Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The 10 Best WIRED-Tested Handheld Vacuums of 2026

    July 27, 2026

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    July 27, 2026

    BNY Mellon Unit Joins MiCA Register With 15 CASPs

    July 27, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The 10 Best WIRED-Tested Handheld Vacuums of 2026
    • TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
    • BNY Mellon Unit Joins MiCA Register With 15 CASPs
    • Jodrell Bank’s Lovell telescope faces axe in science cuts, BBC understands
    • Thai MP calls for new committee to scrutinize AI data centers’ environmental impact
    • Russia-Ukraine War: Putin Needs New Money Pots
    • Blanche-led DoJ likely to derail Epstein survivors’ pursuit of justice, experts say | Jeffrey Epstein
    • Can a Progressive Win in a Purple State? Abdul El-Sayed Wants to Find Out.
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, July 27
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 27, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain breach evolved into an exceptional case in which a second criminal group claimed to have compromised the first extortion crew and pilfered data that had already been stolen. The result was not simply another ransomware story. It exposed fundamental weaknesses in SaaS integrations, identity-based trust, third-party risk management and executive decision-making.

    Scene of the crime

    Founded in 2015, Klue, a Vancouver, British Columbia-based software-as-a-service (SaaS) company, provides an AI-powered competitive intelligence platform that serves more than 500 customers and employs more than 200 people across North America and Europe. The company has raised approximately $81 million in venture funding. The platform helps organizations monitor competitors, analyze market signals and distribute insights across sales, marketing, product and executive teams. By aggregating public sources, internal knowledge, and third-party data, Klue turns fragmented information into actionable intelligence that supports faster strategic decisions, stronger competitive positioning, and more effective product planning. Klue’s “Battlecards app” integrates with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack, syncing account records, deal data, contact information and call transcripts.

    Cause of the breach

    Klue occupies a privileged position within customer environments since it integrates with platforms such as Salesforce and other collaboration ecosystems. Those integrations rely heavily on OAuth tokens that permit trusted, authenticated access without repeatedly requesting credential inputs. Attackers from the Icarus criminal group discovered an unused but still-active service account credential originally created for a pilot project. That unused, forgotten credential provided an entry point into Klue’s integration infrastructure. Rather than stealing passwords, the attackers harvested OAuth tokens. This distinction matters. Modern identity-based attacks increasingly focus on session tokens and application trust relationships instead of credential theft. Once valid OAuth tokens were obtained, the attackers effectively inherited the permissions granted to Klue within customer environments. They executed extensive Salesforce API queries over a period of hours, extracting customer relationship management data including contact information, quotes, pricing information, sales communications and account records.

    breach Cyber Hacked hackers Klue reality Risk thirdparty
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    Garden Finance Says Solver Breach Caused $450K Drain

    The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days

    MCBS Data Breach Affects 1.2 Million Individuals

    GitHub, PyPI add time-absed defenses against supply chain attacks

    ‘Bullied, beaten up, killed’: Armenia’s drag queens risk it all for the stage

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The 10 Best WIRED-Tested Handheld Vacuums of 2026

    July 27, 2026

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    July 27, 2026

    BNY Mellon Unit Joins MiCA Register With 15 CASPs

    July 27, 2026

    Jodrell Bank’s Lovell telescope faces axe in science cuts, BBC understands

    July 27, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The 10 Best WIRED-Tested Handheld Vacuums of 2026

    July 27, 2026

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    July 27, 2026

    BNY Mellon Unit Joins MiCA Register With 15 CASPs

    July 27, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.