惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
月光博客
月光博客
MyScale Blog
MyScale Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
爱范儿
爱范儿
P
Proofpoint News Feed
人人都是产品经理
人人都是产品经理
Last Week in AI
Last Week in AI
罗磊的独立博客
G
Google Developers Blog
Y
Y Combinator Blog
博客园 - 【当耐特】
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
J
Java Code Geeks
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
美团技术团队
宝玉的分享
宝玉的分享
Jina AI
Jina AI
小众软件
小众软件
T
Tailwind CSS Blog
A
About on SuperTechFans

TechCrunch

Robots beat human records at Beijing half-marathon Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures TechCrunch Mobility: Uber enters its assetmaxxing era Cracks are starting to form on fusion energy’s funding boom Blue Origin successfully re-uses a New Glenn rocket for the first time ever Tesla brings its robotaxi service to Dallas and Houston VC Ron Conway says he has a ‘rare form of cancer’ AI chip startup Cerebras files for IPO Anthropic’s relationship with the Trump administration seems to be thawing The App Store is booming again, and AI may be why “Tokenmaxxing” is making developers less productive than they think Hackers are abusing unpatched Windows security flaws to hack into organizations Zoom teams up with World to verify humans in meetings Gigs turns your concert history into a personal live music archive Chef Robotics escaped the robot cooking graveyard and says it’s thriving — here’s why Uber will now pick up your returns from your doorstep Anthropic launches Claude Design, a new product for creating quick visuals Google’s AI Mode can now help you find products in stock nearby Bluesky confirms DDoS attack is cause of continued app outages Bluesky confirms DDoS attack is cause of continued app outages Netflix plans to add a vertical video feed, use AI for recommendations SaySo is a new short-form video app that aims to restore users’ trust in news Loop raises $95M to build supply chain AI that predicts disruptions Are we tokenmaxxing our way to nowhere? New leaders, new fund: Sequoia has raised $7B to expand its AI bets Netflix co-founder and chair Reed Hastings to leave board Upscale AI in talks to raise at $2B valuation, says report Physical Intelligence, a hot robotics startup, says its new robot brain can figure out tasks it was never taught From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation
Klue says hackers stole credential from 2022 that led to ...
Zack Whittaker · 2026-06-24 · via TechCrunch

Market research company Klue has confirmed that a credential dating back to 2022, which was part of a limited pilot, was used by hackers earlier this month to steal reams of data from its corporate customers, including several cybersecurity companies.

The new detail suggests that Klue may have had years to decommission the credential that was used for the pilot, raising questions about the company’s security posture and what actions it could have taken to prevent the breaches of its customers’ data.

The hack at Vancouver-based Klue, which it detected on June 12 and first disclosed last Friday, allowed hackers to steal data from a number of its customers, including password manager maker LastPass and several other cybersecurity companies. The hackers used their access to Klue’s systems, which store the keys — known as OAuth tokens — to access their customers’ data stored in other clouds and databases, to download that data, and extort the companies.

Klue spokesperson Katie Berg told TechCrunch that the company’s investigation so far indicates that the credential used by the hackers to steal customers’ data “was originally provided to a third-party in 2022, for a limited pilot.”

When asked by TechCrunch, Klue would not explain the purpose of the pilot, how long it ran, or identify the third-party that the company gave the credential to. Klue also did not share why the credential wasn’t revoked following the conclusion of the pilot.

Klue did not respond to follow-up emails about the incident before publication.

Questions remain about the incident as the company says its investigation is continuing.

Klue hasn’t said what kind of credential was stolen, only stating in a blog post that it was a “legacy credential associated with an integration service.” Klue also would not say whether the credential was an employee’s username and password, for example, or if the company believes the credential was stolen from the third-party rather than from its own systems. 

These details may be crucial to understanding how the breach was carried out — and how to prevent a repeat incident.

Klue’s statement to TechCrunch added that the company is “conducting a comprehensive review of credential management, vendor-access controls, monitoring capabilities, and deployment security processes,” offering no further details.

A hacking group called Icarus took credit for the breach on its data leak site, and has publicly threatened to release the stolen data if its ransom isn’t paid.

Klue has not said if it has had contact with the hackers, or if it plans to pay their demands.

Do you know more about the Klue cyberattack? Are you a company affected by the breach? We would love to hear from you. To contact Zack Whittaker securely, reach out via Signal at username zackwhittaker.1337.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio