Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Klue Hack Affects Multiple Cybersecurity Firms

Klue Hack Affects Multiple Cybersecurity Firms

Posted on June 22, 2026 By CWS

In a recent cybersecurity development, at least nine organizations have reported being affected by a supply chain attack targeting the market intelligence platform Klue. This incident, which took place between June 11 and 12, exploited Klue’s integration with Salesforce, leading to unauthorized data access from multiple customer accounts, including several prominent cybersecurity firms.

Details of the Klue Security Breach

Klue confirmed on Friday that the breach occurred through the use of compromised legacy credentials, allowing attackers to infiltrate its systems and compromise Salesforce integrations. The attackers gained access to OAuth tokens that enabled them to connect Klue with third-party platforms, including Salesforce, thereby accessing sensitive data within several connected customer environments.

The company has since revoked the compromised credentials and tokens, disabled integrations across various services, and is conducting an investigation alongside CrowdStrike and law enforcement authorities. According to Klue, the breach was restricted to affected third-party platforms with no evidence of customer content within the Klue platform being compromised.

Impact on Cybersecurity Firms

Among the affected organizations are cybersecurity firms such as HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium. Additionally, Insurity and Sprout Social have informed their customers of the breach. These companies have reiterated that the breach was confined to Salesforce instances and did not compromise their internal systems, aligning with Klue’s assessment of the situation.

The hackers managed to extract business information from the targeted organizations’ Salesforce CRMs, which included sales account data and business contact details like names, email addresses, job titles, phone numbers, and business addresses. In response, Salesforce and Gong have both disabled Klue integrations to mitigate further risk.

Speculations and Threats Following the Attack

Huntress has suggested that a threat actor known as Icarus might be behind this attack. Following the breach, Icarus has listed Klue on its Tor-based leak site, claiming responsibility and threatening to release the stolen data unless negotiations are initiated by June 22.

This incident highlights the ongoing vulnerabilities within supply chain integrations and the importance of securing third-party connections. As investigations continue, affected organizations are advised to review and strengthen their security protocols to prevent future breaches.

This cyberattack serves as a critical reminder of the need for robust cybersecurity measures, particularly in the realm of third-party integrations that can become points of vulnerability for data exfiltration.

Security Week News Tags:business data security, CrowdStrike investigation, cybersecurity breach, cybersecurity firms, data exfiltration, Icarus hacker, Klue hack, OAuth tokens, Salesforce integration, supply chain attack

Post navigation

Previous Post: Hackers Use Fake Google Ads to Deploy Malware
Next Post: North Korean Hackers Target Developers via Mastra npm

Related Posts

Zscaler Expands with SquareX Acquisition for Enhanced Browser Security Zscaler Expands with SquareX Acquisition for Enhanced Browser Security Security Week News
Wytec Expects Significant Financial Loss Following Website Hack Wytec Expects Significant Financial Loss Following Website Hack Security Week News
Oracle Releases June Security Patch with 245 Fixes Oracle Releases June Security Patch with 245 Fixes Security Week News
Cyber Risk Trends for 2026: Building Resilience, Not Just Defenses Cyber Risk Trends for 2026: Building Resilience, Not Just Defenses Security Week News
OpenAI Expands ChatGPT Security Features Globally OpenAI Expands ChatGPT Security Features Globally Security Week News
SAP Addresses Critical Vulnerabilities in S/4HANA SAP Addresses Critical Vulnerabilities in S/4HANA Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New BootROM Exploit Threatens iPhone Security
  • Canada’s Spy Agency Neutralizes Botnets with Unique Warrant
  • North Korean Hackers Target Developers via Mastra npm
  • Klue Hack Affects Multiple Cybersecurity Firms
  • Hackers Use Fake Google Ads to Deploy Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New BootROM Exploit Threatens iPhone Security
  • Canada’s Spy Agency Neutralizes Botnets with Unique Warrant
  • North Korean Hackers Target Developers via Mastra npm
  • Klue Hack Affects Multiple Cybersecurity Firms
  • Hackers Use Fake Google Ads to Deploy Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark