Klue, a market intelligence platform that connects to customer Salesforce systems to sync sales and competitive data, was breached on 11 and 12 June 2026. The Icarus extortion group did not break into Klue's customers. They took the standing access Klue already held inside those customers' Salesforce systems, the integration permissions Klue was always supposed to have, and used that legitimate connection to copy customer lists, contacts, pricing, and deal notes straight out.
About a dozen organisations have confirmed impact so far, including LastPass, BeyondTrust, Snyk, Tanium, Recorded Future, and HackerOne. Several of those companies sell security software for a living. None of their own defences were tested. The weak point was a vendor they had connected and trusted years earlier, and most likely forgotten about.
Nobody picked a lock. Nobody needed a password.
This week's executive cyber risk briefing from TXAZ Consulting Services puts it plainly: the attacker carried a valid key that made the access look entirely legitimate. To Salesforce, to the victim companies, every action Klue's stolen access performed looked exactly like Klue doing its normal job. That is what makes this category of breach so difficult to catch through identity controls alone. Identity verified correctly. The identity was simply no longer in friendly hands.
Within days of the first extortion attempt, a second, unrelated criminal group surfaced claiming to hold the same stolen data and threatening to publish the names of nearly 200 companies unless paid. One breach is now being monetised twice. Paying the first attacker bought no certainty that the data would not surface anyway.
The recommended fix addresses how often this happens. It does not address what happens when it does.
The briefing's guidance for executives this week is sound and worth following: pull a written inventory of every third party application connected to your core systems, revoke anything unrecognised or unused, and add two standing questions to every vendor relationship, what access does this company keep to our data, and would paying a ransom actually end our exposure.
That guidance reduces the number of forgotten, unmonitored standing connections sitting inside an organisation's systems. It is necessary. It is also entirely upstream of the moment that actually caused the damage. An inventory tells you what access exists. It does not stop that access, once stolen, from being used to copy a customer database out the door.
The attacker's identity was never the problem. The action was.
Klue's access was real, properly provisioned, and exactly what Salesforce's own permission model expected to see. No anomaly in credentials, no failed login, nothing for an identity governance tool to flag. What changed was not who was asking. It was what they were asking for, a bulk export of customer relationship data, at a volume and pattern a single legitimate sync job would never normally need.
That is the specific kind of action that does not need to be tied to identity at all to be caught. A bulk extraction of customer records, regardless of which application, vendor, or credential initiates it, is a destination, not a path. Gate that destination, require a named human inside the organisation to confirm before that volume of customer data leaves the system, and it does not matter whether the request comes from Klue acting normally, Klue's stolen credentials acting maliciously, or an integration nobody remembers approving five years ago. The export does not complete without that confirmation.
The same pattern, one week later, in hardware.
The same briefing flags a second story that follows the identical logic. US authorities gave federal agencies a 26 June deadline to fix actively exploited flaws in Ubiquiti UniFi network equipment, gear that sits quietly at the edge of office networks in a large share of small and mid-market firms. A fix has existed since May. Attackers are using the flaw to plant hidden administrator accounts and move deeper into the network from there.
A hidden administrator account is a foothold, not the damage. The damage happens when that account is used to do something, move laterally, exfiltrate data, change a configuration that matters. The briefing's own framing is exact: the gap is not a missing patch, it is the absence of anyone accountable for applying one, and the equipment is wired into the rest of the network in a way that bypasses most of the security spending sitting behind it.
Two breaches, one week, the same underlying lesson stated twice. Identity and access inventories tell an organisation what could go wrong. They do not stop the specific action that turns access into loss. A named human confirming a bulk data export, or a critical configuration change, before it completes, holds regardless of whether the request came through a forgotten integration, a stolen key, or a hidden admin account nobody knew existed.
The vendor was trusted. The credential was valid. The data still left the building.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Hoffman, Tim. The Risk Lens: Executive Cyber Risk Briefing, Week 26. TXAZ Consulting Services LLC, 26 June 2026.
