Icarus leaks Salesforce CRM data tied to Klue OAuth breach on June 23, 2026
The main development on June 23, 2026 is that the Icarus extortion group began posting data stolen from Salesforce customer instances after abusing Klue’s OAuth integration, widening a breach that had already forced Salesforce to cut off the Klue Battlecards connection on June 17, as detailed by Dark Reading.
Icarus publishes stolen Salesforce CRM records from Klue-linked attacks
Dark web posts attributed to Icarus list multiple Klue customers and include samples of data taken from connected Salesforce orgs, signaling the move from quiet exfiltration to public coercion. The timing matters: Icarus set a deadline for organizations to make contact, then began releasing stolen files when it passed, a pattern consistent with extortion campaigns targeting SaaS integrations. Dark Reading’s report notes six organizations appearing on the leak site and confirms the data aligns with what early victims had already investigated-typical CRM fields such as business contacts, quotes, opportunity notes, and subscription details rather than product telemetry or credentials, which elevates the risk of tailored social engineering but stops short of a core platform compromise. Dark Reading’s coverage also tracks the growing victim list and the pivot from intrusion to publication.
Salesforce disables Klue Battlecards integration after suspicious activity
Salesforce moved to block the threat path by disabling the Klue Battlecards connection on June 17, a step it communicated in a Salesforce Trust status message. In practice, that cut the live OAuth bridge Klue used to pull or push data into customer orgs, reducing follow-on exposure while customers rotate tokens and audit access. This mirrors the containment playbook from prior OAuth-abuse incidents: sever the third-party connection at the platform level, then scrub lingering app permissions and API keys before restoring any integration.
LastPass disclosure underscores the OAuth route into a Salesforce instance
The scope broadened publicly on June 23 when LastPass confirmed that attackers accessed its Salesforce environment through Klue, exposing customer contact and support case records while leaving password vaults untouched, as covered by TechCrunch. The mechanism behind the campaign-stealing and abusing OAuth tokens tied to the Klue integration-had been documented earlier in industry reporting, including CSO Online’s breakdown of the Klue breach, and it matches what responders see during SaaS-to-SaaS supply-chain attacks. For go-to-market teams, the near-term risk is credible phishing and invoice fraud attempts seeded with real CRM details that now sit in the wild; for admins, the operational takeaway is that token trust can become the blast radius when a connected app is compromised.




