Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Data Breach Impacts Cybersecurity Firms via Klue Integration

Data Breach Impacts Cybersecurity Firms via Klue Integration

Posted on June 23, 2026 By CWS

A recent supply chain attack on the market intelligence platform Klue has led to a significant data breach, affecting Salesforce data across multiple high-profile cybersecurity companies. The Icarus extortion group has claimed responsibility for this breach, threatening to release the stolen data if demands are not met.

Timeline of the Attack

The breach was initiated on June 11–12, 2026, when attackers exploited a compromised legacy credential linked to Klue’s integration service account. This unauthorized access allowed the attackers to deploy malicious code aimed at harvesting OAuth tokens, essential for connecting Klue with third-party platforms, notably Salesforce.

Klue detected this unauthorized activity on June 12 and promptly informed its customers, taking immediate action to revoke the affected credentials. They also disabled integrations with several platforms, including Salesforce, HubSpot, and Slack, among others, to mitigate further damage.

Extent of Data Exfiltration

Once inside, the attackers utilized the Salesforce REST API to exfiltrate significant volumes of CRM data. According to ReliaQuest, the attackers executed nearly 1,000 API queries in just 15 minutes, with extended extraction periods lasting over six hours. The stolen information primarily included business contact details, sales account data, and other related information.

While sensitive business data was accessed, no core platform data, threat intelligence, passwords, or payment information was reported to be compromised. The breach affected at least nine organizations, including HackerOne, Huntress, and Jamf, each experiencing varying levels of data exposure.

Response and Ongoing Investigations

The Icarus group, using its leak platform, has issued a ransom demand, threatening the exposure of stolen data. Huntress investigators have identified indicators linking the attack to Icarus, supported by evidence from their compromised environment. The ransom note originated from an email associated with an Australian company, suggesting further compromise.

In response, Klue has engaged CrowdStrike for incident response and forensic investigation. The company has also reported the incident to law enforcement and is conducting a thorough review of its security protocols. CEO Jason Smith publicly addressed the breach on June 22, describing it as a deliberate criminal act and promising transparency with affected clients.

This incident highlights the vulnerabilities present in OAuth-based supply chain attacks, emphasizing how a single compromised credential can lead to widespread data exposure across interconnected systems.

Stay updated on developments by following us on Google News, LinkedIn, and other platforms for instant updates.

Cyber Security News Tags:CrowdStrike, Cybercrime, Cybersecurity, data breach, Icarus group, incident response, Klue, OAuth tokens, Salesforce, supply chain attack

Post navigation

Previous Post: AryStinger Botnet Compromises 4,300 Routers for Global Proxy
Next Post: Prinz Eugen Ransomware Utilizes RemotePC for Attacks

Related Posts

Massive Cyberattack Targets Trusted Platforms with Malware Massive Cyberattack Targets Trusted Platforms with Malware Cyber Security News
Chrome Security Update Fixes Critical Vulnerabilities Chrome Security Update Fixes Critical Vulnerabilities Cyber Security News
Authorities Seize SocGholish Malware Network Servers Authorities Seize SocGholish Malware Network Servers Cyber Security News
WhatsApp Counters NSO Group’s Pegasus Spyware Attack WhatsApp Counters NSO Group’s Pegasus Spyware Attack Cyber Security News
CISA Warns of Critical SunPower Device Vulnerability Let Attackers Gain Full Device Access CISA Warns of Critical SunPower Device Vulnerability Let Attackers Gain Full Device Access Cyber Security News
0-Click Zendesk Account Takeover Vulnerability Enables Access to all Zendesk Tickets 0-Click Zendesk Account Takeover Vulnerability Enables Access to all Zendesk Tickets Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Prinz Eugen Ransomware Utilizes RemotePC for Attacks
  • Data Breach Impacts Cybersecurity Firms via Klue Integration
  • AryStinger Botnet Compromises 4,300 Routers for Global Proxy
  • Remcos RAT Hidden in GST Note Targets Indian Users
  • Malware Targets Windows via Deceptive npm Package

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Prinz Eugen Ransomware Utilizes RemotePC for Attacks
  • Data Breach Impacts Cybersecurity Firms via Klue Integration
  • AryStinger Botnet Compromises 4,300 Routers for Global Proxy
  • Remcos RAT Hidden in GST Note Targets Indian Users
  • Malware Targets Windows via Deceptive npm Package

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark