Last Update: 08/01/2026 at 1:00 PM EST

Cloud Integrations and Identity Breaches

Coverage from SecurityWeek, Morningstar, and others

Articles

49

Active Days

101

The Topic

Cloud Integrations and Identity Breaches topic image

The topic centers on cyberattacks that abuse trusted cloud connections, exposed credentials, and convincing impersonation to reach enterprise or personal data. A Klue integration compromise enabled unauthorized access to connected Salesforce environments and led to extortion claims, while separate incidents involving Accenture and The Credit Pros raised concerns about source code, credentials, and sensitive personal information. Phishing campaigns targeting LastPass and Bitwarden users show the same broader reliance on identity and trust-based attack paths, although the incidents are not attributable to a single campaign.

First Article: 04/13/26

Latest Article: 07/22/26

Summary

  • Attackers compromised Klue integration infrastructure and used stolen OAuth tokens to query multiple customer Salesforce environments.
  • Salesforce disabled the Klue Battlecards connection while affected organizations revoked tokens, disabled integrations, and investigated data exposure.
  • The Icarus extortion group claimed responsibility for the Klue-related theft and pressured victims through leak-site and Session-based communications.
  • Accenture confirmed a breach after a threat actor offered approximately 35 GB of alleged source code, keys, tokens, and configuration data for sale.
  • The Credit Pros incident may have exposed financial and identity information held in a Salesforce environment, but the available evidence is based partly on threat-actor and legal-investigation claims.
  • Fake LastPass and Bitwarden notices redirected users to malicious sites, demonstrating continued phishing against password-manager customers without evidence that either provider was breached.

History

07/23/2026

The biggest update is operational: Salesforce disabled the Klue Battlecards connection, and affected organizations began revoking tokens and disabling integrations. The Klue and Accenture items also gained sharper attribution and scale details, but the overall story remains a cluster of related trust-based cyber incidents.

07/21/2026

The story broadens from a Salesforce/OAuth breach cluster into a wider set of enterprise compromise and phishing incidents, with new named cases and actors. The most notable new development is Accenture's confirmed breach alongside allegations of stolen source code and cloud credentials, plus renewed phishing impersonation of password-manager brands.

Full History

Featured

Timeline: 101 Days

Apr 13May 4May 25Jun 8Jun 29Jul 20

Additional Articles

⭐⭐⭐⭐⭐

BleepingComputer / Lawrence Abrams06-19-2026
Klue confirmed an OAuth token theft incident involving compromised Battlecards integrations that enabled extortion-linked data extraction from multiple Salesforce environments after June 12 discovery.
BleepingComputer / Bill Toulas07-14-2026
LastPass warned in an active phishing campaign period that fake security update emails redirect users to DocuSign-impersonating malicious domains to prompt downloads and possible credential entry.
TechCrunch06-23-2026
Klue disclosed a breach detected June 12 after hackers used a reused 2022 pilot credential to access tokens and exfiltrate customer cloud data.
TechRadar06-24-2026
LastPass disclosed that a Klue supply chain attack using stolen OAuth tokens enabled unauthorized access to LastPass customer data in Salesforce.
Mashable / Chance Townsend06-24-2026
LastPass disclosed a Klue-linked breach on the LastPass Salesforce environment after attackers used OAuth tokens to access customer data.
The Register / Carly Page07-09-2026
Accenture investigated an alleged July 6 cybercrime forum listing describing sale of 35GB of internal data, including cloud credentials, with remediation reported.
Help Net Security / Zeljka Zorz06-19-2026
Huntress said a Klue breach beginning June 11 stole OAuth tokens used for Salesforce-connected SaaS integrations, leading to CRM data exfiltration and integration shutdowns.
CSO Online / Gyana Swain06-22-2026
Klue detected an OAuth token theft incident on June 12, leading to Salesforce integration shutdowns and cross-customer CRM data access reports from Huntress and ReliaQuest.
The Hacker News06-19-2026
Salesforce disabled the Klue Battlecards integration after Klue detected June 12, 2026 OAuth token abuse from a compromised vendor credential to access connected Salesforce customer data.
Yahoo Finance / Bailey Pemberton06-26-2026
Salesforce disabled Klue Battlecards after stolen OAuth tokens enabled API record access, exposing enterprise customer data within the Salesforce ecosystem.
Yahoo Finance / Bailey Pemberton06-26-2026
Salesforce disabled Klue Battlecards in response to a breach using stolen OAuth tokens that exposed customer records via the Salesforce API.
Yahoo Finance / Bailey Pemberton06-26-2026
Salesforce disabled the Klue Battlecards integration after OAuth-token access reportedly exposed Salesforce customer records via Salesforce APIs.
BetaKit06-24-2026
Klue disclosed June 12 unauthorized access stemming from a compromised legacy integration credential, involving Salesforce and other platforms, and coordinated response with CrowdStrike.
Protos06-24-2026
LastPass warned that a Klue-linked attack stole personal information tied to Klue-integrated systems, alongside phishing and social-engineering threats.
All About Cookies06-26-2026
LastPass disclosed a 2026 Klue-origin breach that exposed customer PII linked to Salesforce accounts and prompted token rotation and law enforcement notice.
Hackread06-23-2026
LastPass reported that stolen Klue OAuth tokens enabled unauthorized access to Salesforce-stored CRM data after Klue notified customers on June 12, 2026.
Cybersecurity Dive07-08-2026
A threat actor using handle 888 claims early-July data theft from Accenture, allegedly including source code and Azure tokens, RSA and SSH keys.
HookPhish05-28-2026
ShinyHunters named Kemper Corporation in an April 2026 pay-or-leak extortion incident after alleged social-engineered access to a Salesforce environment.
QPulse06-23-2026
LastPass notified June 12 of a Klue third-party incident in which compromised OAuth tokens may have enabled access to LastPass customer data in Salesforce.
The CyberWire06-26-2026
Klue reported an integration infrastructure breach enabling OAuth token-based access to enterprise customer data environments, with related impacts and other privacy-relevant ransomware disclosures in the same period.
StreetInsider06-23-2026
8x8 disclosed June 2026 unauthorized access through a Klue Labs integration with Salesforce, exfiltrating customer CRM data and triggering regulatory notification.
CSO Online / Ron Baklarz07-22-2026
Klue, a Vancouver-based SaaS provider, faced a 2026 supply-chain breach using OAuth token harvesting that exposed downstream customer data through privileged integrations.
Femto Security06-23-2026
ZenBusiness customer data exposure occurred after OAuth Device Flow authorization abuse and MFA bypass, according to an incident analysis dated June 23, 2026.
Quick Intelligence / Felicia Gopi07-21-2026
ShinyHunters published alleged Madison Square Garden Entertainment Salesforce CRM data in June 2026 after social engineering led employees to approve malicious OAuth connected apps.

⭐⭐⭐

BleepingComputer / Lawrence Abrams07-07-2026
Accenture confirmed a breach in response to threat actor 888 claims in July 2026 of 35 GB of source code and credential data stolen and sold online.
TechCrunch06-22-2026
Klue reported that cybercrime group Icarus claimed responsibility for a June 12 breach involving compromised integration credentials that exposed customer cloud data in Vancouver.
TechCrunch06-23-2026
LastPass disclosed theft of customer personal data and support records from a Klue vendor breach, with Klue identified intrusions on June 12 and Icarus demanding ransom.
Fast Company / Jennifer Mattson06-24-2026
On June 12, Klue notified LastPass that stolen OAuth tokens enabled unauthorized access to LastPass customer data in a Salesforce environment.
Yahoo Finance / Bailey Pemberton06-26-2026
Salesforce disabled the Klue Battlecards integration after a breach exposed customer data through stolen OAuth token access via the Salesforce API.
Cybernews06-24-2026
LastPass notified customers in a breach tied to Klue after June 12 discovery, involving OAuth-token access to Salesforce-linked customer CRM data.
Forbes07-16-2026
LastPass warned in response to a phishing campaign using lookalike domains and fake compliance notices that direct users to a fraudulent site to steal credentials.
Yahoo07-16-2026
LastPass identified a July 13 phishing campaign using DocuSign and lookalike domains to impersonate security compliance and steal user credentials.
9to5Mac / Marcus Mendes06-23-2026
LastPass notified users after a Klue vendor breach exposed customer information and support case data, with LastPass revoking access and rotating API tokens in response.
Yahoo Tech / Pranob Mehrotra06-27-2026
LastPass disclosed a Klue vendor breach that exposed customer contact data and support case records while keeping encrypted vaults secure.
CybelAngel07-13-2026
CybelAngel investigated a July 6, 2026 PwnForums sale listing by threat actor 888 alleging Accenture credential exposure, and Accenture confirmed remediated impact on July 8.
The Tech Buzz06-24-2026
LastPass disclosed a vendor-supplier security incident in which contact data and personal metadata were exposed, with potential GDPR and CCPA notification implications.
OffSeq07-08-2026
Accenture confirmed a hacker-claimed 35 GB data breach after an exfiltration claim involving Azure access keys and private keys.
Cybersecurity Insiders / Naveen Goud07-09-2026
Accenture disputed an alleged 35GB data theft claim by hacker 888 and reported limited unauthorized access while ongoing monitoring and security review continue.
Digital Trends06-24-2026
LastPass said a Klue third-party breach exposed customer contact details and support tickets, while password vault credentials were not compromised.
Databreaches06-21-2026
Klue disclosed unauthorized activity discovered June 12, after OAuth token theft and compromised Battlecards integrations enabled Salesforce CRM data exfiltration claimed by Icarus.
MarketWatch04-22-2026
Kemper Corporation confirmed a cybersecurity incident after ShinyHunters posted alleged customer and employee data reportedly stolen from a Salesforce account on April 15, 2026.
ZDNET / Lance Whitney06-24-2026
LastPass disclosed a Klue third-party breach on June 12 that exposed customer contact and CRM data through stolen OAuth tokens used with Salesforce and Gong.
CRN07-08-2026
Accenture confirmed an isolated breach in response to July 6 forum claims by threat actor 888 about the sale of 35 GB of source code and credentials.
PR Newswire04-21-2026
ShinyHunters posted alleged Kemper Corporation data on April 15, 2026, claiming a 29 GB Salesforce account theft as Kemper launched an investigation and notified law enforcement.
The National Law Review04-13-2026
Murphy Law Firm investigates potential class action in response to a Kloeckner Metals Corporation data breach reported on February 23, 2026.
PR Newswire04-13-2026
Kloeckner Metals Corporation, after discovering unusual network activity on February 23, 2026, faced Maine-connected claims that a third party accessed files containing names and Social Security numbers.