Roughly two dozen companies have been affected by the Klue-Salesforce incident, as hackers claim data was stolen from them.

It's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.

More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.