datadog-security-labs · Crawled Jul 18, 2026

Detecting the Klue supply chain attack in Salesforce instances

4 IoCs 1 Malware
Read original article ↗

AI Summary

In June 2026, the threat actor group 'Icarus' conducted a supply chain attack by compromising Klue's backend systems, leveraging dormant OAuth credentials to gain unauthorized access to customer Salesforce and Gong environments. The actor exfiltrated sensitive CRM data including business contacts, price quotes, and sales communications by abusing API queries with stolen OAuth tokens. Klue responded by revoking access and alerting customers, while the actor initiated an extortion campaign using Session Messenger. The attack highlights risks associated with third-party integrations and improper credential lifecycle management.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 4 extracted

Type Value Detail
IP 138[.]226[.]246[.]94 Details →
IP 212[.]86[.]125[.]24 Details →
IP 213[.]111[.]148[.]90 Details →
IP 94[.]154[.]32[.]160 Details →

MITRE ATT&CK TTPs 16 techniques