Desk live·
ForensicPost
Cloud/Tokens/File 26-0611

Klue Compromise Reached Salesforce Environments at Two Dozen Customers

A compromise at Klue reportedly began with a legacy credential and OAuth token theft, reaching Salesforce environments across two dozen customers. An integration is a standing grant, and it outlives the reason it was created.

Constructed geometry · not a chart of case data
TargetKlue
ActorUnattributed
D. Kennedy9 min readConfidence: medium1 source reviewed

Reporting describes a June 2026 compromise at the competitive-intelligence vendor Klue involving a legacy credential and OAuth token theft, with access reaching Salesforce environments across roughly two dozen customers.

The mechanism is worth stating plainly, because it is the most common way one vendor compromise becomes many customer compromises, and it is almost never described as a vulnerability.

An Integration Is A Standing Grant

When a customer connects a SaaS product to their CRM, they issue a token. That token does not expire when the project that motivated it ends, does not require the user who approved it to still work there, and frequently carries scopes far broader than the feature needs — because the narrow scope was harder to configure and the broad one worked.

From the customer’s side the grant is nearly invisible. It does not appear in an access review, generates no login events for their users, and lives in an administrative console nobody opens.

The Blast Radius Is A Customer List

For an intruder holding a vendor’s token store, the reachable set is exactly the vendor’s integrated customer base. No lateral movement is required and nothing needs to be exploited: the tokens are used as intended, from the vendor’s own infrastructure, which is where the customer’s logs expect them to come from.

The word "legacy" in the reported access route is the part to sit with. It indicates a credential that outlived its purpose and stayed valid — the same failure as a dormant OAuth application, arriving from the other direction.

How we reported this

Compiled from public reporting, listed below. Customer counts are as reported. We have not reviewed any accessed environment. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary