INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Icarus Leaks Data in Salesforce Attacks

| 2026-06-23 20:44 LOW LOW DATA BREACH
Executive Summary
AI-generated
A wave of Salesforce data thefts, which began on June 17, has impacted multiple technology and cybersecurity companies including Huntress, HackerOne, Recorded Future, Jamf, Snyk OneTrust, Insurity, Tanium, Sprout Social, LastPass, Klue's Battlecards application vendor Salesloft, and Gong. The extortion group Icarus is behind the attacks, with more victims expected to be affected. According to Icarus, threat actors accessed customer data within Salesforce instances of these companies, including usernames, user business titles, and user emails for a subset of Gong customers that used the Klue integration. The attack works by exploiting vulnerabilities in third-party integrators like Klue, allowing attackers to access sensitive information without directly breaching the targeted company's systems. As of now, affected companies have suspended access to compromised Salesforce instances, rotated exposed API tokens, and launched investigations into the attacks.
Technical Mitigations AI-generated
• Rotate exposed API access tokens for affected companies like LastPass. • Block suspicious IP addresses as done by Gong to prevent further data compromise. • Implement strict data segmentation policies and controls, such as those used by HackerOne.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope technologytechnology
Intelligence Sources