Cybersecurity Firms Hit by Klue Supply Chain Attack Tied to Extortion Group Icarus
Want more insights like this?
A supply chain attack on market intelligence platform Klue has hit cybersecurity firms Huntress and Recorded Future, among what The Register reports are hundreds of affected Klue customers. Starting June 11, hackers reached Klue's backend servers and pushed a code update that harvested OAuth tokens for customers' integrations. Klue notified customers on June 12.
They then abused the Salesforce REST API to pull large volumes of CRM data — nearly 1,000 queries in 15 minutes, with extraction windows running over six hours. Salesforce wasn't the only exposure: the stolen tokens also covered Klue integrations with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack.
Huntress lost business contacts, price quotes and other sales data. Recorded Future lost client contact names and email addresses, and possibly business contract information. Neither lost threat intelligence, passwords or payment data.
Huntress has linked the attack to Icarus, an extortion group that emerged in April 2026, after receiving direct extortion messages from a threat actor identifying as "mr bean." Klue customers should revoke and re-authorise their integration tokens.
Source: SecurityWeek