Salesforce disables Klue integration after OAuth token theft

Colleagues, a cybersecurity alert: Salesforce disabled the Klue app after an incident in which OAuth tokens were stolen, resulting in customer data exfiltration.
What happened: an attacker used legacy Klue credentials to obtain OAuth tokens and, via integrations, exported CRM records.
Impact: contacts, commercial communications and sales data were exfiltrated; affected parties report payment and engineering data remain unaffected.
Response: Klue revoked tokens, removed unauthorized code and closed remote access; Salesforce temporarily disabled the integration.
Why it matters: third‑party integrations with broad permissions require enhanced monitoring.
What practices do you use to protect integrations and monitor OAuth tokens?
#cybersecurity #OAuth #integrations #CRM

