Klue Hack: New Cyber-Gang Issues Fresh Ransom Threats – Claril Noticias

Market research provider Klue is communicating with its hackers following a major security breach on 12 June, revealing that whilst the original cyber-criminals are allegedly deleting stolen customer data, a second rogue group has emerged to extort its clients directly.

Icarus Group Claims Data Deletion

Klue privately updated its customers on Wednesday night, stating that it remains in contact with the threat actor known as “Icarus”. According to verified sources, Klue believes Icarus is actively removing the exfiltrated files. The hacking group’s dark web leak site is currently offline, further supporting claims that the group is backing down from its initial extortion attempts.

A Growing List of Affected Tech Giants

The security incident compromised sensitive data across a vast network of high-profile corporate clients. Tech giants and cybersecurity firms have since confirmed they were impacted by the breach, including Gong, Jamf, HackerOne, Huntress, Insurity, LastPass, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.

A Second Extortion Attempt Emerges

Just as the situation appeared to stabilise, a chaotic twist unfolded. Klue warned its clients that Icarus disclosed the existence of a rival cyber-gang. This second, unnamed group is now attempting to bypass Klue and extort its customers directly.

The rival faction has published a list of allegedly compromised businesses on its own website. They claim to have stolen the data directly from Icarus’s servers, alleging that Klue paid off an “Icarus operator who is a teenager living somewhere in the UK or adjacent countries.” Whilst there is no independent verification of a ransom payment, or the identity of the operator, the rival group is demanding immediate payment: “Pay the ransom or we will leak everything if you no pay us.” They claim to hold data belonging to 195 different Klue clients.

var playerInstance_jwplayer_6a7a092ea17e5 = jwplayer( “jwplayer_6a7a092ea17e5” );
playerInstance_jwplayer_6a7a092ea17e5.setup({
playlist: “https://cdn.jwplayer.com/v2/media/lv0GaEwB”,
});

According to the rival hackers, the teenage Icarus operator made a critical mistake that allowed them to connect to the server where the stolen client data was being stored.

Klue’s Advice to Customers

In its latest advisory, Klue sought to de-escalate the new threat, noting that Icarus claims the rival group only possesses limited data samples rather than the complete dataset. Klue has strongly advised its clients against paying any ransoms to this secondary group. Instead, affected businesses are urged to demand a random data sample as proof of possession before engaging further.

How the Breach Occurred

The breach was traced back to a compromised 2022 third-party credential from a legacy pilot programme. Cyber-criminals leveraged this outdated access to harvest OAuth tokens, allowing them to breach customers’ cloud environments and databases. Klue has yet to clarify why this four-year-old credential remained active and unrevoked.

Update: Clarifying language has been added to reflect that a communication shared privately with customers was viewed and verified by multiple sources.

Correction: A previous version of this article incorrectly listed ReliaQuest as a victim of the Klue breach. ReliaQuest was not affected.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *