Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Data Breach Impacts Cybersecurity Firms via Klue Integration

Data Breach Impacts Cybersecurity Firms via Klue Integration

Posted on June 23, 2026 By CWS

A recent supply chain attack on the market intelligence platform Klue has led to a significant data breach, affecting Salesforce data across multiple high-profile cybersecurity companies. The Icarus extortion group has claimed responsibility for this breach, threatening to release the stolen data if demands are not met.

Timeline of the Attack

The breach was initiated on June 11–12, 2026, when attackers exploited a compromised legacy credential linked to Klue’s integration service account. This unauthorized access allowed the attackers to deploy malicious code aimed at harvesting OAuth tokens, essential for connecting Klue with third-party platforms, notably Salesforce.

Klue detected this unauthorized activity on June 12 and promptly informed its customers, taking immediate action to revoke the affected credentials. They also disabled integrations with several platforms, including Salesforce, HubSpot, and Slack, among others, to mitigate further damage.

Extent of Data Exfiltration

Once inside, the attackers utilized the Salesforce REST API to exfiltrate significant volumes of CRM data. According to ReliaQuest, the attackers executed nearly 1,000 API queries in just 15 minutes, with extended extraction periods lasting over six hours. The stolen information primarily included business contact details, sales account data, and other related information.

While sensitive business data was accessed, no core platform data, threat intelligence, passwords, or payment information was reported to be compromised. The breach affected at least nine organizations, including HackerOne, Huntress, and Jamf, each experiencing varying levels of data exposure.

Response and Ongoing Investigations

The Icarus group, using its leak platform, has issued a ransom demand, threatening the exposure of stolen data. Huntress investigators have identified indicators linking the attack to Icarus, supported by evidence from their compromised environment. The ransom note originated from an email associated with an Australian company, suggesting further compromise.

In response, Klue has engaged CrowdStrike for incident response and forensic investigation. The company has also reported the incident to law enforcement and is conducting a thorough review of its security protocols. CEO Jason Smith publicly addressed the breach on June 22, describing it as a deliberate criminal act and promising transparency with affected clients.

This incident highlights the vulnerabilities present in OAuth-based supply chain attacks, emphasizing how a single compromised credential can lead to widespread data exposure across interconnected systems.

Stay updated on developments by following us on Google News, LinkedIn, and other platforms for instant updates.

Cyber Security News Tags:CrowdStrike, Cybercrime, Cybersecurity, data breach, Icarus group, incident response, Klue, OAuth tokens, Salesforce, supply chain attack

Post navigation

Previous Post: AryStinger Botnet Compromises 4,300 Routers for Global Proxy
Next Post: Prinz Eugen Ransomware Utilizes RemotePC for Attacks

Related Posts

Critical Windows RDP Vulnerabilities Addressed by Microsoft Critical Windows RDP Vulnerabilities Addressed by Microsoft Cyber Security News
Microsoft and CrowdStrike Teaming Up to Bring Clarity To Threat Actor Mapping Microsoft and CrowdStrike Teaming Up to Bring Clarity To Threat Actor Mapping Cyber Security News
glibc Vulnerability Exposes Millions of Linux Systems to Code Execution Attacks glibc Vulnerability Exposes Millions of Linux Systems to Code Execution Attacks Cyber Security News
Cyberattack Uses Fake CAPTCHA to Deploy Malware Cyberattack Uses Fake CAPTCHA to Deploy Malware Cyber Security News
Carnival Cruise Data Breach Hits Millions Carnival Cruise Data Breach Hits Millions Cyber Security News
Iran-Nexus Hackers Abuses Omani Mailbox to Target Global Governments Iran-Nexus Hackers Abuses Omani Mailbox to Target Global Governments Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark