惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
G
Google Developers Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
腾讯CDC
有赞技术团队
有赞技术团队
Vercel News
Vercel News
MongoDB | Blog
MongoDB | Blog
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog RSS Feed
I
InfoQ
Blog — PlanetScale
Blog — PlanetScale
博客园_首页
The Cloudflare Blog
B
Blog
C
Check Point Blog
Stack Overflow Blog
Stack Overflow Blog
IT之家
IT之家
U
Unit 42
D
Docker
月光博客
月光博客
aimingoo的专栏
aimingoo的专栏
博客园 - Franky
A
About on SuperTechFans

TechCrunch

Robots beat human records at Beijing half-marathon Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures TechCrunch Mobility: Uber enters its assetmaxxing era Cracks are starting to form on fusion energy’s funding boom Blue Origin successfully re-uses a New Glenn rocket for the first time ever Tesla brings its robotaxi service to Dallas and Houston VC Ron Conway says he has a ‘rare form of cancer’ AI chip startup Cerebras files for IPO Anthropic’s relationship with the Trump administration seems to be thawing The App Store is booming again, and AI may be why “Tokenmaxxing” is making developers less productive than they think Hackers are abusing unpatched Windows security flaws to hack into organizations Zoom teams up with World to verify humans in meetings Gigs turns your concert history into a personal live music archive Chef Robotics escaped the robot cooking graveyard and says it’s thriving — here’s why Uber will now pick up your returns from your doorstep Anthropic launches Claude Design, a new product for creating quick visuals Google’s AI Mode can now help you find products in stock nearby Bluesky confirms DDoS attack is cause of continued app outages Bluesky confirms DDoS attack is cause of continued app outages Netflix plans to add a vertical video feed, use AI for recommendations SaySo is a new short-form video app that aims to restore users’ trust in news Loop raises $95M to build supply chain AI that predicts disruptions Are we tokenmaxxing our way to nowhere? New leaders, new fund: Sequoia has raised $7B to expand its AI bets Netflix co-founder and chair Reed Hastings to leave board Upscale AI in talks to raise at $2B valuation, says report Physical Intelligence, a hot robotics startup, says its new robot brain can figure out tasks it was never taught From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation
Klue hack results in data breach at several cybersecurity...
Zack Whittaker · 2026-06-22 · via TechCrunch

A hacking group has taken credit for a breach at market intelligence provider Klue that allowed hackers to steal reams of data from the company’s corporate customers, which include some of the biggest names in cybersecurity.

Vancouver-based Klue, which lets companies conduct market research by connecting their data to its systems, said on Friday that hackers had stolen data from an unspecified number of its customers during a cyberattack a week earlier. (The blog contains the “noindex” code, which tells search engines to not list the page in search results.)

Cybercrime group Icarus took credit for the breach, saying on its leak site that it will publish the stolen data on Monday if the company does not pay the hackers’ ransom.

Klue has not said how many of its hundreds of customers are affected. Several companies have come forward to confirm they had data stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.

This is the latest of a slew of broad-scale hacks in which hackers target companies that hold the keys to other companies’ cloud databases. By breaching firms like Klue, hackers are betting that compromising a single point-of-failure will let them steal data from a large number of organizations at once. Over the past year alone, hackers have increasingly targeted similar middleware providers, including Gainsight and Salesloft, to gain access to hundreds of companies’ data.

Klue said hackers had gained access to the company’s systems on June 12 using a “compromised legacy credential,” such as a password or a token, associated with an integration tool that allows customers to link their company’s cloud data to their Klue accounts. 

The hackers were able to steal data from Klue’s customer clouds, such as Salesforce databases. Companies often store their customers’ personal information in Salesforce databases, making these a prime target.

Much of the stolen data includes business contact information, like names, email addresses, phone numbers, job titles, and some account information of their customers, according to the various affected companies.

It’s not clear how the hackers acquired the compromised credentials, or why Klue did not detect the theft sooner. Similar recent mass-hacks involving the compromise and misuse of credentials, such as at Snowflake and Tanstack, have been linked to employees inadvertently installing password-stealing malware on the devices that they use for work. 

Klue said it has called in incident response firm CrowdStrike, and has disconnected its integrations to prevent further access to customers’ data.

When contacted by TechCrunch on Monday, Klue CEO Jason Smith did not immediately respond to a request for comment, or answer questions about the incident, including if the company has received any communication from the hackers, such as a ransom demand.

Huntress, one of the security companies that had its data stolen in the hack, said in its write-up of the incident that the hackers had contacted it with a ransom note using an Australian company’s email address, whose servers were likely misused for the campaign.

Last June, Klue said it was preparing to lay off around half of its staff, around 100 people, as it doubled down on its AI investments. It’s not clear if the reduction in staff led to lapses in security at the company. It’s not clear who, beyond Smith, is responsible for cybersecurity at the company.

Klue does not currently list a person overseeing cybersecurity on its executive leadership page.

Do you know more about the Klue cyberattack? Are you a company affected by the breach? We would love to hear from you. To contact Zack Whittaker securely, reach out via Signal username zackwhittaker.1337 or by email: zack.whittaker@techcrunch.com.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio