LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Icarus Group Steals Salesforce Data via Klue OAuth Breach

HIGH severityUnverified claimHow we verify

Icarus Group Steals Salesforce Data via Klue OAuth Breach: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·June 18, 2026
Icarus Group Steals Salesforce Data via Klue OAuth Breach

Reported June 18, 2026.

HIGH
Severity
3
Data types exposed
June 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Huntress disclosed on June 18, 2026 that the Icarus Group had obtained Salesforce data, including business contacts and sales records, through a Klue OAuth breach. Individuals who may have been exposed should review their accounts and take appropriate steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Account credentials exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On June 18, 2026, reports stated that the threat actor group Icarus had accessed Salesforce customer-relationship-management records belonging to the cybersecurity firm Huntress by exploiting an OAuth integration with the Klue Battlecards application. The number of people whose information was involved has not been disclosed. The incident forms part of a wider pattern of attacks that target trusted third-party connections to enterprise platforms rather than the platforms themselves.

What happened

According to the available information, Icarus obtained access to Huntress Salesforce data through a breach of OAuth credentials associated with the Klue Battlecards app. The same method is described as having affected multiple other organizations that use Salesforce. No figures have been released for the volume of records taken or the precise dates of the access and exfiltration.

The reported summary characterizes the activity as an ongoing supply-chain-style campaign against Salesforce integrations. No further technical details, such as the initial point of compromise or duration of access, have been made public.

The group behind it: Icarus

The incident is attributed to the group Icarus. The group’s involvement rests on its listing of the victim in connection with the data. Public reporting on Icarus has previously described operations that focus on data theft from corporate environments through compromised credentials and third-party services.

Any specific claims made by the group about the Huntress data appear only in the context of the current listing and remain unverified beyond that attribution.

Huntress and its sector

Huntress operates in the cybersecurity sector, providing managed detection and response services to smaller and mid-sized organizations. Firms in this sector routinely maintain records of client environments, security telemetry, and business relationships that support service delivery.

Compromise of such records can extend visibility into both the provider’s own operations and the customer base it supports.

What was likely exposed

The information described as taken consists of Salesforce data, business contacts, and sales records. Additional categories mentioned in reporting include sales communications, price quotes, and competitive intelligence material stored within the same system.

The exact scope of records and the number of individuals affected remain undisclosed. Organizations of this type commonly store the following categories of data:

What's at stake

Exposure of business-contact and sales data can lead to increased targeted phishing, impersonation attempts, and competitive intelligence gathering by other parties. For the affected organization, the incident may prompt reviews of integration permissions and OAuth token management across connected applications.

Because the scale of the data set is unknown, the duration and intensity of any follow-on activity cannot yet be assessed.

Were you affected?

Individuals can begin by monitoring their email accounts and professional contact points for unusual messages that reference recent business interactions. Organizations should review connected applications within their Salesforce instances and revoke unused OAuth authorizations.

Readers may run a free exposure scan of their email address against known breach data sets to determine whether their information appears in publicly referenced incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyHuntress security record
86/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Huntress’s full breach history →

More recent breaches

Grafana Suffers GitHub Token Breach and Extortion AttemptMay 17, 2026Gms-net Listed by Icarus Ransomware GroupJune 22, 2026Klue.com Listed by Icarus Ransomware GroupJune 19, 2026thecreditpros.com Listed by Icarus Ransomware GroupJune 16, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Icarus Group Steals Salesforce Data via Klue OAuth Breach →

Source: BleepingComputer

Publicly posted by icarus — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram