Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Klue Data Breach Expands Amidst Hacker Dispute

Klue Data Breach Expands Amidst Hacker Dispute

Posted on June 26, 2026 By CWS

Approximately two dozen companies using Klue have reported that their Salesforce systems were compromised in a recent supply chain attack. This incident occurred between June 11 and 12, when cyber attackers exploited outdated credentials to infiltrate Klue’s market intelligence platform. The attackers managed to acquire OAuth tokens tied to Klue’s customer integrations, allowing them to exfiltrate data in significant volumes.

Timeline of the Attack

The breach led to Salesforce deactivating the Klue integration on June 17, and this function remains disabled according to their status page. Gong also followed suit in disabling the integration. Among the impacted entities are AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. Although Klue serves hundreds of clients, the extent of the damage could be broader, though further notifications have not been observed by SecurityWeek.

It is important to note that some Klue customers, such as Autodesk, do not employ the Salesforce integration and thus were not affected by this breach.

Hacker Group Involvement

A hacker group named Icarus has taken responsibility for the attack, listing Klue and several of its clients on a Tor-based leak site. The group threatens to publish the stolen data, which mainly includes business contact and support information unless their ransom demands are met. On Monday, Klue acknowledged the data breach and announced an ongoing investigation, though further public updates have not been issued.

Meanwhile, Klue has privately informed its clients of ongoing communications with the attackers, who have begun erasing the stolen data, as reported by TechCrunch. Icarus’s leak site has been down for several days, possibly due to negotiations, hinting that Klue might have complied with the ransom demands.

Secondary Breach and Ongoing Risks

In a surprising turn of events, Klue reportedly informed its clients that Icarus was themselves hacked, leading to the stolen data falling into the hands of a different threat actor. This new group is allegedly conducting its own extortion attempts, although it appears they only managed to seize sample data.

The incident is believed to affect 195 Klue clients, but no other extortion group besides Icarus has publicly claimed responsibility for the data stolen during the initial Klue breach. SecurityWeek has reached out to Klue for further comments and will provide updates if a response is received.

Related breaches highlight the ongoing challenges in cybersecurity, with recent disclosures from companies like London Hydro, Xsolis, Texas Parks & Wildlife, and Kodak, emphasizing the widespread nature of such threats.

Security Week News Tags:Cybersecurity, data breach, data exfiltration, Extortion, Hackers, Icarus, Klue, market intelligence, Salesforce, supply chain attack

Post navigation

Previous Post: Guardian Agents: Enhancing Identity Governance for AI
Next Post: Amazon Q Flaw Exposes Code Execution and Cloud Risks

Related Posts

Stealthium Enhances Security for AI Accelerators and Neo-Clouds Stealthium Enhances Security for AI Accelerators and Neo-Clouds Security Week News
Password Managers Vulnerable to Data Theft via Clickjacking Password Managers Vulnerable to Data Theft via Clickjacking Security Week News
Proofpoint Completes .8 Billion Acquisition of Hornetsecurity  Proofpoint Completes $1.8 Billion Acquisition of Hornetsecurity  Security Week News
China’s Salt Typhoon Hackers Target Canadian Telecom Firms China’s Salt Typhoon Hackers Target Canadian Telecom Firms Security Week News
Chrome Update Patches Fifth Zero-Day of 2025 Chrome Update Patches Fifth Zero-Day of 2025 Security Week News
Langflow Vulnerability Exploited Rapidly After Disclosure Langflow Vulnerability Exploited Rapidly After Disclosure Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws
  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Enhances Security with Claude Code Auto Mode
  • Windows 11 Vulnerabilities Expose MFA Flaws
  • HP ThinPro Encryption Flaw Risks LUKS Key Exposure
  • Gunra Ransomware Exploits VPN Vulnerabilities for Data Theft
  • China-Linked Group Unleashes StormEncryptor Ransomware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark