LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surface
Recent BreachesData breach tracker

Recent Breaches › 8X8 Inc Discloses Material Cybersecurity Incident (SEC 8-K)

HIGH severityConfirmedHow we verify

8X8 Inc Discloses Material Cybersecurity Incident (SEC 8-K): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 17, 2026
8X8 Inc Discloses Material Cybersecurity Incident (SEC 8-K)

Reported June 17, 2026. Approximately disclosed in filing people affected.

HIGH
Severity
disclosed in filing
People affected
1
Data types exposed
June 17, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

8X8 Inc disclosed a material cybersecurity incident in an SEC 8-K filing on June 17, 2026. Affected individuals should review the filing and take any recommended protective steps.

Severity & verification
HIGH severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the 8X8 Inc Discloses Material Cybersecurity Incident (SEC 8-K) breach?
disclosed in filing accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.
On June 17, 2026, 8X8 Inc filed a disclosure with the U.S. Securities and Exchange Commission stating that an unauthorized third party had gained access to its Salesforce customer relationship management system. The access took place between June 11 and 12, 2026, through a third-party application integration provided by Klue Labs, Inc. Certain information was removed from the system before the activity was identified. The filing does not specify how many individuals are affected or the exact nature of the data removed. Individuals whose records were held in the Salesforce environment now face the possibility that their details have left the company's direct control.

Breaking down the breach

According to the June 17, 2026 SEC 8-K filing, 8X8 was notified on June 13, 2026, that a threat actor had exploited the Klue integration connected to its Salesforce platform. The unauthorized access and subsequent removal of information occurred over the preceding two days. The company stated that it, together with Klue and with support from Salesforce, took immediate steps after discovery.

Public detail on the scale of the incident, the precise method of exploitation, or the volume of data removed remains limited to the statements in the filing. No further technical findings have been released.

How a breach like this happens

Incidents involving third-party integrations often begin with an attacker identifying a trusted connection between a primary system and an external application. Once access is obtained through that connection, the attacker can move into the main environment and locate data repositories such as customer relationship management platforms.

These pathways are attractive because they frequently carry elevated permissions and may receive less continuous monitoring than core internal systems. After initial entry, the focus typically shifts to locating and copying records before detection occurs.

About 8X8 Inc

8X8 Inc provides cloud communications and contact-center services to organizations. Companies in this sector maintain records of customer accounts, service configurations, and support interactions, commonly stored in customer relationship management systems.

A security event affecting such records is consequential because the data can include details used for ongoing business communications and service delivery.

The information in question

The SEC filing describes the removed material only as “certain information” from the Salesforce system. No specific data categories are listed in the available disclosure.

Organizations of this type typically store customer contact details, account identifiers, and interaction histories within their CRM environments. The exact contents exfiltrated in this case remain unconfirmed beyond the general description provided.

Why it matters

Individuals whose information was held in the affected system may encounter follow-on contact attempts that use details originally collected for legitimate business purposes. Such exposure can increase the volume of unsolicited communications or attempts to misuse account-related information.

For the organization, the incident prompted formal regulatory disclosure and required coordinated response with the integration provider and the CRM vendor. The long-term operational or legal consequences are not addressed in the initial filing.

What to do if you're exposed

Review recent account activity for any services connected to 8X8 and consider changing passwords for those accounts. Enable available multi-factor authentication where it is not already active.

Readers can run a free exposure scan of their email address to check whether their information has appeared in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

Company8X8 Inc security record
64/100
DoxxScan™ · Moderate doxx risk
C 66Mixed record

1 reported incident on record.

See 8X8 Inc’s full breach history →

More recent breaches

CID Holdco, Inc Discloses Material Cybersecurity Incident (SEC 8-K)July 22, 2026Upbound Group, Inc Discloses Material Cybersecurity Incident (SEC 8-K)July 21, 2026CareCloud, Inc Discloses Material Cybersecurity Incident (SEC 8-K)March 24, 2026Stryker Hit by Unprecedented 12-Petabyte Data Wipe Listed by handala Ransomware GroupMarch 16, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the 8X8 Inc Discloses Material Cybersecurity Incident (SEC 8-K) →

Source: SEC EDGAR Form 8-K (Item 1.05)

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram