TenMinutesAgo.com — News & Entertainment Now
BUSINESS

Cybersecurity Firms Targeted in Klue Data Breach

By Rowan Beckett 1 month ago

A data breach at Klue, a market intelligence provider, has exposed information from several major cybersecurity companies. The hacking group Icarus claims responsibility and threatens to publish the stolen data.

A hacking group known as Icarus has claimed responsibility for a significant data breach at Klue, a Vancouver-based market intelligence provider. This breach has resulted in the theft of extensive data from Klue's corporate customers, which include prominent names in the cybersecurity sector.

Klue, which facilitates market research by connecting client data to its systems, announced on Friday that a cyberattack had occurred a week earlier, leading to the unauthorized access of data from some of its customers. The company did not disclose the exact number of affected clients.

The Icarus group stated on its leak site that it plans to release the stolen data on Monday unless Klue agrees to their ransom demands. Several companies have already confirmed that they were victims of the breach, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.

This incident is part of a growing trend in which hackers target middleware providers like Klue, aiming to exploit a single point of failure to gain access to the data of multiple organizations. Over the past year, similar attacks have targeted other middleware firms such as Gainsight and Salesloft.

Klue revealed that the breach occurred on June 12, when hackers accessed their systems using a compromised legacy credential, such as a password or token, linked to an integration tool. This tool enables customers to connect their cloud data to their Klue accounts.

The compromised data includes sensitive information stored in customer clouds, particularly from Salesforce databases, which are often used to hold personal information about clients. The data stolen primarily consists of business contact details, including names, email addresses, phone numbers, job titles, and various account information.

It remains unclear how the hackers obtained the compromised credentials or why Klue failed to detect the breach sooner. Previous similar incidents involving credential misuse, such as those affecting Snowflake and TanStack, have been attributed to employees inadvertently installing malware that steals passwords on their work devices.

In response to the breach, Klue has enlisted the help of incident response firm CrowdStrike and has disconnected its integrations to mitigate further access to customer information.

When approached for comment by TechCrunch on Monday, Klue's CEO Jason Smith did not respond to inquiries regarding the incident, including whether the company has received communication from the hackers about the ransom.

Huntress, one of the affected security firms, reported that the hackers had reached out to them with a ransom note using an email address from an Australian company, suggesting that the servers of this company were misused during the attack.

In June of the previous year, Klue announced plans to lay off approximately half of its workforce, around 100 employees, as part of a strategy to focus more on artificial intelligence investments. It is uncertain if these staffing reductions contributed to any security lapses within the company. Additionally, Klue does not currently list an individual responsible for cybersecurity on its executive leadership page.

The tech community is urged to come forward with any additional information regarding the Klue cyberattack. Affected companies or individuals can contact Zack Whittaker securely via Signal or email.

cybersecuritydata breachhackingklueicarus
Filed under Business