Reporting describes a June 2026 compromise at the competitive-intelligence vendor Klue involving a legacy credential and OAuth token theft, with access reaching Salesforce environments across roughly two dozen customers.
The mechanism is worth stating plainly, because it is the most common way one vendor compromise becomes many customer compromises, and it is almost never described as a vulnerability.
An Integration Is A Standing Grant
When a customer connects a SaaS product to their CRM, they issue a token. That token does not expire when the project that motivated it ends, does not require the user who approved it to still work there, and frequently carries scopes far broader than the feature needs — because the narrow scope was harder to configure and the broad one worked.
From the customer’s side the grant is nearly invisible. It does not appear in an access review, generates no login events for their users, and lives in an administrative console nobody opens.
The Blast Radius Is A Customer List
For an intruder holding a vendor’s token store, the reachable set is exactly the vendor’s integrated customer base. No lateral movement is required and nothing needs to be exploited: the tokens are used as intended, from the vendor’s own infrastructure, which is where the customer’s logs expect them to come from.
The word "legacy" in the reported access route is the part to sit with. It indicates a credential that outlived its purpose and stayed valid — the same failure as a dormant OAuth application, arriving from the other direction.
Compiled from public reporting, listed below. Customer counts are as reported. We have not reviewed any accessed environment. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense