Klue A.I CyberSecurity Scoring
Klue
Company Information
Website:http://www.klue.com
Employees number:199
Number of followers:32,457
NAICS:5112
Industry Type:Software Development
Homepage:klue.com
Klue Risk Score (AI oriented)
Between 0 and 549
KlueSoftware Development
Updated:
04/08/2026
04/08/2026
319/1000
Critical
C
Klue Global Score (TPRM)
xxxx
KlueSoftware Development
Score locked

KlueCritical
Current Score
319C (CRITICAL)
01000
8 incidents
-67.83 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
384
Breach
04 Aug 2026 • Klue
Klue: Klue Data Breach Lawsuit Investigation
Klue Data Breach Exposes OAuth Tokens, Prompts Class Action Investigation
319
CRITICAL-65
KLU1785882933
Klue Data Breach Exposes OAuth Tokens, Prompts Class Action Investigation
A data breach at Klue, a Vancouver-based B2B software company specializing in AI-powered competitive enablement tools, has exposed sensitive OAuth tokens, potentially compromising access to connected services. The incident was discovered on June 22, 2026, prompting an ongoing investigation by the company.
Klue, founded in 2015, serves product marketing, competitive intelligence, and sales teams with platforms designed to track competitors and buyer insights. The breach’s full scope remains under review, but the exposure of OAuth tokens used to authenticate third-party integrations raises concerns about unauthorized access to linked accounts.
Shamis & Gentile P.A., a leading class action law firm, is investigating the breach and potential compensation for affected individuals. Those impacted may be eligible to join a lawsuit, though details on the number of users affected or specific data compromised have not yet been disclosed. Klue has pledged to provide updates as the investigation progresses.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
490
JUNE 2026
554
Breach
25 Jun 2026 • Klue
Klue: Klue Hit by Double Extortion as Second Hacker Group Emerges
Klue Faces Unprecedented Dual Extortion Attack After Data Breach
489
CRITICAL-65
KLU1782428022
Klue Faces Unprecedented Dual Extortion Attack After Data Breach
Vancouver-based market intelligence platform Klue has disclosed a rare and escalating cybersecurity crisis, involving two criminal groups with conflicting extortion demands following a data breach. The incident, first reported by TechCrunch, marks an unusual case of competing threats targeting the same victim highlighting evolving tactics in cyber extortion.
The breach initially involved a hacking group that stole sensitive customer data, including proprietary market research, competitive analysis, and strategic planning materials used by enterprise clients to track rivals. In a surprising turn, the original attackers later claimed they were deleting the stolen files, though Klue’s customers were warned not to assume the threat had passed. Before any relief could set in, a second criminal group emerged, demanding ransom for the same compromised data.
The situation leaves Klue’s enterprise clients including sales and marketing teams at major corporations in limbo, uncertain whether their highly sensitive business intelligence has been destroyed, leaked, or is now in the hands of multiple threat actors. The competitive intelligence sector handles particularly valuable data, such as go-to-market strategies and product roadmaps, which could cause significant damage if exposed.
Security researchers note that while secondary markets for stolen data are not new, the simultaneous, opposing claims from two criminal groups are highly unusual. The first group’s alleged data deletion could be a face-saving exit or genuine reversal, while the second group’s demands suggest they either independently accessed Klue’s systems or acquired the data from the original attackers.
Klue has not disclosed technical details of the breach, the scope of compromised data, or the number of affected customers. The incident underscores the cascading risks of B2B SaaS breaches, where third-party vendors handling critical business intelligence become high-value targets. It also arrives amid growing enterprise concerns over vendor security postures, following high-profile breaches at platforms like Okta and LastPass.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
573
Cyber Attack
17 Jun 2026 • Klue
Huntress, Salesforce and Klue: Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
Klue OAuth Breach Exposes Salesforce Data in Icarus Extortion Campaign
553
CRITICAL-20
HUNSALKLU1781793603
Klue OAuth Breach Exposes Salesforce Data in Icarus Extortion Campaign
A recent OAuth breach at market intelligence platform Klue has enabled the Icarus threat group to steal Salesforce CRM data from multiple organizations as part of an ongoing extortion campaign. The attack, first reported by BleepingComputer and confirmed by cybersecurity firms ReliaQuest and Huntress, has prompted Salesforce to disable the Klue Battlecards integration while investigations continue.
### How the Attack Unfolded
Attackers compromised Klue’s backend systems, leveraging a dormant but active credential from a prototype integration. Once inside, they deployed a malicious code update to harvest OAuth tokens used by customers to connect Klue Battlecards with third-party platforms, including Salesforce.
Using these stolen tokens, the threat actors executed automated Python scripts to query Salesforce’s REST API for nearly 24 hours. Initial reconnaissance targeted the `/services/data/v59.0/sobjects` endpoint, followed by rapid data exfiltration via `/services/data/v59.0/query`. In one case, attackers sent nearly 1,000 queries in 15 minutes, shifting from stealthy reconnaissance to high-speed theft.
### Extortion Demands & Icarus Involvement
While initial activity resembled past attacks by ShinyHunters, BleepingComputer confirmed that the Icarus group active since April 2026 is behind the campaign. Victims received extortion emails from an alias "mr bean" with a Session Messenger ID for contact. Icarus’s data leak site also teased the campaign with a post titled "Get Ready," warning of upcoming corporate listings.
Huntress, one of the affected organizations, confirmed receiving a similar extortion email, with the provided Session ID matching Icarus’s dark web leak site. The stolen data includes business contacts, sales communications, price quotes, competitive intelligence reports, and account details, though no evidence suggests compromise of passwords, payment data, or engineering systems.
### Response & Mitigation
Klue has disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack while addressing the breach. Salesforce has also suspended the Klue Battlecards app, preventing new connections until further notice.
Security firms have shared IP addresses linked to the attacks:
- 138.226.246.94
- 212.86.125.24
- 213.111.148.90
- 94.154.32.160
Organizations using Klue integrations are urged to review logs, revoke OAuth tokens, terminate active sessions, and monitor for unusual API activity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
638
Breach
11 Jun 2026 • Klue
Klue and LastPass: LastPass customer info leaked again after third-party data breach
LastPass Warns Users of Third-Party Breach Exposing Personal Data
573
CRITICAL-65
LASKLU1782319113
LastPass Warns Users of Third-Party Breach Exposing Personal Data
LastPass has notified customers that their personal information was compromised in a June 11 breach of Klue, a third-party market intelligence firm. The stolen data includes names, phone numbers, email and physical addresses, as well as support case and sales-related records. While LastPass emphasized that its own systems and customer vaults remain unaffected, the incident has raised concerns about downstream risks.
The cybercrime group Icarus has claimed responsibility for the attack and is reportedly contacting users with threats to leak their data. Multiple cybersecurity firms using Klue have also experienced data exposure, increasing the potential for phishing and social engineering attacks targeting affected individuals.
The breach adds to LastPass’s troubled security history, particularly its 2022 incidents, which resulted in significant financial losses. Ripple co-founder Chris Larsen lost $150 million in crypto after his private keys were exposed in the 2022 breach. Cybersecurity researcher ZachXBT later linked the incident to additional thefts, including $5.4 million from over 40 addresses in 2024 and $4.4 million from 25 victims in 2023. Two individuals tied to the "AudiA6" crypto-laundering operation were also found to have processed stolen funds from LastPass users.
Last year, the UK’s Information Commissioner’s Office fined LastPass £1.2 million for the 2022 breach, citing inadequate security measures that allowed unauthorized access to its backup database, impacting 1.6 million UK users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
582
Breach
06 May 2026 • Klue
Instructure: Sandoval warns UNR community after Canvas vendor reports security breach
Cybersecurity Incident Impacts Instructure, Potential UNR Data Exposure Under Investigation
517
CRITICAL-65
INS1778185982
Cybersecurity Incident Impacts Instructure, Potential UNR Data Exposure Under Investigation
The University of Nevada, Reno (UNR) disclosed a cybersecurity incident involving Instructure, the vendor behind the Canvas learning management system. In a statement released Wednesday by UNR President Brian Sandoval, the university confirmed that Instructure experienced a data breach, though it remains unclear whether UNR-specific data was compromised.
According to Instructure’s report to the Nevada System of Higher Education (NSHE), exposed information may include names, institutional email addresses, student ID numbers, and private Canvas messages. The company stated that no evidence suggests passwords, dates of birth, government identifiers, or financial data were affected, and the incident has been contained. A forensic investigation is ongoing.
UNR is collaborating with NSHE to determine whether its data was impacted and will provide updates as more details emerge. In the interim, the university advised the campus community to remain vigilant against phishing attempts, particularly unsolicited messages requesting login credentials or personal information. Suspicious activity should be reported to [email protected].
The full scope of the breach and its potential impact on UNR users are still under assessment.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
635
MARCH 2026
633
FEBRUARY 2026
630
JANUARY 2026
753
Breach
01 Jan 2026 • Klue
Klue, VMware and Google: Blog
VMware-Dependent Organizations Face Critical Cybersecurity Risks as Ransomware Disrupts Key Sectors
626
CRITICAL-127
GOOKLUVMW1782304423
VMware-Dependent Organizations Face Critical Cybersecurity Risks as Ransomware Disrupts Key Sectors
A recent surge in ransomware attacks has severely disrupted schools, ports, and manufacturing operations in 2026, coinciding with Google’s patching of its fifth Chrome zero-day vulnerability of the year. The attacks highlight growing vulnerabilities in virtualized infrastructure, particularly for organizations relying on VMware vSphere, which hosts a majority of business-critical workloads including domain controllers, SQL servers, and application servers.
The incidents follow a supply-chain breach targeting Klue, a market intelligence platform used by multiple cybersecurity firms, raising concerns about the cascading effects of compromised third-party services. While the full scope of the Klue breach remains under investigation, the attack underscores the risks of interconnected digital ecosystems, where a single point of failure can expose downstream targets.
The ransomware campaigns have demonstrated a shift in tactics, with threat actors increasingly targeting virtual machines (VMs) a trend that complicates recovery efforts for affected organizations. VMware environments, which dominate enterprise virtualization, have become high-value targets due to their role in hosting sensitive data and critical services. Security experts warn that inadequate VM backup strategies and untested recovery protocols may leave businesses exposed, even with existing protections in place.
Google’s rapid response to the Chrome zero-day (the fifth in 2026) reflects the ongoing arms race between threat actors and software vendors. The vulnerability, which could enable remote code execution, was patched as part of broader efforts to mitigate exploitation risks amid the ransomware surge. Meanwhile, the disruptions to education, logistics, and industrial sectors serve as a stark reminder of the real-world consequences of cyberattacks on essential services.
The incidents arrive as organizations grapple with evolving threats to cloud email security, with Microsoft 365 and Google Workspace remaining primary vectors for phishing and malware distribution. While cybersecurity firms continue to adapt, the Klue breach and ransomware outbreaks signal a need for heightened scrutiny of supply-chain dependencies and virtualized infrastructure resilience.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Breach
01 Jan 2026 • Klue
Klue: Blog
Cyberattack on Klue Platform Triggers Supply-Chain Breach Impacting Multiple Cybersecurity Firms
626
CRITICAL-127
KLU1783520730
Cyberattack on Klue Platform Triggers Supply-Chain Breach Impacting Multiple Cybersecurity Firms
A recent supply-chain attack has compromised multiple cybersecurity firms following a breach of Klue, a market intelligence platform widely used in the industry. The incident highlights growing risks in third-party dependencies, where a single vulnerability can cascade across interconnected organizations.
While details on the attack’s scope and attribution remain limited, the breach underscores the fragility of supply-chain security, particularly for firms relying on shared intelligence or SaaS platforms. The event follows broader concerns about supply-chain threats, including a recent cyberattack on Tata Electronics, a key supplier for Apple and Tesla, which raised alarms about vulnerabilities in manufacturing and logistics networks.
Separately, the U.S. Department of Homeland Security (DHS) is investigating a cyberattack on a critical information-sharing platform used by government agencies and private-sector partners. The probe reflects heightened scrutiny of digital infrastructure supporting federal operations, though specifics on the attack’s impact or perpetrators have not been disclosed.
The incidents arrive amid ongoing discussions about Managed Detection and Response (MDR) and Managed Security Service Providers (MSSPs), with industry analysts emphasizing the need for clearer distinctions between the two models. While MSSPs traditionally offer broader IT and security management, MDR focuses on proactive threat detection and response, often leveraging advanced tools like Security Information and Event Management (SIEM) systems now evolving to meet compliance demands such as the EU’s NIS2 directive.
As cybersecurity firms grapple with these challenges, vendors like Kaseya continue to roll out updates, including enhancements to Autotask (e.g., improved resource planning, ticket triage, and e-invoicing) and new features for MSPs to streamline operations and contract management. The developments reflect the sector’s push to balance innovation with resilience in an increasingly complex threat landscape.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
JUNE 2025
753
Breach
12 Jun 2025 • Klue
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
691
CRITICAL-62
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations.
### What Happened?
On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress.
Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed.
### How the Attack Unfolded
The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain.
### Key Victims & Impact
While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span:
- Password management (LastPass)
- Privileged access (BeyondTrust)
- Endpoint security (Tanium, Jamf)
- Threat intelligence (Recorded Future)
- Bug bounty coordination (HackerOne)
- Application security (Snyk)
Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure.
### Broader Context: A Year of Supply Chain Attacks
The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses.
### Regulatory & Industry Reactions
- Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene.
- Security vendors on the victim list face heightened procurement questions from enterprise buyers.
- Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications.
### Lessons from the Breach
The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires:
- Automated expiration for pilot credentials.
- Minimum-scoped OAuth grants (avoiding broad CRM access).
- Recurring token audits to identify stale integrations.
As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Klue ??
What was Klue's A.I Rankiteo Cyber Score in July 2026 ??
What was Klue's A.I Rankiteo Cyber Score in June 2026 ??
What was Klue's A.I Rankiteo Cyber Score in May 2026 ??
What was Klue's A.I Rankiteo Cyber Score in April 2026 ??
What was Klue's A.I Rankiteo Cyber Score in March 2026 ??
What was Klue's A.I Rankiteo Cyber Score in February 2026 ??
What was Klue's A.I Rankiteo Cyber Score in January 2026 ??
What was Klue's A.I Rankiteo Cyber Score in December 2025 ??
What was Klue's A.I Rankiteo Cyber Score in November 2025 ??
What was Klue's A.I Rankiteo Cyber Score in October 2025 ??
What was Klue's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Klue's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Klue ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Klue's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?