Cloud Integrations and Identity Breaches
Coverage from SecurityWeek, Morningstar, and others
Articles
49
Active Days
101
The Topic

The topic centers on cyberattacks that abuse trusted cloud connections, exposed credentials, and convincing impersonation to reach enterprise or personal data. A Klue integration compromise enabled unauthorized access to connected Salesforce environments and led to extortion claims, while separate incidents involving Accenture and The Credit Pros raised concerns about source code, credentials, and sensitive personal information. Phishing campaigns targeting LastPass and Bitwarden users show the same broader reliance on identity and trust-based attack paths, although the incidents are not attributable to a single campaign.
First Article: 04/13/26
Latest Article: 07/22/26
Summary
- Attackers compromised Klue integration infrastructure and used stolen OAuth tokens to query multiple customer Salesforce environments.
- Salesforce disabled the Klue Battlecards connection while affected organizations revoked tokens, disabled integrations, and investigated data exposure.
- The Icarus extortion group claimed responsibility for the Klue-related theft and pressured victims through leak-site and Session-based communications.
- Accenture confirmed a breach after a threat actor offered approximately 35 GB of alleged source code, keys, tokens, and configuration data for sale.
- The Credit Pros incident may have exposed financial and identity information held in a Salesforce environment, but the available evidence is based partly on threat-actor and legal-investigation claims.
- Fake LastPass and Bitwarden notices redirected users to malicious sites, demonstrating continued phishing against password-manager customers without evidence that either provider was breached.
History
The biggest update is operational: Salesforce disabled the Klue Battlecards connection, and affected organizations began revoking tokens and disabling integrations. The Klue and Accenture items also gained sharper attribution and scale details, but the overall story remains a cluster of related trust-based cyber incidents.
The story broadens from a Salesforce/OAuth breach cluster into a wider set of enterprise compromise and phishing incidents, with new named cases and actors. The most notable new development is Accenture's confirmed breach alongside allegations of stolen source code and cloud credentials, plus renewed phishing impersonation of password-manager brands.
