<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Klue Breach Expands: Dozens of Customers Compromised as Hackers Turn on Each Other

Klue's supply chain attack exposed data from clients like Salesforce; hackers Icarus hit back but faced their own breach.
Content Team

A supply chain attack on market intelligence platform Klue, carried out June 11–12, has now been confirmed by roughly two dozen customers, including AlertMedia, Blackbaud, Deel, and Tines. Hackers used legacy credentials to steal OAuth tokens and bulk-exfiltrate Salesforce data. Salesforce and Gong both disabled the Klue integration on June 17.

The threat actor, Icarus, demanded ransom via a Tor leak site — but then got hacked themselves. A second group reportedly stole sample data from Icarus and launched their own extortion campaign. Klue, which has hundreds of customers, says Icarus has begun deleting the stolen data, suggesting a ransom may have been paid.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo