In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain breach evolved into an exceptional case in which a second criminal group claimed to have compromised the first extortion crew and pilfered data that had already been stolen. The result was not simply another ransomware story. It exposed fundamental weaknesses in SaaS integrations, identity-based trust, third-party risk management and executive decision-making.
Scene of the crime
Founded in 2015, Klue, a Vancouver, British Columbia-based software-as-a-service (SaaS) company, provides an AI-powered competitive intelligence platform that serves more than 500 customers and employs more than 200 people across North America and Europe. The company has raised approximately $81 million in venture funding. The platform helps organizations monitor competitors, analyze market signals and distribute insights across sales, marketing, product and executive teams. By aggregating public sources, internal knowledge, and third-party data, Klue turns fragmented information into actionable intelligence that supports faster strategic decisions, stronger competitive positioning, and more effective product planning. Klue’s “Battlecards app” integrates with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack, syncing account records, deal data, contact information and call transcripts.
Cause of the breach
Klue occupies a privileged position within customer environments since it integrates with platforms such as Salesforce and other collaboration ecosystems. Those integrations rely heavily on OAuth tokens that permit trusted, authenticated access without repeatedly requesting credential inputs. Attackers from the Icarus criminal group discovered an unused but still-active service account credential originally created for a pilot project. That unused, forgotten credential provided an entry point into Klue’s integration infrastructure. Rather than stealing passwords, the attackers harvested OAuth tokens. This distinction matters. Modern identity-based attacks increasingly focus on session tokens and application trust relationships instead of credential theft. Once valid OAuth tokens were obtained, the attackers effectively inherited the permissions granted to Klue within customer environments. They executed extensive Salesforce API queries over a period of hours, extracting customer relationship management data including contact information, quotes, pricing information, sales communications and account records.


