AI-powered market research platform Klue describes its dynamic battlecards for sales teams as โan essential weapon for reps facing tough competition and savvy buyersโ. Sadly, it has discovered that hackers also like the weapon analogy, with several of its customers falling victim to an attack through its integrated systems.
Although the actual extent of the attacks is yet to be determined, we know cybersecurity vendors are among them. One of the most notable is password manager LastPass, which has confirmed that the attackers were able to โaccess LastPass customer data within our Salesforce environmentโ. Data that may have included โcustomer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related dataโ.
The newly discovered Icarus ransomware and extortion group, first observed in the wild earlier this month, has claimed responsibility for the attack. โWe advice (sic) Klue to contact us for a swift resolution, in order not to affect the companies you work with,โ the group demanded, adding that if Klue didnโt โaccommodate this request, we advice (sic) the companies who want to protect their data to contact usโ.
Example of a Klue Battlecard (image: Klue)
Response from Klue, LastPass and Salesforce
Klue CEO Jason Smith has since released a statement to update customers on the incident, first identified on 12 June, when unauthorised activity was found in โa portion of Klueโs integration infrastructureโ.
The attackers gained access โthrough a compromised legacy credential associated with an integration service,โ Smith said, which I understand to be the Battlecards app, that then enabled attackers to โobtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environmentsโ.
Salesforce, for its part, has said it has โdisabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident.โ
โThere is no evidence that customer content stored within the Klue platform was impacted,โ Smith said, adding that โspecific remediation guidance has been shared directly with affected customersโ.
LastPass has also contacted affected customers while confirming that โLastPass products, services, and infrastructure were not impacted in any way and customer vaults remain secureโ.
How to fight Klue attacks… and similar
Josh Picolet, VP of Detection & Analysis at Team Cymru, told me that the most important lesson from the Klue incident is that attackers are increasingly targeting the connective tissue between organisations rather than the organisations themselves.
โThird-party platforms often sit at the centre of large networks of trust,โ Picolet said, โmaking them attractive targets because a single compromise can create downstream access to dozens or hundreds of victims.โ
โYour security is now only as strong as the third-party apps you have granted standing access to your CRM,โ Sunil Gottumukkala, CEO, at Averlo warned, โand most teams donโt actively track those integrations.โ
I will leave the last words to Denis Calderone, CTO, Suzu Labs, who pointed out that there have now been three Salesforce OAuth supply chain attacks in under a year, from two different threat actors, using the same playbook.
โAt this point, we have to accept that this particular attack pattern has been successfully commoditised,โ he said.
In terms of mitigation? โIf you’re a Klue customer, rotate every OAuth token tied to that integration, and don’t limit yourself to Salesforce. If Klue had an OAuth connection into your Slack, your Google Drive, or anything else, treat those tokens as compromised and rotate them now.โ
The real takeaway here, though, is that every organisation must audit all connected apps for any dormant integration credentials, paying particular attention to automating alerts for abnormal API query volumes from third-party services.
โIf a connected app that normally syncs a few hundred records starts pulling thousands of queries in minutes,โ Calderone concluded, โthat’s your early warning.โ
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.