A threat actor group called Icarus exploited a compromised Klue-Salesforce integration to steal millions of CRM records from multiple organizations. Attackers gained access through a stale legacy credential, inserted backdoor code, and leveraged OAuth tokens to exfiltrate data. The incident shows how over-permissioned third-party integrations create supply chain attack vectors.