The list of Klue customers whose Salesforce data was stolen in the latest supply-chain heist keeps growing, with an increasing number of cybersecurity companies disclosing that they are among the victims of a new data-theft and extortion crew called Icarus.
Klue, which provides market intelligence to more than 250,000 users worldwide, hasnt said how many of its customers were caught up in the breach and didnt immediately respond to The Registers inquiries.
Huntress was one of the first cybersecurity vendors to sound the alarm, and, in an email to The Register, said that it was among the hundreds of Klue customers affected. However, it said that the breach did not affect its tools or highly secure information such as passwords.
Huntress believes in radical transparency about security incidents, including when it affects our company, the certificate shop wrote on Thursday. The data that was copied from our Salesforce account includes business contacts, toll quotes, and other sales-related data and messaging. no threat data, passwords, defrayal card information, or engineering data relating to the Huntress agent or telemetry we collect was affected.
Huntress, along with the other victim companies, said that there is no indication that any of its products or infrastructure were compromised, and that this security incident was specific to CRM data.
Since then, several other security and software vendors including Recorded Future, Tanium, Jamf, Gong, HackerOne, Kudelski Security, Snyk, Insurity, and sprout social have revealed that the data thieves also accessed their CRM data via the Klue integration with Salesforce.
Heres what we doh experience about what happened and who is behind this latest extortion campaign.
The breach occurred on June 11, and Klue spotted the intrusion a daytime later. This unauthorized activity affected a portion of its integration infrastructure, according to the software provider.
Klue has since disconnected all of its integrations with Salesforce, Gong, HubSpot, SharePoint, and Google Drive. It also hired CrowdStrike to assist in the investigation and security response.
Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service, Klue CEO Jason Smith said in a Friday blog post. The assailant used that access to obtain OAuth tokens used to tie Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments.