When Your Vendor's Vendor Gets Hacked: The Klue Breach and What It Means for Your Board
A competitive intelligence platform most executives have never heard of just handed attackers the keys to Salesforce environments at some of the biggest names in cybersecurity. If that sentence doesn't get your attention, it should — because the Klue breach is exactly the kind of supply chain attack I warned about in Cyber Risk Is Business Risk, and it carries a lesson every board needs to hear right now.
What Happened
On June 12, a threat group calling itself Icarus used a compromised legacy credential — a password or token originally created for a prototype integration that Klue later abandoned but never revoked — to break into the infrastructure of Klue, an AI-powered market intelligence platform. From there, they stole OAuth tokens that connected Klue to its customers' Salesforce instances.
Then they went shopping.
The attackers used those stolen tokens to impersonate Klue inside each customer's Salesforce environment, querying and exfiltrating CRM data before anyone noticed. On June 19, Icarus claimed responsibility and issued a deadline: respond by June 22, or the data gets published.
Salesforce disabled Klue's Battlecards app integration on June 11, and Klue's CEO published a statement on June 19 confirming the intrusion. By June 22, at least nine Klue customers had disclosed impact — including LastPass, BeyondTrust, HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Additional affected organizations include Insurity and Sprout Social.
The Irony Nobody Should Miss
Read that victim list again. HackerOne runs the world's largest bug bounty platform. Huntress provides managed detection and response. Recorded Future sells threat intelligence. These are companies that exist to make other companies more secure, and they all got caught by the same thing: an abandoned integration credential that nobody cleaned up.
In my experience, this is where most vendor risk conversations fall apart. Boards ask whether a vendor has a SOC 2 report. They check a compliance box. What they don't ask is: "How many third-party integrations does this vendor maintain, and which ones still have active credentials for services they no longer use?"
That's the question that would have caught this.
The Three Questions, Applied
In Cyber Risk Is Business Risk, I lay out three questions every executive should be able to answer about any risk their organization carries. Applied to vendor risk, they look like this:
What could go wrong? A third-party platform with OAuth access to your CRM gets compromised. The attacker doesn't need to breach you — they breach your vendor's vendor and walk through a door you forgot you left open.
How likely is it? Extremely. The average enterprise now has hundreds of SaaS integrations, many with long-lived OAuth tokens that are rarely audited. Klue's compromised credential was for a prototype integration they abandoned. How many abandoned integrations exist in your environment right now?
What would it cost us? In this case, the exposed data was CRM records — customer names, email addresses, job titles, phone numbers, business addresses, sales records, and in LastPass's case, the contents of customer support interactions. That's enough for highly targeted phishing campaigns against your customers, or for competitive intelligence your rivals would pay for.
What to Ask Your CISO This Week
If you're a board member or executive reading this, here are four questions for your next conversation with your security team:
- Do we have an inventory of every OAuth token and API integration connected to our critical SaaS platforms? If the answer is no, you have the same blind spot Klue's customers had.
- How often do we audit third-party integrations for dormant or unused connections? The credential that enabled this breach was for a prototype that Klue abandoned. Legacy integrations are legacy risk.
- What data do our SaaS vendors' integrations actually have access to? Klue's integration could read Salesforce CRM data. Did the security teams at these companies know that? Did anyone model the blast radius if Klue itself got compromised?
- What's our response playbook when a vendor notifies us of a breach? Huntress published a detailed investigation blog within days. That's the standard. Can your team match it?
The Bigger Picture
This breach landed during the same week that SEC Regulation S-P's compliance deadline hit for smaller covered institutions (June 3, 2026), and as regulators continue tightening expectations around third-party risk management. The EU's NIS2 Directive required essential entities to be fully compliant by March 31, 2026. The regulatory environment is making clear that "we didn't know our vendor had a problem" is no longer an acceptable answer.
The Klue incident also highlights a growing pattern I've been tracking: the SaaS supply chain as an attack surface. When your competitive intelligence tool, your sales engagement platform, and your customer success system all have OAuth tokens linking them to your CRM, you're not managing a technology stack. You're managing an interconnected web of trust relationships, and any one of them can be the entry point.
Compliance checks don't catch abandoned credentials. Questionnaires don't reveal dormant integrations. The only thing that catches this is ongoing, active governance of your third-party relationships — not at contract renewal time, but continuously.
That's the difference between compliance and security. And it's exactly the gap that attackers like Icarus are learning to exploit.