Klue Breach Hits 200 Firms via 4-Year-Old Credential [2026]

A credential that Klue issued in 2022 for a “limited pilot” sat live and unwatched for roughly four years. When an extortion crew calling itself Icarus finally found it on June 12, 2026, a single forgotten token opened a path into the Salesforce environments of close to 200 companies, several of them the same firms that sell cybersecurity products for a living.

LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium and Huntress all confirmed they lost business data in the incident. So did Gong, OneTrust, Sprout Social, Insurity, 8×8, Pendo, NoPass and GMS. The Klue data breach has become one of the defining cybersecurity stories of mid-2026, not because of how much data leaked, but because of who it hit and how little it took to make it happen.

This is a breakdown of what actually happened, why the attack spread through a marketing-intelligence vendor instead of a traditional network breach, how it compares to last year’s Salesloft Drift incident, and what it signals for anyone managing third-party OAuth connections into a CRM.

Google · Preferred Sources

Don't miss new tech stories on Google

Add Tech Insider once in the Google app and our stories appear in your news suggestions.

Add Now

What Happened: Inside the Klue Breach Timeline

Klue is a competitive-intelligence platform that sales and marketing teams connect to their CRM to track competitor moves. According to TechCrunch’s reporting, attackers first accessed Klue’s systems on June 12, 2026 — the date Klue says it detected the unauthorized activity — when an attacker used a compromised legacy credential tied to an integration tool that links customer cloud data, including Salesforce, to Klue accounts. Klue has since confirmed that the credential itself “was originally provided to a third-party in 2022, for a limited pilot,” and it was apparently never deactivated once that pilot ended. Klue’s investigation says the attacker used that credential to obtain OAuth tokens for connected platforms, including Salesforce. Klue disclosed the intrusion publicly on June 15, 2026, saying hackers had stolen data from an unspecified number of customers, and said it had engaged CrowdStrike to investigate and had disconnected the affected integrations.

Klue has been consistent on one specific point of scope: the company says the attacker’s access ran through connected third-party platforms, chiefly Salesforce, rather than through customer content stored directly inside Klue’s own systems. That distinction does not shrink the breach for the companies whose Salesforce data was pulled, but it does narrow what “exposed” actually means here, a detail worth keeping in mind while reading vendor statements that otherwise sound alarming.

The scale became clear over the following two weeks. TechCrunch named the first wave of affected companies on June 22. LastPass confirmed its own exposure on June 23, and BeyondTrust followed a day later, according to SecurityWeek. By early July, a separate TechCrunch year-in-review piece on 2026’s worst breaches was treating Klue as one of the year’s defining vendor incidents, alongside a wave of unrelated attacks on open-source security tools.

Klue’s own CEO did not respond to TechCrunch’s requests for comment, which left most of the public detail in this story coming from the victims rather than from Klue itself.

Klue Breach Timeline: Key Dates at a Glance

  • 2022: Klue provides a credential to a third party for a limited pilot; the credential is later used in the attack.
  • June 12, 2026: Klue says it detected unauthorized activity; this is also when TechCrunch reports the attacker first accessed Klue’s systems using the dormant credential.
  • June 15, 2026: Klue discloses the intrusion publicly, citing an “unspecified number” of affected customers.
  • June 22, 2026: TechCrunch names the first wave of affected companies, including Jamf, HackerOne, Recorded Future, Snyk, Tanium, Huntress, Gong, OneTrust, Sprout Social and Insurity.
  • June 23, 2026: LastPass confirms its own exposure.
  • June 24, 2026: BeyondTrust confirms impact; roughly 15 of an estimated 195-200 exposed companies have gone public by this point.
  • Early July 2026: TechCrunch’s mid-year breach roundup lists Klue among 2026’s defining vendor incidents.
  • Late July 2026: 8×8, Pendo, NoPass and GMS confirm impact, and FINRA issues a member alert referencing Klue’s June 12, 2026 detection date, pushing the publicly confirmed victim count to at least 16.

Anatomy of the Attack: How One Dormant Credential Exposed 200 Companies

The mechanics of the Klue data breach are almost mundane, which is exactly what makes it worth studying. Icarus did not need a zero-day or custom malware. It needed one old integration credential that nobody had gotten around to retiring.

Once inside Klue’s systems, the attacker generated OAuth tokens that Klue’s platform used to pull customer data from connected Salesforce instances. Those tokens are what let a customer’s Klue integration read contacts, support cases and account records automatically. In the hands of an attacker, the same tokens became a key ring for hundreds of separate Salesforce tenants. Reporting from SecurityWeek describes the attacker running automated scripts to pull data in bulk from each connected Salesforce instance once the tokens were in hand.

The OAuth Token Problem

OAuth tokens exist so that two systems can talk to each other without sharing a password directly. That convenience is also the weakness. A token scoped for a “limited pilot” in 2022 should have expired, been rotated, or been reviewed well before 2026. Instead it stayed active long enough that whoever eventually found it inherited standing access into a live production system, no phishing email or malware drop required. Security teams have a name for this: fourth-party risk, meaning the exposure that comes not from your own vendor but from your vendor’s vendor.

The Victim List: When Security Vendors Become the Story

What sets this breach apart from a typical vendor incident is the client list. Klue markets itself to sales and product-marketing teams, so its customer base includes plenty of ordinary B2B software companies. But several of the confirmed victims sell security or trust products themselves: Snyk (application security), Tanium (endpoint management), Recorded Future (threat intelligence), HackerOne (bug bounty coordination), BeyondTrust (privileged access management) and LastPass (password management).

Huntress, a managed detection and response firm, was also affected and told reporters that the attackers contacted it with a ransom note sent from an Australian company’s compromised email address, a detail that underscores how much of this campaign relied on reused infrastructure rather than bespoke tooling.

The irony is not lost on the industry: companies whose entire pitch is “we keep your data safe” ended up notifying their own customers about a breach that started in a sales-intelligence tool none of their customers had ever heard of.

Klue Breach Victims at a Glance

CompanyPrimary BusinessData ExposedPublic Confirmation
LastPassPassword managementBusiness contact info, CRM/support case data (Salesforce)June 23, 2026
BeyondTrustPrivileged access managementBusiness contact and sales-related dataJune 24, 2026
JamfApple device managementCustomer account dataConfirmed by TechCrunch, June 22
HackerOneBug bounty coordinationCustomer account dataConfirmed by TechCrunch, June 22
Recorded FutureThreat intelligenceCustomer account dataConfirmed by TechCrunch, June 22
SnykApplication securityCustomer account dataConfirmed by TechCrunch, June 22
TaniumEndpoint securityCustomer account dataConfirmed by TechCrunch, June 22
HuntressManaged detection and responseCustomer account data; received attacker ransom noteConfirmed by TechCrunch, June 22
GongRevenue intelligenceCustomer account dataConfirmed by TechCrunch, June 22
OneTrustPrivacy and compliance softwareCustomer account dataConfirmed by TechCrunch, June 22
Sprout SocialSocial media managementCustomer account dataConfirmed by TechCrunch, June 22
InsurityInsurance softwareCustomer account dataConfirmed by TechCrunch, June 22
8×8Cloud communicationsCustomer account dataConfirmed, July 2026
PendoProduct analyticsCustomer account dataConfirmed, July 2026
NoPassNot publicly detailedCustomer account dataConfirmed, July 2026
GMSNot publicly detailedCustomer account dataConfirmed, July 2026

Roughly 195 to 200 companies had data exposed inside Klue’s systems in total, based on TechCrunch’s reporting. By late July 2026, at least 16 organizations had gone public with a confirmed impact statement, up from about 15 in late June, after 8×8, Pendo, NoPass and GMS came forward. Huntress has said it expects the real number of affected Klue customers to be considerably higher once more companies finish their own reviews.

New Victims and Regulatory Attention: What’s Changed Since June

The publicly confirmed victim list did not stop growing after TechCrunch’s initial June 22 report. By late July 2026, four more companies had confirmed impact: 8×8, a cloud communications provider; Pendo, a product analytics platform; and NoPass and GMS, both of which have not detailed their exposure beyond confirming it. That brings the total number of publicly named victims to at least 16, out of the roughly 195 to 200 companies reportedly exposed inside Klue’s systems overall.

The other development is regulatory rather than corporate. FINRA, the Financial Industry Regulatory Authority, has issued a member alert referencing the Klue breach and citing the same June 12, 2026 detection date Klue disclosed. FINRA’s alert describes the threat actor, tracked as Icarus, as having used a compromised service-account credential to access Klue’s backend directly. Klue is not a financial services company, but a fourth-party breach that reaches into the Salesforce environments of firms FINRA regulates is enough to draw a formal notice, a preview of how this style of OAuth-token incident can pull in regulators outside a breached vendor’s own sector.

Is Your Company Affected? How to Check

With roughly 195 to 200 companies exposed but only about 16 named publicly as of late July 2026, most affected organizations have not said anything yet. Not seeing your company’s name in a headline is not the same as confirmation that you were not affected.

A few concrete steps can help security and IT teams figure out where they stand:

  • Check Salesforce’s Connected Apps and OAuth grant list for any entry tied to Klue, including integrations that were only ever run as a pilot or trial.
  • Ask your Klue account team directly whether your instance was among the accounts with exposed OAuth tokens, rather than waiting for an unprompted notice.
  • Search inboxes and ticketing systems for a breach notification from Klue, since the company’s own June 15, 2026 disclosure described only “an unspecified number” of affected customers.
  • Review Salesforce login and API access history around June 12, 2026, the date Klue says it detected unauthorized activity, for unfamiliar IP ranges or bulk data pulls.
  • Treat any Klue integration, active or dormant, as a credential that needs to be rotated or revoked now rather than reviewed later.

Huntress has publicly said it expects the real number of affected Klue customers to climb once more companies complete their own reviews, which is another reason to check directly rather than assume the absence of a headline means the absence of exposure.

LastPass and BeyondTrust: What Was Exposed, What Wasn’t

LastPass has been the most detailed of the named victims about scope, which matters given its product is literally a vault for other people’s passwords. In a statement covered by BleepingComputer, the company said: “The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.” LastPass also said the exposure was “limited to standard business contact information and related CRM data,” including names, phone numbers, email addresses, physical addresses and support case content, and stated plainly that “LastPass products, services, and infrastructure were not impacted in any way, and customer vaults remain secure.”

BeyondTrust’s disclosure followed a similar shape: business contact and sales-related information taken from its Salesforce instance, with no indication that its privileged-access-management products themselves were touched. BeyondTrust’s initial notification reportedly went unnoticed for a period before its scope became public, a reminder that vendor breach notifications can arrive quietly through account managers long before they become news stories.

That distinction, CRM data versus core product compromise, is the difference between an embarrassing disclosure and an existential one. It is also exactly the distinction that is easy to lose in headlines that just say “LastPass breached.”

A Second Front: Backdoors Hit Trivy, Bitwarden and Checkmarx

The Klue incident did not happen in isolation. In the same stretch of 2026, TechCrunch’s mid-year breach roundup also documented a separate, ongoing supply chain campaign against open-source security tooling. Aqua Security’s Trivy scanner, the password manager Bitwarden, and the code-analysis platform Checkmarx were each hit, with attackers distributing backdoored copies capable of stealing passwords, credentials and other sensitive tokens from anyone who installed them.

Klue and the Trivy-Bitwarden-Checkmarx incidents are not the same attack, and there is no public evidence tying them to the same group. But they share a target profile: tools and platforms that security teams trust by default, compromised at the supply-chain layer rather than through a direct attack on the end customer. For defenders, the practical lesson is identical either way. Trust in a vendor’s name is not the same as verification of a vendor’s current security posture.

The Icarus Playbook: Double Extortion and a Ransom Note From Australia

Icarus, the group that claimed credit for the Klue intrusion, followed a familiar extortion script: breach quietly, exfiltrate broadly, then threaten public disclosure on a leak site unless a ransom is paid. Klue reportedly reached an agreement with the group to keep the stolen data from being published, which implies a payment was made, though Klue has not confirmed that publicly.

Paying did not close the exposure. A second, separate hacking group is reported to have also obtained a portion of the same stolen Klue customer data, meaning victims potentially face extortion attempts from more than one direction even after Klue’s own negotiation. That is the sharpest argument against treating a ransom payment as a resolution: once data leaves the network, the number of parties who might hold a copy is no longer something the paying company controls.

Why This Keeps Happening: Fourth-Party Risk in the SaaS Supply Chain

Every company on the victim list almost certainly runs a vendor risk management program. Most of them likely reviewed Klue before connecting it to Salesforce. None of that caught a credential that predates most current vendor-risk questionnaires by two or three years. Point-in-time vendor assessments are good at catching problems that exist on the day of the review. They are much weaker at catching a token that was fine in 2022 and is simply never looked at again.

Echoes of the 2025 Salesloft Drift Breach

This is not a new pattern. Between August 9 and 17, 2025, a group tracked as UNC6395 stole OAuth tokens from Salesloft’s Drift chatbot integration and used them to pull data out of more than 700 Salesforce environments, including Cloudflare, Google, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud and Zscaler, according to Google’s Threat Intelligence team. Salesloft and Salesforce revoked the affected tokens on August 20, 2025, and Drift was pulled from the Salesforce AppExchange while the investigation continued.

Tanium shows up on both victim lists, ten months apart, hit once through Drift and once through Klue. Two unrelated integrations, the same underlying failure mode: a third-party app with standing OAuth access into Salesforce, compromised, then used to bulk-export CRM data at scale. If a company’s response to the 2025 incident was to review its Salesloft connection and move on, the Klue breach is evidence that the fix needed to be broader than that.

The 2026 Breach Landscape by the Numbers

Metric2026 FigureSource
Global average cost of a data breach$4.88 millionSentinelOne
Forecast global ransomware damage costs$74 billionSentinelOne
Increase in global data breaches vs. prior year40%SentinelOne
Security leaders citing AI-powered attacks as top challenge53%SentinelOne
Cloud breaches traced to compromised identities70%SentinelOne
Average time to detect a breach277 daysSentinelOne
Average time to detect a credential-based breach328 daysSentinelOne
Average weekly cyberattacks per organization1,968 (+18% year over year)SentinelOne
Global cybersecurity spending$240 billion (+12.5% year over year)SentinelOne
Companies confirmed impacted by Klue breach (as of late July 2026)~16 of an estimated 195-200 exposedSecurityWeek, TechCrunch

Read against those numbers, courtesy of SentinelOne’s 2026 cybersecurity statistics, the Klue breach looks less like an outlier and more like a data point inside a broader trend of identity- and credential-driven compromise. Seventy percent of cloud breaches tracing back to compromised identities is not a coincidence sitting next to a breach caused by an un-rotated four-year-old token.

Market Impact: Cyber Insurance, SaaS Vendors and the Cost of Trust

The direct financial fallout from the Klue breach itself has not been disclosed by any of the named companies. The more measurable impact is likely to show up sideways rather than in a single headline number. Cyber insurance underwriters increasingly ask about third-party integration reviews and credential rotation policies during renewal, and a breach with this many named enterprise customers gives underwriters a concrete case to point to when tightening those questions.

There is also a trust cost specific to the security vendors on the list. Snyk sells developers on catching vulnerable dependencies. Tanium sells IT teams on knowing everything running on their endpoints. HackerOne sells the promise of coordinated, trustworthy vulnerability handling. A CRM-layer breach does not touch any of those core products directly, but it still hands competitors and skeptical prospects an easy talking point in a sales cycle. In a market where several of these categories are already crowded, that reputational friction is arguably a bigger cost than the CRM data itself.

Competitive Comparison: How the Named Vendors Responded

A Tale of Two Disclosures

LastPass’s response is worth studying as close to a best-practice template given the circumstances: a specific statement of what was and was not touched, an explicit line about vault integrity, and a public timeline within roughly ten days of the initial intrusion. BeyondTrust’s substance was similar, but its notification reportedly took longer to register publicly. Klue itself sits at the other end of the spectrum. Its June 15, 2026 statement described “an unspecified number” of affected customers, and its CEO did not respond to press inquiries as the story grew over the following two weeks.

The pattern is consistent with how these incidents usually play out: the company at the center of the breach tends to say the least, while the downstream customers with the most reputational exposure end up doing the public explaining on its behalf.

Industry and Regulatory Reaction

Security researchers and incident responders have pointed to the Klue breach as further evidence that OAuth and API token governance deserves the same scrutiny as password policy, particularly for SaaS platforms with broad read access into a CRM. Because the exposed data was largely business contact and support-case information rather than financial or health records, the breach is unlikely to trigger the heaviest state-level breach notification thresholds in the U.S. on its own. It nonetheless lands inside a 2026 regulatory environment already paying closer attention to software supply chain risk: FINRA has issued a member alert citing the breach’s June 12, 2026 detection date, and the incident follows a string of unrelated breaches this year involving Match Group, Nintendo’s TinyPulse-linked incident, and KDDI, each of which pushed regulators and enterprise customers to ask harder questions about vendor data handling.

Several of the named victims, including LastPass and BeyondTrust, said they notified law enforcement and are cooperating with Klue and Salesforce on the investigation. That cooperation is standard, but it also means the full scope of the breach, including whether the 195-to-200 figure grows, likely will not be finalized for months.

5 Predictions for the Rest of 2026

  • More named victims surface. That prediction already played out once: 8×8, Pendo, NoPass and GMS confirmed impact after our initial reporting, pushing the named-victim count to at least 16. Huntress has said it expects additional Klue customers to come forward once internal reviews finish, so today’s list is still very likely a floor, not a ceiling.
  • Cyber insurers tighten SaaS integration questions. Expect renewal questionnaires to ask more directly about credential age and OAuth grant review cadence, not just whether a vendor risk program exists on paper.
  • A wave of OAuth token audits. Security teams at companies with heavy Salesforce and CRM integration footprints are likely to run one-off audits of every connected app’s token age and scope in the weeks following this disclosure, mirroring what happened after the 2025 Salesloft Drift breach.
  • Security vendors face sharper procurement questions. Enterprise buyers evaluating Snyk, Tanium, HackerOne and similar vendors are likely to add explicit questions about this breach into RFPs for the rest of 2026.
  • Double-extortion complicates ransom math further. With a second group reportedly holding a portion of the stolen Klue data independent of Klue’s own negotiation, expect more public discussion of why paying an initial ransom demand no longer guarantees data does not surface elsewhere.

How Engineering Teams Can Cut Fourth-Party OAuth Risk

Nothing here requires new tooling budgets. It requires treating third-party OAuth grants with the same lifecycle discipline as employee credentials: an expiration date, an owner, and a recurring review. A simple internal audit pattern looks like this in concept.

# Illustrative credential-hygiene check (conceptual, not a specific vendor's tool)
for integration in third_party_integrations:
    age_days = today - integration.credential_issued_date
    if integration.usage == "pilot" and age_days > 90:
        flag_for_offboarding(integration)
    if integration.last_reviewed is None or age_days_since(integration.last_reviewed) > 180:
        flag_for_review(integration)
    if integration.oauth_scope in ["full_access", "api_all"]:
        flag_for_scope_reduction(integration)

Three habits would have shortened the Klue breach’s blast radius. First, time-boxing pilot credentials so they expire automatically instead of relying on someone remembering to revoke them. Second, scoping OAuth grants to the minimum object-level access a given integration actually needs, rather than broad CRM-wide read access by default. Third, maintaining a live inventory of every connected app with standing API access, since a breach at any one of them can move as fast as this one did once the tokens were in an attacker’s hands.

Frequently Asked Questions

What is Klue, and why did its breach affect so many other companies?
Klue is a competitive-intelligence platform that connects to customers’ CRM systems, including Salesforce, to track competitor activity. Because it held OAuth tokens for hundreds of customer integrations, a breach of Klue itself gave attackers a path into each of those connected Salesforce environments.

When exactly did the Klue breach happen?
Klue’s investigation and TechCrunch’s reporting place the intrusion on June 12, 2026, the date Klue says it identified unauthorized activity tied to the compromised credential, with Klue disclosing the incident on June 15, 2026. The breach did not become widely known until TechCrunch’s reporting and a wave of vendor confirmations in June and July 2026, which is when most of the roughly 195-200 affected companies were named or came forward publicly.

Which companies confirmed they were affected by the Klue data breach?
LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, Huntress, Gong, OneTrust, Sprout Social, Insurity, 8×8, Pendo, NoPass and GMS have all confirmed impact, out of close to 200 companies whose data was reportedly exposed inside Klue’s systems.

Was LastPass’s password vault compromised in the Klue breach?
No. LastPass has stated explicitly that its products, services and infrastructure were not affected and that customer vaults remain secure. The exposed data was limited to business contact information and Salesforce CRM and support-case records.

Who is behind the Klue breach?
An extortion group calling itself Icarus claimed responsibility and reportedly reached an agreement with Klue not to publish the stolen data. A separate hacking group is also reported to hold a portion of the same stolen data.

How does the Klue breach compare to the 2025 Salesloft Drift breach?
Both incidents used stolen OAuth tokens from a connected third-party app to bulk-export data from Salesforce environments. The 2025 Salesloft Drift breach, attributed to a group tracked as UNC6395, hit more than 700 organizations between August 9 and 17, 2025. Tanium was named as a victim in both incidents.

Were Trivy, Bitwarden and Checkmarx part of the same attack as Klue?
No public evidence links them to the same group or campaign. They were separately compromised through backdoored software copies in a supply chain attack documented around the same time, and are best understood as a parallel trend rather than the same incident.

What should companies do to reduce risk from similar OAuth-based supply chain attacks?
Security teams generally recommend maintaining a current inventory of every third-party app with API access to core business systems, time-boxing pilot or trial integrations so unused credentials expire automatically, scoping OAuth grants to the minimum necessary access, and reviewing token age on a recurring schedule rather than only at initial vendor onboarding.

How many companies were affected in total by the Klue breach?
Reporting puts the number of companies with data exposed inside Klue’s systems at roughly 195 to 200, though only about 16 had publicly confirmed impact as of late July 2026, with more expected to come forward as investigations continue.

Has the number of confirmed Klue breach victims grown since June 2026?
Yes. Since our late-June reporting, four more organizations — 8×8, Pendo, NoPass and GMS — have publicly confirmed impact, bringing the total to at least 16 named victims as of late July 2026. The overall exposure estimate remains roughly 195 to 200 companies. Huntress has said it expects that number to climb further once more companies finish reviewing their own logs.

Has any regulator responded to the Klue breach?
Yes. FINRA has issued a member alert referencing the incident and citing the same June 12, 2026 detection date Klue disclosed, signaling that the breach is drawing scrutiny from financial-sector regulators even though Klue itself is not a financial services company.

Is the Klue breach investigation still open as of August 2026?
Yes. Klue, Salesforce and the affected vendors say the investigation remains open, and no additional named victims or revised figures beyond the roughly 195 to 200 companies exposed and 16 publicly confirmed organizations have been reported. That count could still change as more companies complete their own reviews.

Related Coverage

For ongoing coverage of breaches, ransomware and security tooling, see tech-insider.org’s Cybersecurity section.

Elias Virtanen

Elias Virtanen

Cybersecurity Analyst

Elias Virtanen is the Cybersecurity Analyst at Tech Insider, bringing hands-on expertise from his background in penetration testing and security consulting. He previously worked as a security researcher at F-Secure in Helsinki, where he focused on threat intelligence and vulnerability disclosure. Elias covers ransomware trends, zero-trust architecture, and the evolving regulatory landscape including NIS2 and the EU Cyber Resilience Act. He holds a CISSP certification and an MSc in Information Security from Aalto University.

View all articles