Klue Breach Highlights Vulnerabilities in SaaS Integrations and Third-Party Cyber Risk
The cybersecurity landscape has been shaken by a breach involving Klue, a Vancouver-based software-as-a-service (SaaS) company. The incident began as a supply chain breach by the Icarus criminal group, which exploited an unused service account credential to access Klue's integration infrastructure. This allowed the attackers to harvest OAuth tokens, granting them extensive access to customer environments. The breach escalated when a second criminal group claimed to have compromised Icarus, further complicating the situation. Klue, which provides an AI-powered competitive intelligence platform, serves over 500 customers and integrates with major platforms like Salesforce and HubSpot. The breach exposed significant weaknesses in SaaS integrations, identity-based trust, and third-party risk management.