Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Klue Data Breach Expands Amidst Hacker Dispute

Klue Data Breach Expands Amidst Hacker Dispute

Posted on June 26, 2026 By CWS

Approximately two dozen companies using Klue have reported that their Salesforce systems were compromised in a recent supply chain attack. This incident occurred between June 11 and 12, when cyber attackers exploited outdated credentials to infiltrate Klue’s market intelligence platform. The attackers managed to acquire OAuth tokens tied to Klue’s customer integrations, allowing them to exfiltrate data in significant volumes.

Timeline of the Attack

The breach led to Salesforce deactivating the Klue integration on June 17, and this function remains disabled according to their status page. Gong also followed suit in disabling the integration. Among the impacted entities are AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. Although Klue serves hundreds of clients, the extent of the damage could be broader, though further notifications have not been observed by SecurityWeek.

It is important to note that some Klue customers, such as Autodesk, do not employ the Salesforce integration and thus were not affected by this breach.

Hacker Group Involvement

A hacker group named Icarus has taken responsibility for the attack, listing Klue and several of its clients on a Tor-based leak site. The group threatens to publish the stolen data, which mainly includes business contact and support information unless their ransom demands are met. On Monday, Klue acknowledged the data breach and announced an ongoing investigation, though further public updates have not been issued.

Meanwhile, Klue has privately informed its clients of ongoing communications with the attackers, who have begun erasing the stolen data, as reported by TechCrunch. Icarus’s leak site has been down for several days, possibly due to negotiations, hinting that Klue might have complied with the ransom demands.

Secondary Breach and Ongoing Risks

In a surprising turn of events, Klue reportedly informed its clients that Icarus was themselves hacked, leading to the stolen data falling into the hands of a different threat actor. This new group is allegedly conducting its own extortion attempts, although it appears they only managed to seize sample data.

The incident is believed to affect 195 Klue clients, but no other extortion group besides Icarus has publicly claimed responsibility for the data stolen during the initial Klue breach. SecurityWeek has reached out to Klue for further comments and will provide updates if a response is received.

Related breaches highlight the ongoing challenges in cybersecurity, with recent disclosures from companies like London Hydro, Xsolis, Texas Parks & Wildlife, and Kodak, emphasizing the widespread nature of such threats.

Security Week News Tags:Cybersecurity, data breach, data exfiltration, Extortion, Hackers, Icarus, Klue, market intelligence, Salesforce, supply chain attack

Post navigation

Previous Post: Guardian Agents: Enhancing Identity Governance for AI
Next Post: Amazon Q Flaw Exposes Code Execution and Cloud Risks

Related Posts

Microsoft Defender’s Vulnerability Exploited in Zero-Day Attack Microsoft Defender’s Vulnerability Exploited in Zero-Day Attack Security Week News
Supply Chain Attack Hits SAP NPM Packages Supply Chain Attack Hits SAP NPM Packages Security Week News
Cybersecurity Firm Magnitude Secures M for AI Risk Management Cybersecurity Firm Magnitude Secures $10M for AI Risk Management Security Week News
CrowdStrike to Acquire Pangea to Launch AI Detection and Response (AIDR) CrowdStrike to Acquire Pangea to Launch AI Detection and Response (AIDR) Security Week News
Red Access Raises  Million for Agentless Security Platform Red Access Raises $17 Million for Agentless Security Platform Security Week News
Explore ROI for Cyber-Physical Security in Live Webinar Explore ROI for Cyber-Physical Security in Live Webinar Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI
  • Japan’s Army Faces Malware Breach via Infected USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chinese APT Group Deploys TinyRCT in Southeast Asia
  • Amazon Q Flaw Exposes Code Execution and Cloud Risks
  • Klue Data Breach Expands Amidst Hacker Dispute
  • Guardian Agents: Enhancing Identity Governance for AI
  • Japan’s Army Faces Malware Breach via Infected USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark