[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbJ2A-x7pHnX2P5AF5QmHdFd1WEO5R7GfzYmngvq4PP4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":22,"source":23,"isVerified":4,"isSpamList":24,"isSensitive":4,"severity":25,"processingStatus":26,"logoUrl":27,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a669c6d932e5f055682f97c","KlueOAuth2026","Klue 2026 OAuth Tedarik Zinciri Data Breach","klue-oauth-2026","klue.com",{"name":12,"sector":13,"country":14,"website":10},"Klue","Software","Canada","2026-06-11T00:00:00.000Z","2026-07-26T23:46:53.292Z",0,[19,20,21],"Third-party integration credentials","OAuth access tokens","OAuth refresh tokens","\u003Cp>\u003Cstrong>The Klue 2026 OAuth data breach\u003C\u002Fstrong> is a supply-chain incident in which an actor used a previously compromised GitHub personal access token to introduce unauthorized code into Klue's integration service and collect OAuth credentials used to connect to third-party systems, including Salesforce. Stolen access and refresh tokens were then used to access data in some connected Klue customer environments.\u003C\u002Fp>\n\u003Cp>Klue's initial statement and the summary of an independent CrowdStrike investigation completed on June 30 are primary sources, while BleepingComputer independently reported the incident and confirmed downstream victims. The company did not publish the number of affected customers, OAuth tokens, or downstream records. LeakData therefore keeps pwnCount at zero as an unknown total and limits the classes to confirmed stolen integration credentials.\u003C\u002Fp>\n\u003Ch2>Technical Initial-Access Chain\u003C\u002Fh2>\n\u003Cp>According to CrowdStrike's findings, the threat actor leveraged a previously compromised GitHub personal access token on June 11, 2026. The PAT was used to introduce unauthorized code into Klue's integration service. That code collected third-party integration credentials, including OAuth access and refresh tokens for Salesforce. The investigation did not determine how the actor initially obtained the GitHub token.\u003C\u002Fp>\n\u003Cp>This path does not mean customer Salesforce passwords were directly stolen. OAuth tokens can provide API access through permissions previously granted to an integrated application, while a refresh token can be used to obtain new access tokens. Theft of integration credentials therefore allowed one event in Klue's application path to propagate into multiple customer environments.\u003C\u002Fp>\n\u003Ch2>Downstream Customer Access\u003C\u002Fh2>\n\u003Cp>Klue confirmed that the actor used the tokens to access data in a number of connected customer environments on certain third-party platforms, including Salesforce. BleepingComputer reported disclosures by organizations including LastPass, Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, and Huntress. Each organization had a different accessed-data scope, and their customer records are not combined in this Klue entry.\u003C\u002Fp>\n\u003Cp>Klue did not publish the number of customer environments, Salesforce objects, or records affected. Counts from downstream companies also cannot be summed into Klue pwnCount because the same people or CRM records could occur across measurements. This entry documents the parent integration compromise; the fields involved for each victim should be assessed separately in that organization's verified record.\u003C\u002Fp>\n\u003Ch2>Scope Found Unaffected\u003C\u002Fh2>\n\u003Cp>Klue's initial statement said the incident was limited to affected third-party integrations and there was no evidence that customer content stored directly in the Klue platform was impacted. CrowdStrike likewise found no evidence that the actor accessed Klue systems outside those related to the integration service. Those findings mean Klue-hosted customer content should not be added as a data class.\u003C\u002Fp>\n\u003Cp>“No evidence” is the published forensic conclusion and does not mean every downstream customer system was unaffected; access to connected environments is confirmed. The distinction shows that battlecards or competitive content stored in Klue and the integration credentials Klue managed for third-party access occupied different security boundaries.\u003C\u002Fp>\n\u003Ch2>Incident Timeline\u003C\u002Fh2>\n\u003Cp>The actor added unauthorized code to the integration service on June 11. Salesforce notified Klue on the morning of June 12 about suspected third-party activity originating from its API integration service. That morning Klue disabled the affected Google Kubernetes Engine pods and compromised GitHub PATs and rotated OAuth credentials. LeakData uses June 11, the verified beginning of technical activity, as the breach date.\u003C\u002Fp>\n\u003Cp>CrowdStrike found no evidence of threat-actor activity in the Klue environment after June 12 and completed its full investigation on June 30. Klue published an initial public update on June 18 and the completed findings summary on July 1. These dates distinguish unauthorized code execution, detection and containment, customer communication, and completion of independent review.\u003C\u002Fp>\n\u003Ch2>Containment and Hardening\u003C\u002Fh2>\n\u003Cp>Klue revoked affected credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, launched a comprehensive investigation, and notified law enforcement. It gave CrowdStrike unrestricted access to environments, systems, endpoints, backups, logs, and the engineering team. Findings and specific remediation guidance were shared directly with affected customers.\u003C\u002Fp>\n\u003Cp>Klue blocked GitHub personal access tokens organization-wide and migrated workflows to GitHub Apps and short-lived credentials. It added automated secret scanning, enhanced GitHub and Google Cloud logging, CI\u002FCD visibility, centralized SIEM monitoring, endpoint detection and response, runtime network filtering, and an allowlist of approved GitHub Actions. Those controls target the long-lived credential and deployment-path risks behind the event.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>This entry does not claim that every customer's Salesforce data came from one Klue database. The confirmed parent data assets are third-party OAuth access and refresh tokens collected through Klue's integration service. Downstream CRM data theft resulted from abuse of those tokens. A zero-person value does not make the incident insignificant; it means no unique person-based scope was published.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that a stolen GitHub PAT enabled unauthorized code on June 11, OAuth integration credentials were collected, and connected customer environments were accessed; Klue disabled the service and tokens on June 12, and CrowdStrike found no later activity. There is no evidence Klue-platform customer content was affected. Initial PAT theft, token count, and total downstream record scope remain undisclosed.\u003C\u002Fp>","Integration infrastructure and OAuth token breach",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fklue_com.svg"]