Klue A.I CyberSecurity Scoring
Klue
Company Information
Website:http://www.klue.com
Employees number:199
Number of followers:32,457
NAICS:5112
Industry Type:Software Development
Homepage:klue.com
Klue Risk Score (AI oriented)
Between 700 and 749
KlueSoftware Development
Updated:
18/06/2026
18/06/2026
735/1000
Moderate
Ba
Klue Global Score (TPRM)
xxxx
KlueSoftware Development
Score locked

KlueModerate
Current Score
735Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
753
Cyber Attack
17 Jun 2026 • Klue
Huntress, Salesforce and Klue: Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
Klue OAuth Breach Exposes Salesforce Data in Icarus Extortion Campaign
735
CRITICAL-18
HUNSALKLU1781793603
Klue OAuth Breach Exposes Salesforce Data in Icarus Extortion Campaign
A recent OAuth breach at market intelligence platform Klue has enabled the Icarus threat group to steal Salesforce CRM data from multiple organizations as part of an ongoing extortion campaign. The attack, first reported by BleepingComputer and confirmed by cybersecurity firms ReliaQuest and Huntress, has prompted Salesforce to disable the Klue Battlecards integration while investigations continue.
### How the Attack Unfolded
Attackers compromised Klue’s backend systems, leveraging a dormant but active credential from a prototype integration. Once inside, they deployed a malicious code update to harvest OAuth tokens used by customers to connect Klue Battlecards with third-party platforms, including Salesforce.
Using these stolen tokens, the threat actors executed automated Python scripts to query Salesforce’s REST API for nearly 24 hours. Initial reconnaissance targeted the `/services/data/v59.0/sobjects` endpoint, followed by rapid data exfiltration via `/services/data/v59.0/query`. In one case, attackers sent nearly 1,000 queries in 15 minutes, shifting from stealthy reconnaissance to high-speed theft.
### Extortion Demands & Icarus Involvement
While initial activity resembled past attacks by ShinyHunters, BleepingComputer confirmed that the Icarus group active since April 2026 is behind the campaign. Victims received extortion emails from an alias "mr bean" with a Session Messenger ID for contact. Icarus’s data leak site also teased the campaign with a post titled "Get Ready," warning of upcoming corporate listings.
Huntress, one of the affected organizations, confirmed receiving a similar extortion email, with the provided Session ID matching Icarus’s dark web leak site. The stolen data includes business contacts, sales communications, price quotes, competitive intelligence reports, and account details, though no evidence suggests compromise of passwords, payment data, or engineering systems.
### Response & Mitigation
Klue has disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack while addressing the breach. Salesforce has also suspended the Klue Battlecards app, preventing new connections until further notice.
Security firms have shared IP addresses linked to the attacks:
- 138.226.246.94
- 212.86.125.24
- 213.111.148.90
- 94.154.32.160
Organizations using Klue integrations are urged to review logs, revoke OAuth tokens, terminate active sessions, and monitor for unusual API activity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
753
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Klue ??
What was Klue's A.I Rankiteo Cyber Score in May 2026 ??
What was Klue's A.I Rankiteo Cyber Score in April 2026 ??
What was Klue's A.I Rankiteo Cyber Score in March 2026 ??
What was Klue's A.I Rankiteo Cyber Score in February 2026 ??
What was Klue's A.I Rankiteo Cyber Score in January 2026 ??
What was Klue's A.I Rankiteo Cyber Score in December 2025 ??
What was Klue's A.I Rankiteo Cyber Score in November 2025 ??
What was Klue's A.I Rankiteo Cyber Score in October 2025 ??
What was Klue's A.I Rankiteo Cyber Score in September 2025 ??
What was Klue's A.I Rankiteo Cyber Score in August 2025 ??
What was Klue's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Klue's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Klue ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Klue's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?