<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Klue Breach Expands: Dozens of Customers Compromised as Hackers Turn on Each Other

Klue's supply chain attack exposed Salesforce CRM data belonging to dozens of its customers; hackers Icarus then got breached themselves.
Content Team

A supply chain attack on market intelligence platform Klue, carried out June 11–12, has now been confirmed by roughly two dozen customers, including AlertMedia, Blackbaud, Deel, Tines, BeyondTrust and LastPass. Hackers used legacy credentials to steal OAuth tokens and bulk-exfiltrate Salesforce data. Klue has reportedly told customers the incident touches 195 of them in total.

Salesforce disabled the Klue integration on June 17 and has yet to re-enable it; Gong disabled it too.

The threat actor, Icarus, demanded ransom via a Tor leak site — but then got hacked themselves. Klue has reportedly told customers that Icarus was breached and the stolen data is now in another threat actor's hands. Klue says Icarus has begun deleting the data, and its leak site has gone dark, which suggests a ransom may have been paid. Klue hasn't confirmed either way.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo