Skip to main content
Back to overview
High

Sprout Social Salesforce CRM Data Accessed via Klue Security Incident

LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances.

Key points

  • Unauthorized access to Sprout Social's Salesforce CRM system through a compromised Klue integration.
  • Threat actor obtained credentials associated with Klue's integration.
  • Access occurred between June 11 and June 12, 2026.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 17, 2026
Updated
Jul 22, 2026
Confidence
High
Evidence
7 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

SproutsocialData DisclosureAccessedKlueSalesforceIcarusOAuthSalesforce. IcarusSalesforce and GongLastPass

Quick context

Questions about this signal

What happened in this signal?

LastPass is the latest cybersecurity firm to have disclosed the impact from the Klue hack, which resulted in unauthorized access to customers’ Salesforce instances. A threat actor calling itself Icarus used a compromised legacy credential to access Klue’s systems and generate OAuth tokens to breach third-party platforms Klue integrates with, such as Salesforce. Icarus then accessed the connected Salesforce instances and exfiltrated data in bulk , using automated scripts. Salesforce and Gong have disabled the Klue integration in response to the attack, and over a dozen organizations have already confirmed the impact. Incident notifications from the affected companies reveal that the attackers accessed business data accessible through the Klue integration, and that no internal systems were compromised. LastPass’s notice follows the same lines: “The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” The company says it has discontinued access to Klue, rotated exposed tokens, notified law enforcement, and launched an investigation together with Klue and Salesforce. Advertisement. Scroll to continue reading. “It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” LastPass said. This week, in addition to LastPass, 8×8 and Pendo announced they were affected. Late last week, HackerOne, Huntress, Insurity, Jamf, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium disclosed the impact from the attack. BeyondTrust also said business contact and sales-related information was stolen from its Salesforce instance, but the notification went unnoticed. On its Tor-based leak site, Icarus has listed several organizations as having their Salesforce data stolen, including Swiss AI communications solutions provider Gms-net. SecurityWeek has emailed the technology company for a statement and will update this article if it responds. Icarus’s website is currently down but, before becoming inaccessible, it listed at least four other companies that have yet to publicly disclose being affected by the Klue incident, which brings the number of victims to roughly 15. Per Huntress’s estimates, however, numerous other Klue customers were likely impacted by the data breach and are expected to come forward. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: OpenAI Refocuses Cybersecurity Efforts on Patching Over Discovery Related: Russian Initial Access Broker Behind FortiBleed Campaign Related: Canadian Electricity Provider London Hydro Discloses Data Breach Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

When was this signal reported?

Shadow Tier lists Jun 17, 2026 as the signal date.

Which organization is connected to this signal?

Sproutsocial is the organization connected to this public signal.

Explore Sproutsocial
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence