leaksear.ch indexes 646,776 Huntress records, the leaksear.ch indexed count, from Salesforce CRM and sales-related data tied to the June 2026 Klue integration compromise (leaksear.ch metadata). Public sources describe a broader third-party OAuth incident involving Klue connected apps, while this replacement article focuses only on the Huntress leak source and field inventory reflected in leaksear.ch metadata Klue incident update.
What happened
leaksear.ch metadata lists June 16, 2026 as the breach date for this Huntress leak source and July 4, 2026 as the date indexed. Public incident timelines describe upstream activity before that date: Klue said it identified unauthorized activity affecting part of its integration infrastructure on June 12, and a later Klue CrowdStrike summary said a threat actor used a previously compromised GitHub personal access token on June 11 to introduce unauthorized code into Klue's integration service and collect third-party integration credentials, including Salesforce OAuth access and refresh tokens Klue CrowdStrike investigation summary.
Klue said the attacker used OAuth tokens to access certain third-party platforms, including Salesforce, and then data within connected customer environments, with no evidence that customer content stored inside the Klue platform was impacted Klue incident update. Salesforce posted a June 17 advisory saying it disabled the connection between the Klue Battlecards app and Salesforce after detecting unusual activity, and said the issue was limited to Klue's app connection rather than a Salesforce platform vulnerability Salesforce Trust advisory.
Huntress reported that the copied data from its Salesforce account included business contacts, price quotes, and other sales-related data and messaging, and it said Huntress products, infrastructure, telemetry, passwords, and payment card information were not impacted Huntress investigation. Huntress later said data listed for Huntress on June 22 aligned with the scope it had previously shared, including business contact information, business names, product trial or usage data, subscription units and pricing, sales-related communications, and opportunity notes Huntress investigation. No reporter is listed for this leak source in leaksear.ch metadata.
What data was exposed
The leaksear.ch indexed count is 646,776 records for this Huntress leak source (leaksear.ch metadata). The searchable fields are: address, country, email, name, phone, and username (leaksear.ch metadata).
Other stored fields are grouped below for readability and are not described as searchable:
- CRM and Salesforce identifiers: account_id, campaign_id, contact_id, lead_id, owner_id, salesforce_id.
- Names, organization, and role details: company, department, first_name, last_name, industry, title, website, mobile_phone.
- Lead, campaign, case, and source context: case_type, lead_source, source_member, source_object, status.
- Date and activity fields: converted_date, created_date, last_activity_date, last_login_date, last_modified_date.
- Communication preference and response flags: do_not_call, has_opted_out_of_email, has_responded, is_email_bounced.
At a category level, supplied metadata describes Salesforce CRM and sales-related business contact details, sales communications, product or subscription information, and pricing or quote data (leaksear.ch metadata). Huntress support described the potentially impacted information as business names, contact info, products used, and pricing info Huntress support advisory.
Why this matters
Salesforce CRM data can be sensitive even when passwords and payment cards are not involved because it maps business relationships, account ownership, contact channels, product interest, pricing, and sales context. For this dataset, the searchable fields can help correlate address, country, email, name, phone, and username, while the stored fields add account, lead, campaign, status, ownership, activity, and communication preference context, so responders should treat this as business-contact and sales-intelligence exposure rather than a credential leak (leaksear.ch metadata).
The incident also highlights connected-app risk. ReliaQuest characterized the Klue activity as abuse of a compromised Salesforce-connected integration used to pull CRM records through the Salesforce REST API, and recommended revoking and rotating integration credentials and tokens, reviewing API activity for unusual query volume, and restricting connected-app access to known infrastructure ReliaQuest threat spotlight.
Because Salesforce said the issue did not arise from a Salesforce platform vulnerability, incident response should focus on connected-app access, OAuth grants, service accounts, vendor notifications, and downstream exposure validation Salesforce Trust advisory. For security researchers, the important distinction is that broader reporting about multiple affected Klue customers is separate from the 646,776 leaksear.ch indexed count for this specific Huntress leak source.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, country, email, name, phone, and username.