Cybersecurity giants hit in massive Klue data breach – Claril Noticias

Several major cybersecurity firms have had their corporate data stolen following a cyberattack on Vancouver-based market intelligence provider Klue on 12 June, executed via a compromised legacy credential.

Icarus Group Claims Responsibility and Demands Ransom

The cybercrime syndicate known as Icarus has claimed responsibility for the security breach. The group announced the hack on its leak site, threatening to publish the exfiltrated corporate data on Monday unless Klue pays an undisclosed ransom demand.

Klue, which specialises in helping businesses conduct market research by integrating client data with its proprietary systems, confirmed on Friday that unauthorised actors had accessed and stolen information belonging to an unspecified number of its customers during the incident. Interestingly, the company’s official blog post announcing the breach contains the “noindex” code, a technical directive that prevents search engines from indexing the page and displaying it in public search results.

Top-Tier Tech and Cybersecurity Brands Impacted

While Klue has declined to specify the exact number of its hundreds of corporate clients affected by the breach, several prominent technology and security organisations have already stepped forward to confirm they were compromised. The list of affected enterprises includes Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.

The Growing Threat of Supply Chain Exploitation

This incident represents the latest in a worrying trend of supply chain cyberattacks, where malicious actors target third-party middleware providers that hold access keys to major corporate cloud environments. By compromising a single service provider like Klue, hackers can bypass individual perimeter defences to harvest data from dozens of high-value targets simultaneously. Over the past year, similar integration and middleware platforms, such as Gainsight and Salesloft, have been targeted in comparable campaigns to compromise hundreds of downstream corporate databases.

How the Hackers Gained Access

According to Klue, the attackers breached its systems by leveraging a “compromised legacy credential”—such as an outdated password or API token—associated with an integration tool. This tool is designed to allow customers to seamlessly link their external cloud databases directly to their Klue profiles.

Once inside, the threat actors exfiltrated sensitive data directly from the connected customer cloud environments, including Salesforce databases. Because organisations routinely utilise Salesforce to manage customer relations, these repositories often contain highly valuable personal and corporate information.

Reports from the affected companies indicate that the stolen datasets primarily consist of business contact information. This includes names, email addresses, phone numbers, job titles, and specific customer account details.

Credential Theft and Detection Failures

It remains unclear how the attackers initially acquired the legacy credentials, or why Klue’s internal security monitoring failed to detect the exfiltration in real time. Recent high-profile credential-stuffing and access-abuse campaigns, including those targeting Snowflake and TanStack, have frequently been traced back to employees inadvertently downloading info-stealing malware on corporate or personal devices used for work purposes.

Incident Response and Corporate Fallout

In response to the breach, Klue has retained the services of cybersecurity firm CrowdStrike to lead the incident response and forensic investigation. The company has also deactivated all active integration pipelines to prevent any further unauthorised access to customer data environments.

Klue Chief Executive Jason Smith did not immediately respond to inquiries regarding the breach, nor did he clarify whether the firm has engaged in negotiations with the Icarus group regarding the ransom demand.

However, security firm Huntress, which was also affected by the breach, revealed in its write-up of the incident that the hackers had sent them a direct ransom note. Interestingly, the email originated from the compromised servers of an unrelated Australian business, suggesting the attackers are routing their communications through hijacked third-party infrastructure.

Staffing Cuts and Security Leadership Questions

The cyberattack comes at a turbulent time for the Canadian software firm. Last June, Klue announced it was preparing to lay off around half of its staff—representing approximately 100 employees—as part of a strategic pivot to focus heavily on artificial intelligence. It is currently unknown whether these drastic personnel reductions contributed to security oversights or lapses in credential management.

Furthermore, questions remain regarding who is directing the company’s cybersecurity strategy. Klue does not currently list a Chief Information Security Officer (CISO) or any dedicated security executive on its executive leadership page.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *