Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Threat actor group Icarus stole OAuth tokens from Klue, a competitive intelligence SaaS platform, by compromising a legacy credential in Klue’s environment. The stolen tokens provided persistent, credential-less access to customer Salesforce environments, resulting in confirmed data exfiltration at six downstream organizations including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. The business risk is significant: any organization that integrated Salesforce through Klue may have had CRM data, including customer records, sales pipeline information, and contact data, accessed without authorization.

Author

Tech Jacks Solutions