Cyber Incident Victim: HackerOne
Timeline
Summary
HackerOne was among the cybersecurity firms whose data was exposed after attackers infiltrated the Klue platform using a legacy credential tied to an integration tool, gaining access to connected databases such as Salesforce. The intruders, identified as the Icarus group, exfiltrated business contact information including names, email addresses, phone numbers, job titles and some account details, as well as customer support case records and sales‑related data from affected clients. Klue has engaged CrowdStrike to investigate, disabled all external integrations, and has not disclosed whether a ransom demand will be met.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Klue, a Vancouver‑based marketing intelligence platform, discovered unauthorized access to its systems on June 12 2026 when its security team identified hackers operating inside the network. The intrusion was traced to a legacy credential tied to an integration tool that connects client cloud data with Klue accounts, which allowed the attackers to move laterally and reach databases such as Salesforce. The cybercriminal group Icarus publicly claimed responsibility for the breach and issued a threat to release the stolen data on the open web if a ransom payment was not made by a specified deadline. In response, Klue enlisted the cybersecurity firm CrowdStrike to conduct an investigation and contain the incident, while also disabling all external integrations as a precautionary measure to prevent further data exfiltration.

The data taken during the Klue breach primarily consisted of business contact information belonging to the platform’s clients. According to Klue’s disclosure, the compromised data includes full names, email addresses, phone numbers, job titles and some account details for the affected organizations. Among the victims named in the reports are several prominent cybersecurity firms, including HackerOne, Snyk, Recorded Future, Jamf, OneTrust, Tanium and Gong. While the exact volume of records taken from HackerOne has not been specified, the nature of the stolen information aligns with the broader set of business contacts that were exfiltrated from Klue’s systems. No additional details about how HackerOne was notified or what internal steps it took have been provided in the available sources. The attackers have not yet released the data publicly, pending the outcome of the ransom demand, and Klue has not indicated whether any payment was made or if further remediation actions beyond the engagement of CrowdStrike and integration shutdowns have been undertaken.
