Klue breach exposes data at cybersecurity clients

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Icarus claimed responsibility for the Klue breach and threatened to publish stolen data on Monday unless the company pays a ransom, according to the group's leak site
- Klue said hackers gained access on June 12 using a "compromised legacy credential" tied to an integration tool that links customers' cloud data to their Klue accounts
- At least nine affected companies have confirmed customer data was stolen, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium
- Stolen data consisted primarily of business contact information—names, email addresses, phone numbers, job titles—pulled from customer Salesforce databases
- Klue hired CrowdStrike for incident response and disconnected its integrations to block further access to customer clouds
- The attack mirrors a 2024–2025 pattern of hackers targeting middleware providers like Gainsight, Salesloft, and Snowflake to reach hundreds of downstream companies through a single point of failure
- Klue laid off roughly 100 people (about half its staff) last June to fund AI investments, and its executive leadership page currently lists no person overseeing cybersecurity
Why it matters: Klue has hundreds of customers but has not disclosed how many were affected by the breach, even as nine major security and tech firms have already confirmed exposure. The company's prior 50% staff reduction to fund AI investments, combined with the absence of a named cybersecurity leader on its executive page, sharpens scrutiny of whether headcount and security oversight kept pace as Klue scaled integrations touching customer Salesforce environments.
Ask SkimNews




