Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations.
What Happened?
On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress.
Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed.
How the Attack Unfolded
The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain.
Key Victims & Impact
While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span:
- Password management (LastPass)
- Privileged access (BeyondTrust)
- Endpoint security (Tanium, Jamf)
- Threat intelligence (Recorded Future)
- Bug bounty coordination (HackerOne)
- Application security (Snyk)
Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure.
Broader Context: A Year of Supply Chain Attacks
The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses.
Regulatory & Industry Reactions
- Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene.
- Security vendors on the victim list face heightened procurement questions from enterprise buyers.
- Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications.
Lessons from the Breach
The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires:
- Automated expiration for pilot credentials.
- Minimum-scoped OAuth grants (avoiding broad CRM access).
- Recurring token audits to identify stale integrations.
As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
Source: https://tech-insider.org/klue-data-breach-2026/
Jamf cybersecurity rating report: https://www.rankiteo.com/company/jamf-software
Huntress cybersecurity rating report: https://www.rankiteo.com/company/huntress-labs
Snyk cybersecurity rating report: https://www.rankiteo.com/company/snyk
Recorded Future cybersecurity rating report: https://www.rankiteo.com/company/recorded-future
HackerOne cybersecurity rating report: https://www.rankiteo.com/company/hackerone
LastPass cybersecurity rating report: https://www.rankiteo.com/company/lastpass
Tanium cybersecurity rating report: https://www.rankiteo.com/company/tanium
Klue cybersecurity rating report: https://www.rankiteo.com/company/klue
BeyondTrust cybersecurity rating report: https://www.rankiteo.com/company/beyondtrust
"id": "JAMHUNSNYRECHACLASTANKLUBEY1784126732",
"linkid": "jamf-software, huntress-labs, snyk, recorded-future, hackerone, lastpass, tanium, klue, beyondtrust",
"type": "Breach",
"date": "6/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '195-200 companies',
'industry': 'Competitive Intelligence',
'name': 'Klue',
'type': 'Vendor'},
{'industry': 'Password Management',
'name': 'LastPass',
'type': 'Customer'},
{'industry': 'Privileged Access',
'name': 'BeyondTrust',
'type': 'Customer'},
{'industry': 'Endpoint Security',
'name': 'Jamf',
'type': 'Customer'},
{'industry': 'Bug Bounty Coordination',
'name': 'HackerOne',
'type': 'Customer'},
{'industry': 'Threat Intelligence',
'name': 'Recorded Future',
'type': 'Customer'},
{'industry': 'Application Security',
'name': 'Snyk',
'type': 'Customer'},
{'industry': 'Endpoint Security',
'name': 'Tanium',
'type': 'Customer'},
{'industry': 'Cybersecurity',
'name': 'Huntress',
'type': 'Customer'}],
'attack_vector': 'Compromised OAuth Token',
'customer_advisories': 'Affected firms (e.g., LastPass, BeyondTrust) '
'clarified exposure of business contact and CRM data '
'only',
'data_breach': {'data_exfiltration': True,
'sensitivity_of_data': 'Low (non-core product data)',
'type_of_data_compromised': 'Business contact and CRM data'},
'date_detected': '2025-06-12',
'date_publicly_disclosed': '2025-06-15',
'description': 'In June 2025, a dormant credential issued by '
'competitive-intelligence platform Klue in 2022 became the '
'entry point for a breach affecting nearly 200 companies, '
'including prominent cybersecurity vendors. The attack, '
'claimed by the extortion group Icarus, exploited an '
'unmonitored OAuth token to access Salesforce environments, '
'underscoring the risks of neglected third-party integrations.',
'impact': {'brand_reputation_impact': 'Heightened procurement scrutiny for '
'security vendors',
'data_compromised': 'Business contact and CRM data',
'systems_affected': 'Salesforce environments'},
'initial_access_broker': {'entry_point': 'Legacy OAuth token'},
'investigation_status': 'Ongoing (as of June 2026)',
'lessons_learned': 'The incident highlights risks of dormant credentials, '
'fourth-party risk, and the need for automated expiration '
'of pilot credentials, minimum-scoped OAuth grants, and '
'recurring token audits.',
'motivation': 'Extortion',
'post_incident_analysis': {'root_causes': 'Overlooked dormant credential '
'(4-year-old OAuth token), lack of '
'automated expiration, and broad '
'OAuth grants'},
'ransomware': {'data_exfiltration': True},
'recommendations': ['Automated expiration for pilot credentials',
'Minimum-scoped OAuth grants (avoiding broad CRM access)',
'Recurring token audits to identify stale integrations'],
'regulatory_compliance': {'regulatory_notifications': 'Limited (breach may '
'not trigger major '
'notifications)'},
'response': {'communication_strategy': 'Public disclosure by Klue on June 15, '
'2025; affected firms acknowledged '
'exposure later'},
'stakeholder_advisories': 'Cyber insurers tightening scrutiny of third-party '
'integrations; security vendors facing heightened '
'procurement questions',
'threat_actor': 'Icarus',
'title': 'Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential',
'type': 'Data Breach',
'vulnerability_exploited': 'Unmonitored legacy credential (4-year-old OAuth '
'token)'}