CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Klue Integration Abused in Salesforce Data Theft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2117

As cited

Copy frozen at (site build).

threat intel

Klue Integration Abused in Salesforce Data Theft

Attackers compromised the Klue integration in Salesforce to exfiltrate customer relationship management (CRM) data by abusing OAuth tokens and automated REST API queries. The activity follows a pattern seen in prior Salesforce third-party compromises affecting Salesloft, Drift, and Gainsight throughout 2025 and 2026. A Telegram account claiming to be ShinyHunters took responsibility, though attribution remains unconfirmed.

Why it matters: Organizations using Klue or similar Salesforce integrations face immediate risk of CRM data exposure; practitioners should revoke OAuth tokens, rotate credentials, and restrict API access to allowlisted infrastructure while hunting for suspicious Salesforce API activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Klue Integration Abused in Salesforce Data Theft

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Klue Integration Abused in Salesforce Data Theft

Attackers abused a compromised Klue integration to harvest Salesforce Customer Relationship Management (CRM) data by generating Open Authorization (OAuth) tokens and issuing automated Representational State Transfer (REST) Application Programming Interface (API) queries. Defenders should revoke and rotate affected credentials, restrict API access to known infrastructure, and monitor Salesforce logs for abnormal query volume.

Why it matters: Organizations that rely on Klue or other Salesforce-linked integrations face CRM data theft via abused OAuth tokens and should immediately revoke those tokens, limit API access to trusted hosts, and review Salesforce logs for unusual activity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Klue Integration Abused in Salesforce Data Theft

Attackers abused a compromised Klue integration to harvest Salesforce Customer Relationship Management (CRM) data by generating Open Authorization (OAuth) tokens and issuing automated Representational State Transfer (REST) Application Programming Interface (API) queries. Defenders should revoke and rotate affected credentials, restrict API access to known infrastructure, and monitor Salesforce logs for abnormal query volume.

Why it matters: Organizations that rely on Klue or other Salesforce-linked integrations face CRM data theft via abused OAuth tokens and should immediately revoke those tokens, limit API access to trusted hosts, and review Salesforce logs for unusual activity.

VendorsMicrosoftSalesforce
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary