
Customer Data Stolen from Companies Using Klue and Salesforce
Hackers broke into Klue, a business intelligence platform, and used that access to steal customer information from companies that use Salesforce.
Source
BleepingComputer
Original headline: Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
Plain-English summary by GetCyberRight. Read the full report at the source above.
A company called Klue, which provides market intelligence services to businesses, experienced a security breach.
Hackers used a technique involving OAuth, which is the system that lets you log into one service using your account from another service. The attackers, who call themselves Icarus, broke into Klue and then used that access to steal data from Salesforce accounts. Salesforce is a widely used customer management system that stores contact information, sales records, and business data. This affects people whose information is stored in the Salesforce systems of companies that use Klue.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If you are a customer of a business that uses both Klue and Salesforce, your contact details, purchase history, or other information they keep about you may have been stolen. The hackers are reportedly using this stolen data for extortion, meaning they may threaten to release it unless companies pay them. If you receive a notice from any company saying your data was part of this breach, take it seriously.
Here is what to do:
- Read the notice carefully to understand exactly what information was exposed.
- Watch your email and phone for suspicious contacts from people claiming to be from companies you do business with.
- If the exposed data included financial information, monitor your bank and credit card statements for unusual activity.
- Consider placing a fraud alert on your credit report by contacting one of the three major credit bureaus. This breach highlights why it matters which companies you trust with your information. When possible, limit what personal details you share with businesses. Ask companies about their data security practices. The more places your information lives, the more opportunities exist for it to be stolen. Stay alert for breach notifications and act quickly when you receive them.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Your School Records May Have Been Exposed: Global Schools Group Data Breach
A major data breach at Global Schools Group has exposed student and employee records. Parents should check if their children's schools are affected.
2 min readGlobal Schools Group Data Breach: Your Child's School Records May Be Exposed
A major data breach at Global Schools Group may have exposed student and employee records. Parents should find out if their school was affected.
2 min read
Business Data Theft Campaign Targets Companies Using Salesforce: Check Your Accounts
Hackers called Icarus are stealing customer data from companies by breaking into their Salesforce accounts, then demanding ransom payments.
2 min readWhy Faster Software Updates Don't Always Mean Better Security
A major cyberattack exposed how the rush to release software quickly is creating dangerous security gaps that threaten the apps and services families use every day.
4 min read