Bottom line: In the Klue compromise, data that one attacker group had already stolen was subsequently stolen by a second group from the first group’s infrastructure – a scenario that calls into question control over stolen data.
The compromise of SaaS provider Klue reveals a rare scenario: one attacker group was itself attacked, after which a second group stole already-compromised data. The incident exposes critical vulnerabilities in SaaS integrations, identity-based trust, and third-party risk management.
The Vancouver-based SaaS company Klue provides an AI-powered competitive intelligence platform and serves over 500 customers with more than 200 employees across North America and Europe. The platform integrates with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack to synchronize account data, deal information, contact details, and call transcripts. The attacker group Icarus identified an unused but still-active service account credential that was originally created for a pilot project. Through this access, the attackers harvested OAuth tokens, which gave them access to credentials stored with customers in Salesforce. They conducted extensive Salesforce API queries and extracted CRM data such as contact information, deals, pricing, and sales communications.
The most unusual element of the incident occurred after the initial compromise: Icarus informed Klue that a second attacker group had stolen sample data following a compromise of Icarus’s servers. This second group allegedly attempted to extort affected organizations directly and advised victims not to trust Icarus. Whether all claims are verifiable matters less than the strategic lesson: stolen data itself becomes a target within criminal ecosystems.
This scenario fundamentally changes the traditional ransomware decision-making model. Organizations have long debated whether ransom payments increase the likelihood that stolen information remains private. The Klue compromise reveals an even more troubling possibility: even if an organization believed the original attackers would commit to deleting stolen data, the criminals may no longer control that data. If threat actors leave poorly secured infrastructure or are themselves compromised, victims may face repeated extortion campaigns even after paying the original demand.
The incident demonstrates how OAuth tokens serve as attack vectors – a focus of modern identity-based attacks that have shifted from credential theft to session tokens and application trust relationships. From a CISO perspective, the Klue compromise reinforces the insight that third-party risks do not end with contract management, but rather the operational security of the vendors themselves becomes a critical risk factor.
Source: www.csoonline.com · Published July 27, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.