Two of the biggest names in threat intelligence got robbed through a sales tool, and not one firewall fired.

On June 11, 2026, Salesforce yanked the Klue Battlecards integration from its platform after attackers abused OAuth tokens tied to the competitive-intelligence vendor. The fallout reached Klue’s customer list, which includes Huntress and Recorded Future, two companies whose entire business is telling everyone else how attackers get in. When the people who sell cybersecurity get their CRM data exfiltrated through a third-party app they barely think about, the lesson is not about their failure. It’s about a standing door every one of us left open.

Illustration of a software supply chain attack flowing through a connected vendor
The attack came through a trusted integration, not the front door.

The token was the key, and nobody was watching it

Here’s how this works. You connect a SaaS app to Salesforce. You click “Allow.” Salesforce hands that app an OAuth token, which is a long-lived credential the app uses to read and pull your data on your behalf. No password prompt after that. No MFA challenge. The token just works, quietly, until somebody revokes it.

Klue got compromised. The attackers grabbed those tokens and used them exactly as designed, to query and exfiltrate data from the Salesforce instances of Klue’s customers. From Salesforce’s logs, this traffic looked like Klue doing its normal job. There was nothing to brute-force, no login to trip an alarm, no malware on anyone’s endpoint. The integration was the attack surface, and the integration was trusted by definition.

This is the part that should keep IT leads up at night. Your threat detection stack is tuned to watch users and devices. It is rarely tuned to watch the dozens of machine identities you’ve granted standing access to your crown-jewel SaaS data. Those tokens don’t sit behind your firewall. They sit in some other company’s infrastructure, governed by some other company’s security hardening, and you inherited all of their risk the moment you clicked “Allow.”

SaaS-to-SaaS trust is the surface you never inventoried

Defense in depth was built for a world where data lived on servers you controlled. That world is gone for most teams. Your sensitive records live in Salesforce, your conversations live in a chat platform, your code lives in a Git host, and all three are stitched together by integrations you approved years ago and forgot.

Every one of those connections is a credential that bypasses your perimeter. The Klue incident is the same pattern that hit Salesforce customers through other OAuth-connected apps over the past two years. A vendor gets popped, the attacker harvests the tokens, and the tokens unlock everyone downstream. The breach scales through trust relationships, not through your network.

And the ugly truth about cyber security in a SaaS-heavy shop is that most organizations cannot answer a basic question: which third-party apps currently hold an active token to our most sensitive systems, and what can each one actually reach? If you can’t list them, you can’t monitor them, and you definitely can’t revoke them in a hurry when a vendor sends you a breach notice at 5 PM on a Friday.

Salesforce logo representing the disabled Klue app integration
Salesforce disabled the Klue integration platform-wide while the incident played out.

Own your integrations before a vendor owns them for you

You can’t patch a vendor’s breach. You can shrink what it costs you. Start today with the connections you’ve already approved.

  • Inventory every OAuth grant. Pull the connected-apps list from Salesforce, Google Workspace, Microsoft 365, and your Git host. For each app, record who approved it, what scopes it holds, and when its token last got used.
  • Cut the scopes. Most integrations request far more than they need. Downgrade read-write grants to read-only where the workflow allows, and kill any app nobody can explain.
  • Revoke the dormant tokens. If an integration hasn’t made an API call in 90 days, it is risk with no upside. Pull it.
  • Watch the machine identities. Build threat-protection alerts for abnormal API volume from a connected app, especially bulk record exports. That’s your only signal when the credential itself is legitimate.
  • Restrict who can approve apps. Default-deny user-consented integrations so a single employee can’t quietly hand a stranger your CRM.

The ongoing work is harder and matters more. Treat third-party OAuth tokens as Tier 0 credentials and rotate them on a schedule, not just after an incident. Subscribe to security advisories for every vendor holding a token, because that 5 PM email is your starting gun. And rehearse the response: when a SaaS provider tells you they’ve been breached, your team should already know which integrations to revoke, which data those apps could reach, and how to tell your customers before the headline does. Incident response that assumes the compromise came through a trusted partner is no longer a tabletop exercise. It’s the most likely Tuesday you’ll face.

The firms that got hit here are good at this. That’s the point. If borrowed trust can empty their Salesforce, it can empty yours, and the only defense you fully own is knowing exactly what you’ve delegated and to whom.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.