Klue disclosed a cybersecurity incident affecting hundreds of customers including Recorded Future, Tanium, HackerOne, Kudelski Security,Insurity, and Huntress, after attackers gained unauthorized access to data stored within the company’s environment. That you know. But you may not know is that the company may have used a credential that dates back to 2022:
Market research company Klue has confirmed that a credential dating back to 2022, which was part of a limited pilot, was used by hackers earlier this month to steal reams of data from its corporate customers, including several cybersecurity companies.
The new detail suggests that Klue may have had years to decommission the credential that was used for the pilot, raising questions about the company’s security posture and what actions it could have taken to prevent the breaches of its customers’ data.
Sunil Gottumukkala, CEO, Averlon had this to say:
“This is the same pattern we saw with the Salesloft Drift attack, where stolen OAuth tokens were used to pull data from Salesforce and Google Workspace. This method is becoming the dominant way data leaves the enterprise: not through your perimeter, but through an approved SaaS integration.
“A compromised legacy credential at Klue gave attackers OAuth tokens into hundreds of customers’ Salesforce instances, which they used to impersonate the app and exfiltrate competitive intelligence and customer data. Your security is now only as strong as the third-party apps you have granted standing access to your CRM, and most teams don’t actively track those integrations.
“The immediate work is to inventory every OAuth integration into your SaaS, revoke what you don’t need, scope what you keep, and watch for anomalous token activity. And since the stolen data includes contact and sales detail, expect targeted phishing next. Warn your customers and employees before the attacker reaches them.”
John Strand, Owner, Black Hills Information Security, Inc. provided this comment:
“This is just a preview of the coming SaaS apocalypse. As AI accelerates offensive cyber operations across threat actors, from nation-states to militias, the risk is no longer limited to organizations building new AI-driven SaaS applications. Attackers are increasingly turning existing SaaS platforms into centralized points of failure, allowing them to exploit multiple customers simultaneously.”
Denis Calderone, CTO, Suzu Labs added this comment:
“Three Salesforce OAuth supply chain attacks in under a year, from two different threat actors, using the same playbook. Salesloft, Gainsight, and now Klue. Icarus is a brand-new extortion group, active since late April, and they executed the exact same technique that ShinyHunters ran through Gainsight back in November. Compromise the integration vendor, harvest OAuth tokens, query the Salesforce REST API with automated scripts, exfiltrate CRM data in bulk. At this point we have to accept that this particular attack pattern has been successfully commoditized.”
“What’s got our attention is how many security vendors are on the victim list. Huntress, Recorded Future, Tanium, HackerOne, Kudelski Security, Snyk, Jamf. The data sitting in their Salesforce instances includes competitive battlecards, pricing strategy, customer contacts, deal sizes, and sales communications. We expect to see some highly targeted spear-phishing campaigns as a result of this data. The attacker has access to real data that only an insider would know.
“We feel it important to highlight the root cause here. Huntress traced initial access back to a single credential Klue created for a prototype third-party integration they never actually deployed. One forgotten API key got the attacker into Klue’s backend. From there, they pushed a malicious code update that harvested the OAuth tokens of all connected customers at once. So one dormant credential that nobody remembered existed opened the door to 300 organizations’ CRM environments in a single operation.
“If you’re a Klue customer, rotate every OAuth token tied to that integration, and don’t limit yourself to Salesforce. Klue also integrated with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. The confirmed bulk exfiltration targeted Salesforce, but the token harvest covered all connected platforms.
“If Klue had an OAuth connection into your Slack, your Google Drive, or anything else, treat those tokens as compromised and rotate them now. Every org needs to audit connected apps for dormant integration credentials and building automated alerts on abnormal API query volume from third-party services. If a connected app that normally syncs a few hundred records starts pulling thousands of queries in minutes, that’s your early warning.”
Damon Small, Board of Directors, Xcape, Inc. said this:
“This third-party compromise highlights a severe operational risk where specialized business platforms become aggregate targets for corporate espionage, exposing the strategic playbooks of the cybersecurity sector itself. By exploiting Salesforce-linked integrations, attackers bypassed external perimeters to directly access sensitive competitive analysis, product intelligence, and customer data.
“For security executives, this incident demonstrates that non-core software vendors often possess highly privileged pathways into primary data repositories. To contain this exposure, organizations must immediately catalog all API and OAuth integrations connected to their central Customer Relationship Management systems. Teams should prioritize revoking obsolete or over-privileged third-party tokens, implementing strict scoping boundaries on automated data access, and establishing anomaly detection baselines for bulk data exports conducted by integrated applications.
“Critical Takeaways
- Security leaders must immediately audit and inventory all active OAuth tokens and connected applications within their Customer Relationship Management environments to identify over-privileged third-party access.
- Organizations should enforce strict data scoping and API restriction policies to limit the volume of proprietary competitive intelligence and customer telemetry accessible by integrated platforms.
- Security operations teams need to establish baseline detection rules specifically tailored to identify anomalous, high-volume data exports or API queries originating from external business applications.
“It is tough to sell threat visibility to your customers when your own corporate battlecards are exposed because you did not have a Klue.”
I guess that it is far past time for you to audit your environment to ensure that you’re not the next Klue. Because it is much easier to not be the next Klue that it is for me to write about you.
Tata investigates breach claims involving Apple and Tesla
Posted in Commentary with tags Hacked on June 23, 2026 by itnerdTata has apparently been pwned and the victims are Apple and Tesla.
The individual claimed to have stolen approximately 730,000 files, including engineering documents, presentations, spreadsheets, and other internal records associated with Tata Electronics’ manufacturing operations. The alleged breach comes months after Tata Electronics disclosed a separate cyber incident that temporarily disrupted some IT systems.
Tata Electronics is a key supplier within the global electronics supply chain, producing components and assembling products for major technology companies including being one of Apple’s most significant manufacturing partners outside of China, accounting for roughly a third of its iPhone production in India.
John Strand, Owner, Black Hills Information Security, Inc.:
“Whenever a breach becomes public because stolen data appears on the dark web, it raises a larger question: how many similar operations, especially those conducted by nation-state-level adversaries, are still operating undetected? The attacks that make the news deserve attention, but the greater concern is the reuse and evolution of the same tactics, tools, and infrastructure across campaigns that never become visible.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:
“Apple escaped supplier concentration in China and recreated it in India under one corporate roof. A third of India’s iPhone output, one conglomerate. Single point of failure, different mailing address.
“Vendor cybersecurity review has to cover the whole corporate family. Second cyber incident at Tata Electronics in months. TCS and JLR were hit by different attackers in the past year. Subsidiaries share IT vendors and security culture, so a breach at one should trigger immediate review of every entity holding sensitive client IP.
“When you hand trade secrets to a contract manufacturer, the cybersecurity terms in that vendor agreement need to reflect what’s being transferred. Continuous monitoring, audit rights, and breach notification requirements should be baseline for a supplier holding IP at this sensitivity level. A questionnaire at onboarding doesn’t cut it. 630 gigabytes on a leak site shows what happens when vendor oversight doesn’t match the exposure.”
John Carberry, Solution Sleuth, Xcape, Inc. adds this:
“This breach underscores a critical distortion in enterprise risk management where the actual containment of a data exposure plays second fiddle to managing the commercial boundaries of the cyber insurance policy. While the immediate operational crisis centers on leaked schematics for Apple and Tesla, the true systemic damage occurs when organizations prioritize check-the-box compliance to preserve underwriting limits rather than addressing the root cause of third-party aggregation risk.”
“Critical Takeaways
“Look on the bright side: your competitors will finally find out how much it actually costs to manufacture your products.”
I think its a safe bet that if Apple and Tesla do not get the answers that they are looking for, that their contract manufacturing will be someplace else shortly.
Leave a comment »