IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Klue

Supply Chain Attack

SalesforceCRM integrationOAuth exposure
Published
23-Jun-2026
Brief Version
v1.18
Updated
22x via AI Monitoring Agents
Next AI Monitor
Daily at 1:30 AM ET for 12 months
Brief ID
PANDA-FTIB-KLUE-2026-001
Template
Flash Threat Brief Template v2.0

Research Framing

Klue Exposure Snapshot

1-Topic

Klue is a competitive enablement and market-intelligence SaaS platform whose Salesforce integration can sit close to customer and prospect CRM records. The public incident is best framed as a trusted SaaS integration and OAuth-token exposure path, not as a confirmed Salesforce platform vulnerability. 1,2,5,6

The operational question for downstream customers is whether Klue or Klue Battlecards had token-backed access into their Salesforce environment, which objects were reachable, and whether Salesforce API activity indicates customer, prospect, support, or commercial data access. 3,5,6,7,30

Public customer notices now make this a concrete disclosure-pattern issue as well as a technical one: responders should preserve Salesforce logs, revoke and rotate integration tokens, scope CRM objects, and keep product-system compromise language separate from Salesforce business-data exposure. 11,12,32,33,34,35,38,39,40,41,42,43

2-Persona / Audience Lens

3-BLUF

  • Klue is a competitive enablement SaaS provider with Salesforce integration paths; the incident matters because attackers can abuse that trusted integration relationship to reach downstream customer CRM data. 1,5,6
  • LastPass publicly confirmed a Klue-linked customer-data incident while stating its product systems, services, infrastructure, and vaults were not compromised. 3,4,30
  • The strongest technical framing is OAuth/connected-app abuse: compromised Klue integration access produced token-backed Salesforce API activity, not a Salesforce core-platform exploit. 1,2,5,6
  • Responder priority is to revoke and rotate Klue/Salesforce integration tokens and credentials, preserve Salesforce logs, scope CRM data queried or exported, and notify legal/privacy teams where customer or prospect data was accessed. 1,5,6,7
  • 29-Jun-2026 · Newly retained (>24h) Icarus remains the public actor label tied to the Klue extortion/data-theft activity in this source set. FINRA and ZeroFox reinforce Icarus/ICARUS naming and mitigation priorities, while ZeroFox also notes Underground Uwu / Scattered Lapsus$ Hunters claims that remain caveated. No reliable source merged Klue with UNC6395/Salesloft Drift. 5,6,36,37,53,54
  • 30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Salesforce/CRM sales or business data exposure. 30-Jun-2026 · Newly retained; undatedABBYY adds an undated trust-center boundary. These sources expand public victimology but do not change the Salesforce platform-vulnerability boundary or actor attribution. 55,56,57,58
  • 02-Jul-2026 · Freshly reported (<24h) Klue's primary CrowdStrike update revises the mechanism from generic legacy-credential compromise to a GitHub PAT (personal access token) and unauthorized integration-service code path, while stating CrowdStrike found no evidence of threat-actor access outside integration-service-related systems or activity after June 12. 59
  • 04-Jul-2026 · Newly retained; undated Postman adds a direct public customer-disclosure boundary: Salesforce customer contact and sales information was exfiltrated via the compromised Klue service account, customer data was not accessed from Gong, and Postman core platform services were not impacted. 60
  • 05-Jul-2026 · Newly retained (>24h) Automox adds a useful no-impact disclosure boundary: after Klue/Salesforce review, it reported no anomalous or malicious Salesforce activity and said Klue had no indication Automox data or customer data was affected. Treat this as leak-list deconfliction, not a confirmed data-theft victim row. 61
  • 07-Jul-2026 · Newly retained (>24h) eSentire adds a narrow direct customer-disclosure boundary: Salesforce data was accessed through Klue, exposure was described as minimal due to restricted OAuth permissions and a limited connected-app footprint, and eSentire reported no identified customer-service risk from the incident. 62
  • 08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific customer-disclosure boundary: the Klue-linked access involved Salesforce/CRM business-contact and commercial information, while Thinkproject states its products and services were not affected and its CRM system is separate from the customer product platform. 63
  • 09-Jul-2026 · Newly retained (>24h) Snyk now closes its Klue/Salesforce status incident after a Mandiant-assisted forensic investigation, preserving a business-CRM-data-only boundary. 09-Jul-2026 · Freshly reported (<24h) Secure ISS relays a SentinelOne partner-notification boundary: Salesforce-environment-only impact through the Klue API integration, no lateral movement, and no core-product, cloud-infrastructure, or production-environment impact reported. 64,65
  • 11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation and narrows the public boundary: containment and remediation are complete, and the independent forensic investigation found no evidence of exposure beyond OneTrust's Salesforce environment. Governance, compliance, and notification review remain ongoing. 44
  • 13-Jul-2026 · Freshly reported (<24h) Microsoft places Klue in a broader Salesforce/SaaS OAuth-abuse tradecraft discussion associated with ShinyHunters. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system access path; preserve Icarus/ICARUS as the Klue-specific public extortion/operator label unless stronger evidence merges or replaces that attribution. 66
  • 14-Jul-2026 · Newly retained; undated Sisense adds another direct public customer-disclosure boundary: Sisense says the Klue incident was limited to certain business and sales-related data in its Salesforce CRM application and did not impact the Sisense product platform or product-platform data. 67
  • 16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add older direct public customer-disclosure boundaries: both tie Klue to Salesforce access and preserve product/platform exclusions, while Splashtop notes its investigation remained ongoing. 68,69

4-Executive Summary

Klue is a competitive enablement and market-intelligence SaaS platform used by sales teams to synchronize battlecards, win/loss context, and competitive intelligence with CRM workflows. That business role matters: a Klue integration can sit close to sensitive Salesforce data such as accounts, contacts, leads, opportunities, notes, and customer relationship context. Public reporting and Klue's own statement describe unauthorized activity affecting part of Klue's integration infrastructure, with a compromised legacy integration credential used to obtain OAuth tokens that connected Klue to Salesforce. 02-Jul-2026 · Freshly reported (<24h) Klue's later CrowdStrike summary refines that mechanism: a previously compromised GitHub PAT was used to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens. 1,5,6,59

This is a supply-chain attack because downstream customers may be exposed through a trusted third-party application rather than through a direct compromise of their own infrastructure first. LastPass publicly confirmed a Klue-linked customer-data incident and said its LastPass product systems and vaults were not compromised. That distinction is important for executives and counsel: the event may still trigger CRM data, privacy, and notification analysis even where core product systems, password vaults, or endpoint infrastructure were not breached. 3,4

26-Jun-2026 · Newly retained (>24h) LastPass's detailed response adds useful scoping language for counsel and customer communications: the company describes Salesforce and Gong integration context, token rotation, discontinued Klue access, law-enforcement cooperation, customer anti-phishing guidance, published IOCs, and a product/vault boundary. 30 26-Jun-2026 · Freshly reported (<24h) TechCrunch adds a second-wave extortion concern: Klue reportedly told customers the original criminals were deleting stolen data while another group had begun making threats. 31

26-Jun-2026 · Freshly reported (<24h) SecurityWeek now reports roughly two dozen public Klue-Salesforce impact disclosures and names an expanded set of customer-notice examples. 36 26-Jun-2026 · Newly retained (>24h) Obsidian adds tenant-forensics detail across impacted organizations, including Global Describe reconnaissance, QueryMore pagination, API-version deviation, user-agent deviation, and broad object harvest patterns. 37

27-Jun-2026 · Newly retained (>24h) LogicMonitor/Catchpoint and Tanium add direct customer-disclosure boundaries: both tie the incident to Salesforce data exposure through Klue while separating that exposure from core product, production, monitoring, or cloud-infrastructure compromise. 41,43 27-Jun-2026 · Newly retained; undated Tines adds a trust-center boundary that Klue credentials were used to access Salesforce data, with no evidence of unauthorized access to the Tines platform or customer environments. 42

28-Jun-2026 · Newly retained (>24h) OneTrust, Gong, and Insurity add three direct public-disclosure boundaries: OneTrust ties the event to Klue Battlecards/Salesforce CRM-related data without evidence of customer-tenant exposure; Gong scopes impact to customers who connected Klue with Gong and says call recordings/transcripts were not directly impacted; Insurity says a limited set of active credentials found in exposed CRM data were rotated or reset and that Insurity products were not involved. 44,45,46

29-Jun-2026 · Freshly reported (<24h) AudienceView adds a fresh status-page resolution timestamp while retaining the older June 22 monitoring context for its Klue-Salesforce integration incident. 47 29-Jun-2026 · Newly retained (>24h) Link11 adds a direct CRM-data notice, while FINRA and ZeroFox add sector guidance, Icarus/ICARUS reinforcement, limited IOCs, and a caveat that Underground Uwu / Scattered Lapsus$ Hunters claims should not be collapsed into UNC6395/Salesloft Drift. 48,53,54 29-Jun-2026 · Newly retained; undated AlertMedia, Cresta, and Lucanet add undated trust-center disclosures that improve public victim boundary coverage without creating a universal impact model; Camunda is now handled separately because its latest trust-center update provides a dated source-specific boundary revision. 49,50,51,52

30-Jun-2026 · Newly retained (>24h) ControlUp, Deel, and Saviynt add direct public customer-disclosure boundaries for Klue-linked Salesforce, CRM, sales, or business-contact data exposure while separating that exposure from their respective product, production, infrastructure, or product-customer-data environments. 55,56,57 30-Jun-2026 · Newly retained; undated ABBYY adds an undated trust-center disclosure stating Salesforce data accessed through Klue's integration was affected while ABBYY's network, products, and technology were not affected. 58

02-Jul-2026 · Freshly reported (<24h) Klue says CrowdStrike completed its investigation on June 30, found no evidence of threat-actor access outside systems related to the integration service, found no evidence of threat-actor activity in the Klue environment after June 12, and that Klue deployed CrowdStrike Falcon monitoring. 59 02-Jul-2026 · Newly retained (>24h) Camunda's latest trust-center update narrows Camunda's own impact boundary: exfiltrated data did not include support data and was limited to standard business-contact and account information in Salesforce CRM. 50

04-Jul-2026 · Newly retained; undated Postman's Security & Trust Portal adds a direct public customer-disclosure boundary: Postman says customer contact data and sales information were exfiltrated from its Salesforce environment via the compromised Klue service account between June 11-12, customer data was not accessed from Gong, and Postman's core platform services remain secure and were not impacted. 60

07-Jul-2026 · Newly retained (>24h) eSentire adds another direct public customer-disclosure boundary: eSentire says it uses Klue, was among the organizations whose Salesforce data was accessed, and describes the exposure as minimal because the integration was tightly scoped with restricted OAuth permissions and a limited connected-app footprint. It reports no identified risk to customers from eSentire's services and excludes customer communications, support interactions, threat intelligence, telemetry, credentials, passwords, and payment-card data. 62

08-Jul-2026 · Newly retained (>24h) Thinkproject adds a UAT CRM-specific public customer boundary: Klue had authorized software-integration access to that CRM environment, exfiltrated data may include business-contact and commercial information, Thinkproject products and services were not affected, and the CRM system is separate from the customer product platform. 63

09-Jul-2026 · Newly retained (>24h) Snyk's July 8 status resolution adds investigation-closure confidence: Snyk says its Klue/Salesforce forensic investigation, conducted with Mandiant, is complete; the impact remained limited to business CRM data; and no Snyk platform or sensitive platform-data impact was found. 64 09-Jul-2026 · Freshly reported (<24h) Secure ISS's July 9 advisory relays a SentinelOne partner-notification boundary: the Klue impact was contained to SentinelOne's Salesforce environment through the Klue API integration, with no lateral movement and no core-product, cloud-infrastructure, or production-environment impact reported. Treat it as a qualified public advisory because the direct SentinelOne portal reference is access-controlled and data analysis remains ongoing. 65

11-Jul-2026 · Newly retained (>24h) OneTrust's July 10 update closes its technical investigation, validates scope, and finalizes containment and remediation. OneTrust says the independent forensic investigation found no evidence of exposure beyond its Salesforce environment, while governance, compliance, and notification review remain ongoing. 44

13-Jul-2026 · Freshly reported (<24h) Microsoft's July 13 research adds a fresh campaign-deconfliction layer: it groups Salesforce and SaaS OAuth-abuse activity observed from mid-2025 to mid-2026 as tradecraft commonly associated with ShinyHunters and includes Klue integration activity in that broader discussion. 18-Jul-2026 · Newly retained (>24h) Microsoft also names Storm-3138 for the Klue system-access path. Use this to strengthen OAuth/connected-app hunting and activity-cluster deconfliction while preserving Icarus/ICARUS as the Klue-specific public extortion/operator label unless a reliable source directly merges or replaces that attribution. 66

14-Jul-2026 · Newly retained; undated Sisense adds another direct public customer-disclosure boundary: its Trust Center says Sisense was one of many affected organizations and that the incident was limited to certain business and sales-related data in Sisense's Salesforce CRM application. Sisense states the product platform and data stored within the product platform were not impacted, and says it disconnected certain third-party integrations, rotated credentials and tokens to Klue and Salesforce, and is monitoring access logs. 67

16-Jul-2026 · Newly retained (>24h) Qualtrics and Splashtop add two older direct public disclosure boundaries. Qualtrics says the Klue application connected to Salesforce for internal sales-team support, unauthorized access was limited to a subset of Salesforce data, impacted data included business-to-business identifiers, and Qualtrics products, core infrastructure, services, and hosted platform customer data were not accessed or compromised. Splashtop says Klue OAuth tokens were used to access certain Salesforce data, it disabled the Klue Salesforce integration and revoked access, the investigation remained ongoing, and Splashtop products and services were not impacted. 68,69

The best technical framing is OAuth/connected-app abuse in the Salesforce ecosystem. Klue says it revoked credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, and notified law enforcement. ReliaQuest and Datadog add the operational layer: token-backed access, automated Salesforce REST API queries, OAuth refresh-token evidence, connected-app identification, and object-level scoping are the artifacts defenders should examine. 1,5,6

For responders, the first question is not "did we patch Salesforce?" It is "did we use Klue or Klue Battlecards, what Salesforce data did that integration reach, and did token-backed API activity occur in our tenant?" The near-term response is to preserve Salesforce logs, identify Klue connected apps, revoke and rotate tokens and integration secrets, scope CRM objects queried or exported, and coordinate legal, privacy, and client communications around confirmed data access rather than speculative actor claims.

Expansion Research Add
Salesforce's own public guidance and researcher reporting support the same boundary: this should not be treated as a Salesforce platform vulnerability unless new primary evidence changes that status. The control plane is third-party application trust, OAuth tokens, connected apps, and Salesforce API visibility. 2,5,6,13

The closest public comparator is the Salesloft Drift campaign: Google Cloud, FBI/IC3, Unit 42, Arctic Wolf, BleepingComputer, and FINRA all describe a trusted SaaS integration/OAuth-token path into downstream Salesforce environments. That prior campaign is why Klue should be scoped as a SaaS integration supply-chain event, not as an isolated vendor notice. 18,19,20,21,22,24

5-AI Agent Delta Updates

6-Why It Matters

7-Timeline

8-Incident Response Playbook Ideas

9-Term Glossary

10-TTPs

11-Common Questions Q&A

12-CVE / Vulnerability References

13-IOCs / Observables

14-Threat Actor Glossary

15-Talking Points

16-Decision Ready Actions

17-Exploitable Technology Risks

18-Social Media / Community Signals

19-Tier 0 Through Tier 8 Source Summary

20-Source Reconciliation

21-About the Contributors

22-Real World Examples

23-Public Victims / Disclosure Matrix

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

26-Source Weighting / Relevance

27-Additional IntelliOS Threat Intel Products on This Topic

28-Notes

29-Citations

30-Version Change Log