Klue Cyberattack Exposes Data from Huntress, HackerOne, Jamf, and Other Cybersecurity Firms

A breach at Vancouver-based market intelligence firm Klue has resulted in data being stolen from multiple corporate customers, including some of the largest names in cybersecurity. Cybercrime group Icarus has claimed responsibility for the attack and threatened to publish the stolen data if a ransom is not paid.

Klue disclosed the incident on Friday, June 22, 2026, revealing that hackers had gained access to its systems on June 12 using a “compromised legacy credential” tied to an integration tool that allows customers to connect their cloud data to Klue’s platform. Through that access, the attackers were able to reach customers’ cloud databases, including Salesforce instances that typically store personal customer information.

Companies confirmed to have had data stolen include Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, and Huntress. The stolen data largely consists of business contact information such as names, email addresses, phone numbers, job titles, and some account details. Huntress confirmed it received a ransom note sent via a misused Australian company’s email address.

Klue has not disclosed how many of its hundreds of customers are affected. CEO Jason Smith did not respond to requests for comment. The company does not currently list a cybersecurity executive on its leadership page. Klue laid off approximately half its staff — around 100 people — in June 2025 as part of a shift toward AI investment, though it is not clear whether that reduction contributed to any security lapses.

Klue has engaged incident response firm CrowdStrike and has disconnected its customer integrations to prevent further data access. It is not yet known how the credentials were originally compromised.

The attack follows a pattern of hackers targeting middleware and data integration providers — including Gainsight and Salesloft — to access data across many organizations at once by exploiting a single point of failure.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top