A supply chain attack on market intelligence platform Klue, carried out June 11–12, has now been confirmed by roughly two dozen customers, including AlertMedia, Blackbaud, Deel, Tines, BeyondTrust and LastPass. Hackers used legacy credentials to steal OAuth tokens and bulk-exfiltrate Salesforce data. Klue has reportedly told customers the incident touches 195 of them in total.
Salesforce disabled the Klue integration on June 17 and has yet to re-enable it; Gong disabled it too.
The threat actor, Icarus, demanded ransom via a Tor leak site — but then got hacked themselves. Klue has reportedly told customers that Icarus was breached and the stolen data is now in another threat actor's hands. Klue says Icarus has begun deleting the data, and its leak site has gone dark, which suggests a ransom may have been paid. Klue hasn't confirmed either way.
Source: SecurityWeek