Salesforce has disabled the Klue Battlecards application integration after Klue disclosed a security breach involving OAuth token abuse that led to unauthorized access to customer data. According to company reports released on June 19, 2026, an attacker infiltrated Klue’s integration infrastructure on June 11 using a compromised legacy credential tied to a Klue integration service. The intruder generated OAuth tokens to connect Klue with third-party platforms, including Salesforce, and queried CRM systems to exfiltrate business contacts, price quotes, and internal sales messaging. An extortion group known as Icarus later used the stolen data to threaten affected victims. Klue has revoked credentials, removed malicious code, and disabled impacted integrations while forensic investigations continue.
Prepared by Jonathan Pierce and reviewed by editorial team.
Your business data might be at risk. The Klue breach allowed unauthorized access to customer data, including business contacts and price quotes. If you use Salesforce or Klue, check your account for suspicious activity.
This breach is another reminder of the importance of digital security. Klue is taking steps to fix the issue, but the damage is done. Be vigilant about your online data. Worth forwarding if you know someone using these platforms.
No left-leaning sources found for this story.
No right-leaning sources found for this story.
Comments