A major cybersecurity incident has shaken the industry. Klue, a Canadian market intelligence provider, suffered a cyberattack that allowed hackers to steal sensitive data from numerous customers, including some of the biggest names in cybersecurity such as Huntress, HackerOne, Jamf, and Recorded Future. The attack was claimed by the cybercrime group Icarus, which threatens to publish the stolen data unless a ransom is paid.
Compromised legacy credential used for access
According to Klue, the hackers gained access to corporate systems on June 12, 2026, using a compromised legacy credential such as a password or token associated with an integration tool that allows customers to connect their cloud data to Klue's systems. This type of attack exploits a single point of weakness to target many organizations at once, a growing trend in the threat landscape. The stolen data includes business contact information: names, email addresses, phone numbers, job titles, and some account details, primarily from Salesforce databases.
Sponsored Protocol
Affected companies and industry response
Several companies have confirmed involvement: Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium. Huntress reported being contacted by the hackers with a ransom note sent from an Australian company's email address, likely misused as a relay. Klue has engaged incident response firm CrowdStrike and disconnected integrations to limit further damage, but has not yet disclosed the exact number of affected customers or whether it received any ransom demand. CEO Jason Smith has not responded to requests for comment.
Sponsored Protocol
Lessons for Italian SMEs and global businesses
This incident underscores the vulnerability of digital supply chains. Italian SMEs using middleware providers like Klue must be aware of the risks associated with legacy credentials and inadequate access controls. Similar attacks have occurred with Gainsight and Salesloft, showing how a single point of failure can compromise hundreds of organizations. For further reading on data breach prevention, consult the Wikipedia page on data breaches (Data breach). Additionally, for more tech industry news, see the article on Polymarket illustrating how even robust platforms can face controversies.
Source: https://techcrunch.com/2026/06/22/klue-hack-results-in-data-breach-at-several-cybersecurity-firms