Threat reportSupply ChainTL-2026-0926

LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)

mediumACTIVE

LastPass Customer CRM Data Exposed via Klue OAuth Token (TL-2026-0926), also tracked as Klue Supply Chain Breach, is a medium-severity supply-chain compromise, first published 2026-06-24. It is attributed to Icarus with medium confidence, affects Klue Klue Competitive/Market Intelligence Platform (Salesforce, maps to 15 MITRE ATT&CK techniques (T1059, T1078, T1087), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
1Icarus
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0926

Threat ID
TL-2026-0926
Also known as
Klue Supply Chain Breach, Klue OAuth Token Theft, Icarus Salesforce Campaign
Severity
MEDIUM
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Icarus
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
technology, cybersecurity, saas, software, insurance
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in LastPass Customer CRM Data Exposed via Klue OAuth Token

Malware and tooling: Malicious Klue integration-service code update (OAuth-token harvester)

How LastPass Customer CRM Data Exposed via Klue OAuth Token works

The Icarus extortion group breached competitive-intelligence SaaS vendor Klue using a disused-but-active prototype integration credential, pushed a malicious code update that harvested customer OAuth tokens, and replayed those tokens against connected Salesforce environments. LastPass confirmed on June 23, 2026 that its Salesforce CRM was accessed via this chain, exposing business contact and support-case data; no LastPass products, infrastructure, or customer password vaults were affected.

On June 11-12, 2026, threat actors tracked as the 'Icarus' extortion group compromised the backend infrastructure of Klue, a market/competitive-intelligence platform that integrates with Salesforce (and Gong) to synchronize CRM data. Initial access was achieved through a long-disused but still-active credential originally provisioned for prototype integration testing and never decommissioned. After gaining access, the actor pushed a malicious code update to Klue's integration service that was capable of collecting the OAuth tokens that Klue's customers had granted to connect Klue with their third-party systems (notably Salesforce).

Using the harvested OAuth bearer tokens, the attackers authenticated directly to victims' Salesforce REST APIs, bypassing traditional login controls and MFA because OAuth access tokens represent an already-consented, trusted API-based authentication relationship between services. The actors ran automated Python tooling — identifiable by default urllib user-agent strings — that executed bulk queries against the Salesforce REST API, in some cases running nearly a thousand queries in 15 minutes to enumerate and copy CRM objects at scale. Infrastructure used for the access has been associated with PROSPERO, a Russian bulletproof-hosting provider previously linked to Ivanti EPMM exploitation.

LastPass was notified of the Klue incident on June 12, 2026. Salesforce detected anomalous activity tied to the Klue 'Battlecards' connected app and disabled the Klue app integration on June 17, 2026, stating the issue was limited to Klue's app connection and did not stem from a vulnerability in the Salesforce platform itself. The data accessed in LastPass's Salesforce instance was limited to customer relationship records: names, email addresses, phone numbers, physical addresses, support-case details, and sales-related records. LastPass emphasized that its products, services, infrastructure, and encrypted customer password vaults were NOT affected, and that no sensitive authentication data was compromised. LastPass warned that the exposed contact details and CRM records could be weaponized to make phishing and social-engineering scams appear more credible.

The Icarus group, active since approximately April 28, 2026, follows the now-familiar third-party OAuth-abuse playbook seen in prior 2025 Salesforce supply-chain campaigns (e.g., Drift/Gainsight, ShinyHunters/UNC6395) but is assessed as a distinct, unrelated cluster with no confirmed link to those actors. Icarus sent extortion emails to victims (Huntress employees received such emails on June 16, 2026) and publicly claimed Klue as a victim on June 19, 2026. The campaign impacted many organizations beyond LastPass, including Huntress (3.4 GB exfiltrated), Jamf, Recorded Future, Tanium, Gong, Insurity, Sprout Social, OneTrust, HackerOne, and Snyk. There is no CVE associated with this incident; it is a credential-hygiene and trusted-integration abuse case rather than a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-0926

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship

Persistence

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Discovery

T1087 Account Discovery; T1526 Cloud Service Discovery

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

lateral-movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Impact

T1657 Financial Theft

Affected products and versions in LastPass Customer CRM Data Exposed via Klue OAuth Token

  • Klue — Klue Competitive/Market Intelligence Platform (Salesforce 'Battlecards' connected app integration)
    Vulnerable versions: Integration infrastructure as of June 2026
    Fixed in: Integration disabled by Salesforce 2026-06-17; Klue credentials/tokens rotated
  • Salesforce — Salesforce CRM (downstream tenants via Klue connected app)
    Vulnerable versions: Orgs with active Klue OAuth grant
    Fixed in: Klue app integration disabled platform-side 2026-06-17
  • LastPass (GoTo) — LastPass Salesforce CRM instance
    Vulnerable versions: CRM data accessible via Klue OAuth token prior to 2026-06-12
    Fixed in: Tokens rotated; Klue access revoked

Remediation for LastPass Customer CRM Data Exposed via Klue OAuth Token

Immediate actions

  • Revoke and rotate ALL OAuth tokens and API keys granted to the Klue connected app across every Salesforce org
  • Disable / remove the Klue 'Battlecards' connected app integration in Salesforce until validated clean
  • Discontinue employee access to Klue pending investigation
  • Hunt Salesforce event logs (EventLogFile / Setup Audit Trail) for REST API access from the published IOC IPs and for urllib/Python user-agents performing high-volume queries
  • Block the published IOC IP ranges and email sender domains at perimeter and mail gateways

Workarounds

  • Until token rotation is complete, restrict Salesforce connected-app access by IP range and trusted-IP policy
  • Set OAuth connected-app policy to 'Admin approved users are pre-authorized' and revoke broad refresh tokens

Longer-term hardening

  • Inventory and least-privilege every third-party connected app; remove unused integrations and stale prototype/test credentials
  • Enforce IP allow-listing and short token lifetimes / mandatory refresh for OAuth-connected apps
  • Deploy anomaly detection on Salesforce API call volume and geolocation (alert on bulk REST queries from new ASNs/bulletproof hosting)
  • Require continuous credential-hygiene reviews to identify and decommission disused-but-active service credentials
  • Brief support and sales-facing staff plus affected customers on heightened phishing/social-engineering risk from exposed contact data

Weaknesses (CWE) in LastPass Customer CRM Data Exposed via Klue OAuth Token

CWE-1392, CWE-522, CWE-1059, CWE-294, CWE-672

Timeline of LastPass Customer CRM Data Exposed via Klue OAuth Token

  • Icarus extortion group becomes operationally active.
  • Security incident at Klue: actor accesses backend infrastructure via a long-disused but still-active prototype integration test credential.
  • Actor pushes a malicious code update to Klue's integration service that harvests customer OAuth tokens and replays them against connected Salesforce REST APIs (bulk Python/urllib queries, ~1000 queries in 15 minutes).
  • Klue detects unauthorized activity in its integration infrastructure; LastPass is notified of the Klue incident the same day.
  • Huntress employees receive extortion emails tied to the campaign.
  • Salesforce detects anomalous activity tied to the Klue 'Battlecards' connected app and disables the Klue app integration platform-wide.
  • Icarus publicly claims Klue as a victim.
  • LastPass publicly discloses that customer CRM data in its Salesforce instance was accessed via the stolen Klue OAuth tokens; publishes IOCs and confirms vaults/infrastructure unaffected.

Sources cited for LastPass Customer CRM Data Exposed via Klue OAuth Token

Detection coverage for TL-2026-0926

As of 2026-06-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0926 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats