Unauthorized OAuth Token Compromise in Klue Marketing SaaS Integration Exposes Recorded Future Salesforce Data
What Happened — On June 12‑13 2026, Recorded Future’s CSIRT was notified that the marketing SaaS vendor Klue experienced unauthorized access to the integration layer that connects Klue with other marketing and sales platforms. The attacker leveraged a compromised OAuth token used for the Klue‑Salesforce integration, resulting in limited exposure of Recorded Future’s Salesforce business‑contact fields and possibly contract information. No core Recorded Future systems or customer‑platform data were accessed.
Why It Matters for Compliance & Audit Readiness —
- This scenario directly tests SOC 2 vendor‑management controls (CC6.1 – CC6.2) that require continuous monitoring of third‑party access tokens and integration points.
- Maintaining audit‑ready evidence of token revocation, log correlation, and third‑party risk assessments satisfies the Security and Availability principles.
- Verisq’s Vendor Risk capability can automate continuous verification that SaaS integrations remain within approved risk tolerances, providing defensible audit artifacts.
Who Is Affected — Technology‑SaaS providers that rely on third‑party marketing or sales integrations; specifically Recorded Future and its Salesforce‑based business data.
Recommended Actions —
- Inventory all OAuth tokens and SaaS integrations; map each to SOC 2 vendor‑management controls.
- Deploy automated token rotation and revocation workflows with immutable log storage for audit evidence.
- Conduct a post‑incident third‑party risk review and update contractual security clauses with vendors. Source: https://www.recordedfuture.com/blog/klue-security-incident-jp
Technical Notes — The breach stemmed from a compromised OAuth token in the Klue‑Salesforce integration layer; no public CVE is associated. Exfiltrated data included contact names, email addresses, and potentially contract identifiers stored in Salesforce. Source: https://www.recordedfuture.com/blog/klue-security-incident-jp