Threat reportSupply ChainTL-2026-0926
LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)
LastPass Customer CRM Data Exposed via Klue OAuth Token (TL-2026-0926), also tracked as Klue Supply Chain Breach, is a medium-severity supply-chain compromise, first published 2026-06-24. It is attributed to Icarus with medium confidence, affects Klue Klue Competitive/Market Intelligence Platform (Salesforce, maps to 15 MITRE ATT&CK techniques (T1059, T1078, T1087), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 1Icarus
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0926
- Threat ID
- TL-2026-0926
- Also known as
- Klue Supply Chain Breach, Klue OAuth Token Theft, Icarus Salesforce Campaign
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Icarus
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- technology, cybersecurity, saas, software, insurance
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in LastPass Customer CRM Data Exposed via Klue OAuth Token
Malware and tooling: Malicious Klue integration-service code update (OAuth-token harvester)
How LastPass Customer CRM Data Exposed via Klue OAuth Token works
The Icarus extortion group breached competitive-intelligence SaaS vendor Klue using a disused-but-active prototype integration credential, pushed a malicious code update that harvested customer OAuth tokens, and replayed those tokens against connected Salesforce environments. LastPass confirmed on June 23, 2026 that its Salesforce CRM was accessed via this chain, exposing business contact and support-case data; no LastPass products, infrastructure, or customer password vaults were affected.
On June 11-12, 2026, threat actors tracked as the 'Icarus' extortion group compromised the backend infrastructure of Klue, a market/competitive-intelligence platform that integrates with Salesforce (and Gong) to synchronize CRM data. Initial access was achieved through a long-disused but still-active credential originally provisioned for prototype integration testing and never decommissioned. After gaining access, the actor pushed a malicious code update to Klue's integration service that was capable of collecting the OAuth tokens that Klue's customers had granted to connect Klue with their third-party systems (notably Salesforce).
Using the harvested OAuth bearer tokens, the attackers authenticated directly to victims' Salesforce REST APIs, bypassing traditional login controls and MFA because OAuth access tokens represent an already-consented, trusted API-based authentication relationship between services. The actors ran automated Python tooling — identifiable by default urllib user-agent strings — that executed bulk queries against the Salesforce REST API, in some cases running nearly a thousand queries in 15 minutes to enumerate and copy CRM objects at scale. Infrastructure used for the access has been associated with PROSPERO, a Russian bulletproof-hosting provider previously linked to Ivanti EPMM exploitation.
LastPass was notified of the Klue incident on June 12, 2026. Salesforce detected anomalous activity tied to the Klue 'Battlecards' connected app and disabled the Klue app integration on June 17, 2026, stating the issue was limited to Klue's app connection and did not stem from a vulnerability in the Salesforce platform itself. The data accessed in LastPass's Salesforce instance was limited to customer relationship records: names, email addresses, phone numbers, physical addresses, support-case details, and sales-related records. LastPass emphasized that its products, services, infrastructure, and encrypted customer password vaults were NOT affected, and that no sensitive authentication data was compromised. LastPass warned that the exposed contact details and CRM records could be weaponized to make phishing and social-engineering scams appear more credible.
The Icarus group, active since approximately April 28, 2026, follows the now-familiar third-party OAuth-abuse playbook seen in prior 2025 Salesforce supply-chain campaigns (e.g., Drift/Gainsight, ShinyHunters/UNC6395) but is assessed as a distinct, unrelated cluster with no confirmed link to those actors. Icarus sent extortion emails to victims (Huntress employees received such emails on June 16, 2026) and publicly claimed Klue as a victim on June 19, 2026. The campaign impacted many organizations beyond LastPass, including Huntress (3.4 GB exfiltrated), Jamf, Recorded Future, Tanium, Gong, Insurity, Sprout Social, OneTrust, HackerOne, and Snyk. There is no CVE associated with this incident; it is a credential-hygiene and trusted-integration abuse case rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-0926
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship
Persistence
Defense Evasion
Discovery
T1087 Account Discovery; T1526 Cloud Service Discovery
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
lateral-movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Impact
Affected products and versions in LastPass Customer CRM Data Exposed via Klue OAuth Token
- Klue — Klue Competitive/Market Intelligence Platform (Salesforce 'Battlecards' connected app integration)
Vulnerable versions: Integration infrastructure as of June 2026
Fixed in: Integration disabled by Salesforce 2026-06-17; Klue credentials/tokens rotated - Salesforce — Salesforce CRM (downstream tenants via Klue connected app)
Vulnerable versions: Orgs with active Klue OAuth grant
Fixed in: Klue app integration disabled platform-side 2026-06-17 - LastPass (GoTo) — LastPass Salesforce CRM instance
Vulnerable versions: CRM data accessible via Klue OAuth token prior to 2026-06-12
Fixed in: Tokens rotated; Klue access revoked
Remediation for LastPass Customer CRM Data Exposed via Klue OAuth Token
Immediate actions
- Revoke and rotate ALL OAuth tokens and API keys granted to the Klue connected app across every Salesforce org
- Disable / remove the Klue 'Battlecards' connected app integration in Salesforce until validated clean
- Discontinue employee access to Klue pending investigation
- Hunt Salesforce event logs (EventLogFile / Setup Audit Trail) for REST API access from the published IOC IPs and for urllib/Python user-agents performing high-volume queries
- Block the published IOC IP ranges and email sender domains at perimeter and mail gateways
Workarounds
- Until token rotation is complete, restrict Salesforce connected-app access by IP range and trusted-IP policy
- Set OAuth connected-app policy to 'Admin approved users are pre-authorized' and revoke broad refresh tokens
Longer-term hardening
- Inventory and least-privilege every third-party connected app; remove unused integrations and stale prototype/test credentials
- Enforce IP allow-listing and short token lifetimes / mandatory refresh for OAuth-connected apps
- Deploy anomaly detection on Salesforce API call volume and geolocation (alert on bulk REST queries from new ASNs/bulletproof hosting)
- Require continuous credential-hygiene reviews to identify and decommission disused-but-active service credentials
- Brief support and sales-facing staff plus affected customers on heightened phishing/social-engineering risk from exposed contact data
Weaknesses (CWE) in LastPass Customer CRM Data Exposed via Klue OAuth Token
Timeline of LastPass Customer CRM Data Exposed via Klue OAuth Token
- Icarus extortion group becomes operationally active.
- Security incident at Klue: actor accesses backend infrastructure via a long-disused but still-active prototype integration test credential.
- Actor pushes a malicious code update to Klue's integration service that harvests customer OAuth tokens and replays them against connected Salesforce REST APIs (bulk Python/urllib queries, ~1000 queries in 15 minutes).
- Klue detects unauthorized activity in its integration infrastructure; LastPass is notified of the Klue incident the same day.
- Huntress employees receive extortion emails tied to the campaign.
- Salesforce detects anomalous activity tied to the Klue 'Battlecards' connected app and disables the Klue app integration platform-wide.
- Icarus publicly claims Klue as a victim.
- LastPass publicly discloses that customer CRM data in its Salesforce instance was accessed via the stolen Klue OAuth tokens; publishes IOCs and confirms vaults/infrastructure unaffected.
Sources cited for LastPass Customer CRM Data Exposed via Klue OAuth Token
- LastPass Customer Data Exposed in Klue Supply Chain Attack
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
- LastPass Confirms Customer Data Breach After Klue OAuth Token Theft
- LastPass confirms data breach in Klue supply chain attack
- LastPass says customer data exposed in Klue supply chain breach
- LastPass Customer Data Accessed in Klue Supply Chain Attack Using Stolen OAuth Tokens
- MITRE ATT&CK T1528: Steal Application Access Token
- MITRE ATT&CK T1550.001: Use Alternate Authentication Material - Application Access Token
Detection coverage for TL-2026-0926
As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0926 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.