Hack Notice

Hack Notice: Security shops among the 'hundreds' of Klue hack victims

Security shops among the 'hundreds' of Klue hack victims

Source
https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743
Description
The list of Klue customers whose Salesforce data was stolen in the latest supply-chain heist keeps growing, with an increasing number of cybersecurity companies disclosing that they are among the victims of a new data-theft and extortion crew called Icarus. Klue, which provides market intelligence to more than 250,000 users worldwide, hasnt said how many of its customers were caught up in the breach and didnt immediately respond to The Registers inquiries. Huntress was one of the first cybersecurity vendors to sound the alarm, and, in an email to The Register, said that it was among the hundreds of Klue customers affected. However, it said that the breach did not affect its tools or highly secure info such as passwords. Huntress believes in radical transparence about security incidents, including when it affects our company, the security shop wrote on Thursday. The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging. no threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected. Huntress, along with the other victim companies, said that there is no denotation that any of its products or base were compromised, and that this security incident was specific to CRM data. Since then, several other security and software vendors including Recorded Future, Tanium, Jamf, Gong, HackerOne, Kudelski Security, Snyk, Insurity, and Sprout social have revealed that the data thieves also accessed their CRM data via the Klue integrating with Salesforce. Heres what we do cognize about what happened and who is behind this latest extortion campaign. The breach occurred on June 11, and Klue spotted the trespass a daytime later. This unauthorized action affected a portion of its integration infrastructure, according to the software provider. Klue has since disconnected all of its integrations with Salesforce, Gong, HubSpot, SharePoint, and Google Drive. It also hired CrowdStrike to assist in the investigation and certificate response. Our investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service, Klue CEO Jason smith said in a friday blog post. The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments.

About HackNotice and Security shops among the 'hundreds' of Klue hack victims

HackNotice is a service that notices trends and patterns in publically available data so as to identify possible data breaches, leaks, hacks, and other data incidents on behalf of our clients. HackNotice monitors data streams related to breaches, leaks, and hacks and Security shops among the 'hundreds' of Klue hack victims was reported by one of those streams. HackNotice may also have the breach date, hack date, the hacker responsible, the hacked industry, the hacked location, and any other parts of the hack, breach, or leak that HackNotice can report on for the consumers of our product.

If you are a user of Security shops among the 'hundreds' of Klue hack victims their products, services, websites, or applications and you were a client of HackNotice, monitoring for Security shops among the 'hundreds' of Klue hack victims you may have been alerted to this report about Security shops among the 'hundreds' of Klue hack victims . HackNotice is a service that provides data, information, and monitoring that helps our clients recover from and remediate data breaches, hacks, and leaks of their personal information. HackNotice provides a service that helps our clients know what to do about a hack, breach, or leak of their information.

If Security shops among the 'hundreds' of Klue hack victims had a breach of consumer data or a data leak, then there may live additional actions that our clients should submit to protect their digital identity. Data breaches, hacks, and leaks often lead-in to and do identity theft, account have overs, ransomware, spyware, extortion, and malware. account takeovers are often caused by credential reuse, word reuse, easily guessed passwords, and are facilitated by the sharing of billions of credentials and other customer information through data leaks, as the direct result of data breaches and hacks.

HackNotice monitors trends in publically available data that indicates tens of thousands of data breaches each year, along with billions of records from data leaks each year. On behalf of our clients, HackNotice works to monitor for hacks that lead to lower client security and digital identities that have been exposed and should be considered vulnerable to attack. HackNotice works with clients to discover the extent that digital identities get been exposed and provides remediation suggestions for how to handle each type of exposure.

HackNotice monitors the hacker community, which is a network of individuals that portion data breaches, hacks, leaks, malware, spyware, ransomware, and many other tools that are often used for financial fraud, account accept overs, and further breaches and hacks. HackNotice monitors the hacker community specifically for breaches, hacks, and data leaks that hurt consumers. HackNotice applies industry specific knowledge and advanced surety practices to monitor for trends that designate breaches, hacks, and exposed digital identities.

HackNotice also enables clients to apportion hack notices with their friend, family, and collogues to aid increase awareness around alleged hacks, breaches, or data leaks. HackNotice workings to provide clients with sharable reports to help growth the certificate of our clients personal network. The security of the people that our clients interact with directly impacts the level of security of our clients. Increased exposure to accounts that make been taken over by hackers leads to further account take overs through phishing, malware, and other attach techniques.

If you found this hack notice to live helpful, then you may be interested in reading some additional plug notices such as:

in, associated with organized crime, political activist or national governments to careless disposalsional associations for IT asset managers act aggressively with IT professionals to civilize them on or change of such information to the information systems of a possibly hostile agency, such as a

Defacement http://mairie-laboutarie.fr/media/com_sppagebuilder/assets/iconfont/icoqxfv9ii3t/fonts/cox.txt

Defacement https://www.majlisraja-raja.gov.my/media/x/fonts/kill.html

Defacement https://jatim.kemenkum.go.id/media/x/fonts/kill.html