News Article · Jun 24, 2026 at 12:38 PM
2 min read 0
Member
LastPass, BeyondTrust, and Others Confirm Data Theft in Klue-Salesforce Supply Chain Attack
Security #supply chain attack #data breach #Salesforce #Klue #LastPass #BeyondTrust #OAuth tokens #Icarus

LastPass, BeyondTrust, and Others Confirm Data Theft in Klue-Salesforce Supply Chain Attack

LastPass, BeyondTrust, and over a dozen other organizations have confirmed that customer data was stolen from their Salesforce instances after a supply chain attack on Klue, a market intelligence platform.

Listen to this article 3 min

LastPass, BeyondTrust, and at least 13 other organizations have confirmed that customer data was stolen from their Salesforce instances after a supply chain attack on Klue, a market intelligence platform. The breach, disclosed on June 24, 2026, involved a threat actor named Icarus who used a compromised legacy credential to access Klue's systems and generate OAuth tokens.

According to SecurityWeek, Icarus then used automated scripts to access the connected Salesforce instances and exfiltrate data in bulk. Salesforce and Gong have disabled the Klue integration in response. Over a dozen organizations have already confirmed impact, including HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, 8x8, and Pendo.

What Data Was Stolen and What Was Not

LastPass stated that the accessed information was limited to standard business contact information and CRM data, including customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related data. The company emphasized that its products, services, and infrastructure were not impacted, and customer vaults remain secure. There is no evidence the threat actor accessed any Gong-related data.

BeyondTrust also confirmed that business contact and sales-related information was stolen from its Salesforce instance. The company's notification initially went unnoticed. Huntress estimates that numerous other Klue customers were likely impacted and are expected to come forward.

  • Threat actor Icarus used a compromised legacy credential to access Klue's systems.
  • OAuth tokens were generated to breach third-party platforms like Salesforce.
  • Automated scripts exfiltrated data in bulk from connected Salesforce instances.
  • Salesforce and Gong disabled the Klue integration in response.
  • Icarus's Tor-based leak site listed at least four other companies that have yet to publicly disclose being affected.

Broader Implications and Next Steps

The attack highlights the risks of third-party integrations and the cascading effects of supply chain breaches. LastPass has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. The company advised customers to be vigilant for phishing attempts and to monitor their accounts for suspicious activity.

As of now, Icarus's website is down, but before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected, bringing the number of victims to roughly 15. The incident underscores the need for organizations to regularly audit third-party integrations and enforce strict access controls to mitigate supply chain risks.

Fact check

  • Threat actor Icarus used a compromised legacy credential to access Klue's systems and generate OAuth tokens.

    reported · source

  • Over a dozen organizations have confirmed impact, including HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, 8x8, and Pendo.

    reported · source

  • LastPass stated that customer vaults remain secure and no internal systems were compromised.

    reported · source

  • Salesforce and Gong have disabled the Klue integration in response to the attack.

    reported · source

Source reporting (3)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 239 users online: 0 registered, 235 guests and 4 bots.

Most users ever online was 1,755 on 17 Jun 2026, 5:11 pm.

Bots: AhrefsBot Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 360