The Weakest Link Was Never You

Two overlapping extortion crews spent June running the same play, and it worked every time: get into a company's Salesforce environment — usually through a stolen OAuth token or a compromised third-party integration — and walk out with the data. The crew Huntress tracks as "Icarus" hit the Klue supply chain; LastPass confirmed customer data taken that way. A separate group, ShinyHunters, ran the broader Salesforce spree — Kodak, Oracle PeopleSoft, the Council of Europe, 137,000 school-staff accounts through Infinite Campus.

Notice what none of those are: a user picking a bad password.

There is no such thing as a data breach without a point of failure, and in this wave it's the same one nobody wants to audit — the trust a company hands to its vendors, and the trust those vendors hand to theirs. An OAuth token is a key. Companies have been minting keys to your data and handing them to third parties with a fraction of the scrutiny they'd apply to their own front door.

When LastPass — a company whose entire product is "trust us with every key you own" — gets reached through a supply-chain partner, the lesson isn't "pick a better password manager." It's that the industry keeps selling you personal responsibility while the real failures happen three vendors upstream, where you have no vote and no visibility.

So what do you actually do?

  • Assume the token economy already leaked you. Rotate what you can; turn on hardware 2FA wherever it's offered.
  • Treat every "we take your security seriously" notice as the start of a question, not the end of one: who did you hand a key to, and who did they hand it to?
  • For anything you run: inventory your OAuth grants and third-party integrations like they're doors. They are.

The breach isn't bad luck. It's a decision someone made to trust a vendor they never checked. You just weren't in the room.

Sources: BleepingComputer; Huntress (Icarus attribution); CISA KEV.