Klue Hack Shows How One Stolen Integration Key Exposes Everyone Downstream

A June 2026 supply-chain attack on Klue used a compromised legacy integration credential to steal OAuth tokens and drain Salesforce data from at least nine companies, including LastPass and HackerOne. Here's what happened and what it means.

By THEYDIDNTASK
The Incident On June 11, 2026, Klue — a Canadian competitive-intelligence platform used by enterprise sales and marketing teams — detected unauthorized access to its integration infrastructure. By June 12 the company had contained the intrusion, but the damage was already done: the attackers had used their access to steal OAuth tokens belonging to Klue's customers and drain data from those customers' Salesforce instances. The breach didn't come through Klue's core product. It came through the plumbing — the integration layer that lets customers sync competitive intelligence into their CRM. How It Happened The attackers exploited a compromised legacy credential to reach Klue's integration infrastructure. From there, the chain of compromise looks like this: Legacy access. An old, unrotated integration credential gave the attackers a foothold. Token theft. They harvested OAuth tokens that Klue held for customer Salesforce connections. Bulk exfiltration. With those tokens, they pulled contact records, account data, and business information from connected CRM instances — at scale, and without triggering per-customer alerts. Klue has said the exposed data was limited to Salesforce CRM contact and business data, and that the core platform — competitive-intelligence content, internal notes, and credentials stored elsewhere — was not affected. For customers, the breach still meant their Salesforce data left a system they didn't control, through a vendor they were told to trust. Who Was Affected The list of confirmed downstream victims reads like a who's-who of security vendors: LastPass Recorded Future HackerOne Huntress … and at least five other organizations, with more disclosures expected. It is a dark irony that security companies themselves were caught in a supply-chain blast radius. It is also the point: when you connect a third-party tool to your CRM, you are not securing that connection — you are trusting every other customer and every stale credential on the vendor's side. Why Supply-Chain Breaches Keep Happening This is the same pattern we've watched repeat for years. Attackers increasingly skip the hard target — the security-hardened core product — and go for the soft underbelly: legacy credentials, integration layers, and API tokens that were issued years ago and never rotated. One vulnerable vendor, and dozens of "secure" companies downstream are exposed. It is the modern equivalent of the national public data breach that exposed billions of records, only targeted instead of shotgun — and it's harder to notice because no single organization sees the whole picture. What to Do Audit your third-party integrations. Every OAuth connection your company holds is an attack surface. List them, question them, and remove the ones nobody remembers. Rotate legacy credentials. If an integration predates your current security team, treat it as compromised until proven otherwise. Assume vendor breaches happen. Ask what data your vendors can see on your behalf, and negotiate terms where the answer is "as little as possible." Watch for cross-customer pattern. If a vendor you use discloses an incident, assume your data was in scope until the vendor explicitly says otherwise — and check your own logs for unusual CRM exports. The Pattern Klue is not the first vendor to lose customer data through an old credential, and it won't be the last. The Conduent breach exposing 25 million records and this incident share a root cause: trust placed in connections that were never designed to be defended. The fix isn't more promises from vendors — it's treating every integration as a risk to be minimized, and every credential as something that will eventually be stolen. For practical steps on reducing your exposure, our privacy guide for 2026 is a good place to start.