BreachesUpdated 7 min read

The Klue Breach, Explained: One Forgotten Credential, Nearly 200 Companies

By Scott, Clearfront founder

One credential, issued in 2022 for a pilot that never shipped and never revoked, let a hacking group pull customer data out of the Salesforce environments of close to 200 companies in June 2026, LastPass, HackerOne and Snyk among them. Nobody hacked Salesforce, and nobody hacked LastPass. The attackers walked in through Klue, a market intelligence tool the affected companies used and you have probably never heard of. Here is what happened, who is affected, and the uncomfortable lesson in it for your own accounts.

What happened in the Klue breach?

On 12 June 2026 Klue, a platform that sales and marketing teams use to track competitors, detected an intruder in its systems. A group calling itself Icarus had got in with a legacy credential that Klue says was issued to a third party in 2022 for a limited pilot. The pilot ended. The credential stayed active for roughly four years.

Inside Klue's infrastructure the group found OAuth tokens, the keys Klue's integrations use to connect to its customers' other software. With those tokens Icarus reached into the connected Salesforce environments of Klue's customers and pulled data out in bulk with automated scripts. Salesforce itself was not compromised, and neither were the victims' own networks. The tokens made the access look legitimate.

Which companies are affected?

More than a dozen companies have publicly confirmed impact so far, and the list reads like a security conference speaker lineup: LastPass, HackerOne, Snyk, Huntress, Recorded Future, Tanium, BeyondTrust, OneTrust, Jamf, Sprout Social, 8x8, Pendo and Insurity among them. Reporting on the group's leak site puts the full number of exposed Salesforce environments close to 200, and disclosures are still arriving.

The skew toward security vendors is not an accident. Klue sells competitive intelligence, security companies track their competitors like everyone else, and so the victims of this breach include the companies other companies hire to prevent breaches.

What data was stolen?

CRM data: customer names, email addresses, phone numbers, physical addresses, support case histories and sales records. LastPass confirmed that its products, infrastructure and customer vaults were untouched. What left was the business information its Salesforce instance held about its customers.

It is tempting to file contact details and support tickets as harmless compared to passwords. They are not. A support case history tells an attacker who you are, which product you use, and what you last asked its support team, which is a ready-made script for a convincing phishing email. LastPass is already warning customers about fraudulent sender domains impersonating it.

Why did a credential from 2022 still work?

Because nobody turned it off. Klue describes it as a legacy credential associated with an integration service, created for a pilot that was never shipped. No vulnerability was exploited in Klue's product, in Salesforce, or in any employee account. The weakest point in the chain was an account nobody remembered existed.

The pattern is familiar. The Salesloft Drift breach of 2025 used the same route, stolen OAuth tokens opening the Salesforce environments of hundreds of companies. Supply-chain attacks keep working because every tool a company connects inherits the security of the least-watched credential anywhere in the chain.

Is the Klue breach over?

Not cleanly. Klue has said the attackers committed to deleting the stolen data, while reporting describes a second group surfacing with extortion demands built on the same theft. Salesforce and Gong have disabled their Klue integrations, and the investigation is ongoing.

What does this mean for you?

Your personal details do not only live with the companies you chose. They live in the Salesforce instance of every vendor those companies use, and in the CRM of every vendor of those vendors. You cannot audit that chain, and no setting on any of your accounts would have kept your support tickets out of this one. If a company you use appears on the victim list, expect sharper phishing and verify every email against the company's own site before acting on it. The practitioners arguing this out in public are worth reading too, and I summarised them in what Reddit says about the Klue breach. Work addresses are the ones most exposed by a breach of this shape, and I covered why, and how to check yours, in is your work email in a data breach.

What you can audit is your own chain. The forgotten credential that opened Klue has a personal equivalent: the accounts you opened years ago and never closed, the reused passwords sitting in breach dumps and infostealer logs, the profiles still public under an old username. Clearfront scans 3,400+ public data sources in one sweep locally, finds the accounts, breaches and credentials tied to your identity, and an AI security analyst reports what to close first. Install Clearfront free and run it on yourself, or get the free removal guide to start shrinking what an attacker can reach.

Frequently asked questions

Was LastPass hacked in 2026?
Not directly. Attackers reached the Salesforce environment LastPass uses through its vendor Klue and took CRM data: names, contact details, support cases and sales records. LastPass states its products, infrastructure and customer password vaults were not affected.
How many companies were affected by the Klue breach?
More than a dozen companies have publicly confirmed impact, including LastPass, HackerOne, Snyk, Huntress, Recorded Future, Tanium and BeyondTrust. Reporting based on the attackers' leak site puts the full number of exposed Salesforce environments close to 200.
What is the Icarus hacking group?
Icarus is the extortion group that claimed the Klue compromise. Rather than encrypting systems the way ransomware does, it steals data and threatens to publish it unless victims pay.
What should I do if I get an email about the Klue breach?
Treat it as hostile until proven otherwise. The stolen data includes real support case details, which makes convincing fakes easy. Do not click links in the email. Go to the company's website directly and use its published support channels. LastPass has specifically warned about fraudulent sender domains.

I believe your personal data is yours to own and protect. I built Clearfront, a free, open-source tool for scanning and scrubbing your own digital footprint from public data, and I write here about OSINT, breach exposure, and personal privacy.

Scott

Clearfront founder