Attackers took data from more than a dozen companies in June without cracking a single password. They used access a vendor was already holding. Here's the list to pull.
In June, attackers copied customer records out of more than a dozen companies — including LastPass, Tanium, Recorded Future and the security firm Huntress. No password was cracked. No multi-factor code was intercepted. Nobody clicked a bad link.
The attackers had a key that a software vendor was already holding on those companies' behalf.
The vendor was Klue, a sales-research tool that plugs into its customers' Salesforce accounts. Klue's CEO wrote that an attacker got in through "a compromised legacy credential associated with an integration service" and used it to grab the access tokens Klue held for its customers. Huntress, which published its own account, described that credential more plainly: it was a long-disused but still active login Klue had created to prototype an integration it later abandoned, as reported by The Hacker News.
You probably don't use Klue, and you may not use Salesforce. Here's why this is still your problem.
Every "Connect" button leaves a key behind
Think about the last time you hooked something up to Microsoft 365. A scheduling tool that reads your calendar. An e-signature service. An AI notetaker that joins your Teams meetings. A bookkeeping app that pulls invoices out of email. Each one showed a permissions screen, somebody clicked Accept, and it worked.
That grant doesn't expire when you stop using the tool. It doesn't expire when the person who approved it leaves. It sits there — a standing key to your mail, your files, or your contacts, held by a company you may not have thought about in two years.
Security researchers at ReliaQuest put the problem well in their analysis of the Klue attack, quoted by The Hacker News: these integrations "are non-human identities with persistent, often broad access to sensitive data, yet they are typically monitored far less closely than employee accounts."
That's the part worth sitting with. You almost certainly have a rule about what happens to a departing employee's account. You probably have nothing at all about the accounting trial you abandoned in 2024.
Why nobody notices
When an attacker uses a legitimate integration's key, the activity looks like the integration doing its job. There's no failed login to alert on, no sign-in from a strange country, no "unusual activity" email. In one Klue-affected environment, ReliaQuest counted almost a thousand automated queries in fifteen minutes; in another the data pull ran for more than six hours. It looked like software being software.
Microsoft has been documenting this pattern for a year. Its July 13 research traces three vendor compromises — Salesloft in August 2025, Gainsight in November 2025, Klue in June 2026 — that all worked the same way: no vulnerability in the platform, just abuse of a trusted connection. Microsoft's own new tooling for this flags apps that have been inactive for 90 days or more, which tells you what it thinks the actual risk is. Not malicious apps. Forgotten ones.
Three things worth doing
Get the list. In the Microsoft Entra admin center — the identity side of Microsoft 365 — go to Entra ID, then Enterprise apps, then All applications, and open the Permissions tab on anything you don't recognise. If you'd rather not poke around, ask your IT provider for this by name: "send me every enterprise application in our tenant with its consented permissions, both admin consent and user consent." That's a request they can fill in an afternoon, and the answer is usually longer than owners expect.
Revoke the dead ones. Anything nobody has used in months should lose its access. Be aware of a wrinkle worth flagging to whoever does this: Microsoft's documentation notes that org-wide admin consent can be revoked with a couple of clicks in the portal, but permissions an individual user granted can only be removed with a script. Ask for both.
Decide who gets to say yes next time. By default, staff can approve some app permissions themselves. You can narrow that to apps from verified publishers, or route every request to an admin. Fifteen minutes of settings, once.
And when a supplier announces a breach, the question to ask has changed. Not "was our password stolen?" but "were you holding a key to any of our systems, and have you revoked it?"
Knowing which apps hold standing access to your Microsoft 365 is one of the things a read-only scan is good at — Tenant Strike checks it alongside a hundred-odd other settings and grades the result. But you don't need us to pull the list. You need somebody to actually look at it.
AI-researched from public sources. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike finds the security gaps in your Microsoft 365 and Azure, shows how they chain into a real break-in, and hands you a plain-English fix for every one — read-only, and it never asks for permission to change anything. Start a 7-day Pro trial — no credit card.