Klue SaaS breach exposes critical third‑party cyber risk
In 2026 the Vancouver‑based SaaS provider Klue suffered a supply‑chain breach when the Icarus criminal group exploited an unused service‑account credential to harvest OAuth tokens used for integrations with platforms such as Salesforce and Slack. The attackers gained the same permissions Klue held in customer environments, highlighting fundamental weaknesses in identity‑based trust, SaaS integrations and third‑party risk management.
A concurrent Gen Digital threat report for the first half of 2026 shows a broader shift in cybercrime toward exploiting trusted digital experiences. The report documents millions of blocked e‑shop scams, tech‑support scams, government‑impersonation attacks and massive advertising fraud across the EU, UK and African markets. It stresses that modern attackers manipulate legitimate platforms, messaging services and AI agents, requiring layered security that protects devices, applications, data and digital identities.
Together, the Klue incident and the Gen Digital findings illustrate how attackers are targeting the trust inherent in cloud services and digital workflows, prompting organisations worldwide to reassess third‑party risk controls and adopt more comprehensive cyber‑defence strategies.
Entities: Avast · Gen Digital · Icarus criminal group · Klue