell, duplicate media recaps, generic OAuth commentary, leak-site-only claims, or unsupported Klue/Salesloft Drift conflation. Associated-campaign/activity-cluster search promoted Storm-3138 as Microsoft's Klue system-access activity label while preserving Icarus/ICARUS as the Klue-specific public extortion/operator label and keeping UNC6395/Salesloft Drift as comparator context. No Freshly reported (<24h) or Newly retained (publication date not visible) source was retained. Freshness labels applied to retained source-backed clarification: Newly retained (>24h). PANDA index date updated to Updated Jul 18, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.18 | July 19, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, JavaScript-only trust-center shells, source-index snippets without stable public bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Commvault remained a JavaScript-only Vanta trust-center shell without a stable inspectable disclosure body, and Insurity's July 9 status update remained represented by the retained Insurity citation without changing the analysis. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 19, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
| v1.18 | July 20, 2026, 9:32 PM ET | AI Monitoring Agent checked public sources; no source-backed content update identified. No version increment; no findings added, modified, subtracted, or newly qualified. Duplicate reporting, recrawled summaries, SEO rewrites, generic Salesforce/OAuth commentary, leak-site-only claims, social posts, JavaScript-only trust-center shells, source-index snippets without stable public bodies, and unsupported Icarus/UNC6395/Salesloft Drift/ShinyHunters conflation were not promoted. Public-victim/disclosure search found no new reliable public organization notice that changed the brief; Sprout Social, Jamf, LastPass, Huntress, Tanium, Recorded Future, Insurity, and other retained notices remained represented by existing citations and boundaries. Associated-campaign/activity-cluster search found no new reliable campaign, actor alias, Icarus/UNC6395 connection, Storm-3138 revision, ShinyHunters clarification, or Klue/Salesloft Drift activity-cluster revision. Freshness labels applied to retained sources: none. PANDA index date updated to Updated Jul 20, 2026. Email/external notification intentionally not sent per the automation's non-negotiable no-email policy. |
