Vancouver-based market research firm Klue confirmed that hackers exploited an unrevoked 2022 pilot-programme credential on 12 June to breach its systems and steal sensitive data from major corporate clients, including cybersecurity giant LastPass.
A Forgotten Key to the Kingdom
The security failure suggests that the Canadian company had years to decommission the credential used during the trial. This revelation raises serious questions about Klue’s security posture and the preventative measures that could have averted the widespread compromise of its clients’ proprietary information.
Klue spokesperson Katie Berg stated that the initial investigation indicates the compromised credential “was originally provided to a third-party in 2022, for a limited pilot.” However, the firm has declined to clarify the purpose of this pilot, how long it operated, or the identity of the third-party recipient. Furthermore, Klue has not explained why the access rights remained active long after the project concluded.
How the Breach Unfolded
First detected on 12 June and publicly disclosed the following Friday, the cyber-attack allowed malicious actors to compromise Klue’s internal systems. These systems housed highly sensitive OAuth tokens, which act as digital keys. By stealing these tokens, the hackers bypassed security barriers to access and download client data stored across various external cloud databases.
The victims of this supply-chain attack include password management provider LastPass alongside several other prominent cybersecurity entities. The attackers are now using the stolen data to extort the affected businesses.
Critical Security Gaps Remain Unexplained
Many details surrounding the breach remain highly ambiguous as the corporate investigation continues. Klue has avoided specifying the exact nature of the stolen credential, merely referring to it in a blog post as a “legacy credential associated with an integration service.”
It remains unclear whether the compromised asset was an employee’s login combination or if it was exfiltrated directly from the unnamed third-party’s network rather than Klue’s own infrastructure. Identifying these specifics is vital to understanding the mechanics of the intrusion and preventing future vulnerabilities.
Ransom Demands and the Road Ahead
A cyber-criminal syndicate operating under the name “Icarus” has claimed responsibility for the intrusion. The group has listed Klue on its darknet leak site, threatening to publish the stolen corporate data unless a ransom is paid. Klue has not disclosed whether it has engaged in negotiations with the extortionists or if it intends to meet their financial demands.
In response to the incident, Klue stated it is “conducting a comprehensive review of credential management, vendor-access controls, monitoring capabilities, and deployment security processes.” The company has not provided a timeline or further details regarding these corrective measures.
