Last Update: 08/01/2026 at 2:00 PM EST

Cloud Integrations and Identity Breaches

Coverage from SecurityWeek, Morningstar, and others

Articles

49

Active Days

101

The Topic

Cloud Integrations and Identity Breaches topic image

The topic centers on cyberattacks that abuse trusted cloud connections, exposed credentials, and convincing impersonation to reach enterprise or personal data. A Klue integration compromise enabled unauthorized access to connected Salesforce environments and led to extortion claims, while separate incidents involving Accenture and The Credit Pros raised concerns about source code, credentials, and sensitive personal information. Phishing campaigns targeting LastPass and Bitwarden users show the same broader reliance on identity and trust-based attack paths, although the incidents are not attributable to a single campaign.

First Article: 04/13/26

Latest Article: 07/22/26

History

07/23/20260 new articles

The biggest update is operational: Salesforce disabled the Klue Battlecards connection, and affected organizations began revoking tokens and disabling integrations. The Klue and Accenture items also gained sharper attribution and scale details, but the overall story remains a cluster of related trust-based cyber incidents.

07/21/20261 new articles

The story broadens from a Salesforce/OAuth breach cluster into a wider set of enterprise compromise and phishing incidents, with new named cases and actors. The most notable new development is Accenture's confirmed breach alongside allegations of stolen source code and cloud credentials, plus renewed phishing impersonation of password-manager brands.

  • Accenture confirmed an isolated breach involving alleged source code and cloud credentials.
  • The Credit Pros may have exposed customer personal and financial data.
  • Bitwarden users were targeted by fake security notices.
  • Icarus claimed responsibility for the Klue-related extortion campaign.
  • The story now includes cloud access keys and configuration files for sale.
07/17/202611 new articles

The story has broadened from a single Klue-linked integration breach into a wider cluster of Salesforce-adjacent privacy and legal incidents, with Kemper and Kloeckner now joining the picture. The framing also shifts from one vendor compromise to a broader SaaS and phishing threat landscape tied to credential abuse and downstream data exposure.

  • Kemper and Kloeckner are now part of the story.
  • Edelson Lechtzin LLP is investigating potential class actions.
  • LastPass is tied to impersonation phishing, not confirmed backend compromise.
  • ShinyHunters is linked to the Kemper-related incident.
  • Some exposures now include Social Security numbers and partial card details.
06/22/20264 new articles

The story has sharpened from general Salesforce-linked breach activity into a more specific pattern of OAuth token theft through trusted vendor integrations, with Klue now central to the mechanics. The current version also adds more explicit security-firm reporting and emphasizes token revocation, integration shutdowns, and legal fallout as recurring responses.

  • OAuth token theft through vendor integrations is now the main breach pattern.
  • Klue is newly identified as a central integration point in the incidents.
  • Attackers used scripted API queries to bulk-extract CRM data.
  • Containment actions included disabling integrations and revoking tokens.
  • Security firms Huntress and ReliaQuest add detailed reporting on attacker methods.
06/19/20263 new articles

The story has broadened from generic breach notifications into a more specific Salesforce-centered campaign involving cloud CRM abuse, extortion, and dark web posting. New threat-actor labels and a new vendor-related intrusion make the operational access path more concrete and the risk more coordinated.

  • The Credit Pros was newly added as a Salesforce-related breach victim.
  • ShinyHunters and Icarus are now named threat-actor labels.
  • Klue was newly implicated in OAuth-based Salesforce data theft.
  • Extortion is now part of the described attack pattern.
  • The timeline is now concentrated in April to June 2026.
05/11/2026Topic Formed

Recent coverage is dominated by corporate breach notifications tied to exposed personal information, dark web leak claims, and law-firm investigations into potential class actions. The repeated pattern is unauthorized access to company systems or vendor accounts, followed by notice, internal investigation, and fraud-risk warnings for affected people.