LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Additional Klue Supply-Chain Breach Victims Identified

HIGH severityReportedHow we verify

Additional Klue Supply-Chain Breach Victims Identified: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 18, 2026
Additional Klue Supply-Chain Breach Victims Identified

Reported June 18, 2026.

HIGH
Severity
3
Data types exposed
June 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Additional Klue supply-chain breach victims have been identified, with the incident disclosed on 18 June 2026. Business contacts, support data, and CRM data were exposed, and affected individuals should check their status and take appropriate protective steps.

Severity & verification
HIGH severityReported
Account credentials exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Reports on June 18, 2026, identified Klue as the source of a supply-chain style incident in which attackers used legacy credentials to reach connected customer environments. The compromise occurred in mid-June 2026 and involved roughly two dozen Salesforce instances belonging to Klue customers. Several of those customers, including AlertMedia, Blackbaud and Camunda, later confirmed exposure of their data.

Incidents that originate in one vendor and affect multiple downstream organisations have become a recurring feature of the current threat landscape. When a platform holds integration tokens or credentials that reach customer systems, a single point of failure can expose data across an entire client base.

What happened

Attackers obtained legacy credentials that allowed access to OAuth tokens. With those tokens they reached Salesforce instances connected to Klue and removed business contact and support data. The number of individuals whose records were taken remains unknown. The actor using the name Icarus stated an intention to publish the material.

Public detail on the precise timeline of discovery, the volume of records, or the method used to obtain the initial credentials has not been released.

How a breach like this happens

Many SaaS platforms maintain long-lived credentials or OAuth tokens to enable integrations with customer systems such as Salesforce. When those credentials are not rotated or are stored in locations reachable by an external party, an attacker who obtains them can impersonate the legitimate integration. Once inside the connected environment, the attacker can enumerate and export contact lists, case records and other CRM objects without triggering alerts that would normally accompany a direct login to the customer tenant.

Supply-chain compromises of this type do not require the attacker to breach every target organisation individually; access to the intermediary platform is sufficient.

About Klue

Klue operates a competitive-intelligence platform used by sales and marketing teams. The service aggregates market signals and frequently connects to customer relationship-management systems to pull account and contact information. Because these connections rely on stored authentication material, the platform holds a concentrated set of access rights across many client environments.

A breach at such a provider therefore carries consequences beyond the vendor itself, extending to any organisation that has enabled the integration.

The information in question

The reported incident names business contacts, support data and CRM data as the categories accessed. The exact fields contained within those categories, the number of records, or whether additional data types were present have not been disclosed by Klue or the affected customers.

What's at stake

Business contact information can be used for targeted outreach or social-engineering attempts against the individuals listed. Support and CRM records may contain notes on account status, purchasing history or internal processes that could inform competitive intelligence gathering by third parties. For the organisations involved, the incident adds the operational burden of notifying clients, reviewing integration security and potentially resetting multiple OAuth connections.

The organisation faces reputational and contractual questions from customers whose data left its control.

If your data was in this claimed breach

Organisations that used Klue should review logs for any unusual Salesforce activity around mid-June 2026 and rotate any OAuth tokens issued to the platform. Individuals whose contact details may have been included can treat unsolicited messages with additional caution and monitor accounts linked to those addresses.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyKlue security record
71/100
DoxxScan™ · Moderate doxx risk
C+ 71Fair record

1 reported incident on record.

See Klue’s full breach history →

More recent breaches

Brazilian IT Firm Service IT Breached by WorldLeaksJuly 3, 2026Nissan Discloses Employee Data Breach via Oracle PeopleSoft Zero-DayJune 25, 2026Icarus Group Steals Salesforce Data via Klue OAuth BreachJune 18, 2026Emmy.tv AWS Credentials Exposed in Public HTMLJune 3, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Additional Klue Supply-Chain Breach Victims Identified →

Source: SecurityWeek

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram