Threat actors compromised Klue’s OAuth tokens and used them to extract Salesforce CRM data from multiple enterprise customers, without breaking through security perimeters directly. Instead they leveraged a legitimate integration’s credentials to run unauthorized bulk queries, revealing gaps in supply chain security monitoring for approved integrations.