Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Data Breach Impacts Cybersecurity Firms via Klue Integration

Data Breach Impacts Cybersecurity Firms via Klue Integration

Posted on June 23, 2026 By CWS

A recent supply chain attack on the market intelligence platform Klue has led to a significant data breach, affecting Salesforce data across multiple high-profile cybersecurity companies. The Icarus extortion group has claimed responsibility for this breach, threatening to release the stolen data if demands are not met.

Timeline of the Attack

The breach was initiated on June 11–12, 2026, when attackers exploited a compromised legacy credential linked to Klue’s integration service account. This unauthorized access allowed the attackers to deploy malicious code aimed at harvesting OAuth tokens, essential for connecting Klue with third-party platforms, notably Salesforce.

Klue detected this unauthorized activity on June 12 and promptly informed its customers, taking immediate action to revoke the affected credentials. They also disabled integrations with several platforms, including Salesforce, HubSpot, and Slack, among others, to mitigate further damage.

Extent of Data Exfiltration

Once inside, the attackers utilized the Salesforce REST API to exfiltrate significant volumes of CRM data. According to ReliaQuest, the attackers executed nearly 1,000 API queries in just 15 minutes, with extended extraction periods lasting over six hours. The stolen information primarily included business contact details, sales account data, and other related information.

While sensitive business data was accessed, no core platform data, threat intelligence, passwords, or payment information was reported to be compromised. The breach affected at least nine organizations, including HackerOne, Huntress, and Jamf, each experiencing varying levels of data exposure.

Response and Ongoing Investigations

The Icarus group, using its leak platform, has issued a ransom demand, threatening the exposure of stolen data. Huntress investigators have identified indicators linking the attack to Icarus, supported by evidence from their compromised environment. The ransom note originated from an email associated with an Australian company, suggesting further compromise.

In response, Klue has engaged CrowdStrike for incident response and forensic investigation. The company has also reported the incident to law enforcement and is conducting a thorough review of its security protocols. CEO Jason Smith publicly addressed the breach on June 22, describing it as a deliberate criminal act and promising transparency with affected clients.

This incident highlights the vulnerabilities present in OAuth-based supply chain attacks, emphasizing how a single compromised credential can lead to widespread data exposure across interconnected systems.

Stay updated on developments by following us on Google News, LinkedIn, and other platforms for instant updates.

Cyber Security News Tags:CrowdStrike, Cybercrime, Cybersecurity, data breach, Icarus group, incident response, Klue, OAuth tokens, Salesforce, supply chain attack

Post navigation

Previous Post: AryStinger Botnet Compromises 4,300 Routers for Global Proxy
Next Post: Prinz Eugen Ransomware Utilizes RemotePC for Attacks

Related Posts

New Research Unmask DPRK IT Workers Email Address and Hiring Patterns New Research Unmask DPRK IT Workers Email Address and Hiring Patterns Cyber Security News
Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code Cyber Security News
VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support VMware Workstation and Fusion 25H2 Released with New Features and Latest OS Support Cyber Security News
MCPTotal Launches to Power Secure Enterprise MCP Workflows MCPTotal Launches to Power Secure Enterprise MCP Workflows Cyber Security News
What is ClickFix Attack – How Hackers are Using it to Attack User Device With Malware What is ClickFix Attack – How Hackers are Using it to Attack User Device With Malware Cyber Security News
F5 Addresses Critical Security Flaws in BIG-IP and NGINX F5 Addresses Critical Security Flaws in BIG-IP and NGINX Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korea’s VPN Infrastructure Exposed by TLS Certificate
  • Malicious npm Package Evades Detection with Runtime Activation
  • Massive Data Loss in 103 Seconds by AI Coding Agent
  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korea’s VPN Infrastructure Exposed by TLS Certificate
  • Malicious npm Package Evades Detection with Runtime Activation
  • Massive Data Loss in 103 Seconds by AI Coding Agent
  • Google Fined €403M for GDPR Breaches in Location Data
  • AWS Swiftly Quarantines Exposed IAM Keys on GitHub

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark