CSIDB logo
Incident

HackerOne

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-08 09:19

Linked entities

Victim
HackerOne
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Klue experienced a cyberattack when threat actors exploited a legacy credential tied to an integration tool that links client cloud data to the platform, gaining access to its databases including Salesforce. The attackers, identifying themselves as the Icarus group, exfiltrated business contact information such as names, email addresses, phone numbers, job titles and some account details, as well as customer support case and sales‑related data from several cybersecurity firms including HackerOne, Recorded Future, Tanium, LastPass, Snyk, Jamf, OneTrust and Gong. They threatened to publish the stolen data unless a ransom was paid. In response, the platform enlisted CrowdStrike to investigate, disabled all external integrations, and has not disclosed whether any ransom payment was made.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 12 2026 the marketing intelligence platform Klue detected unauthorized activity in its systems and later identified the intrusion as the work of a hacking and extortion group that calls itself Icarus. According to Klue’s own statement, the attackers gained entry through a legacy credential tied to an integration tool that connects clients’ cloud data with Klue accounts, which allowed them to reach internal databases including Salesforce. Icarus publicly claimed responsibility for the breach and threatened to release the stolen data unless a ransom was paid, a claim that was echoed in multiple media reports covering the incident. The breach was not isolated to Klue; several of its customers, including prominent cybersecurity firms, confirmed that their data had been exfiltrated as a result of the attack. Among those named were HackerOne, Recorded Future, Tanium, Snyk, Jamf, OneTrust and Gong, with Klue noting that hundreds of its clients were potentially affected.

The data taken by the attackers consisted primarily of business contact information such as full names, email addresses, phone numbers, job titles and some account details, which experts warned could be used to craft more sophisticated phishing campaigns. LastPass, in its own notification to customers about the Klue breach, listed HackerOne as one of the companies whose customer support case data and sales‑related information had been compromised, although the specific contents of those tickets were not disclosed. The exposure of this information raised concerns about possible follow‑on attacks targeting the individuals whose contact details were stolen, though no concrete instances of misuse have been reported in the available sources. The scope of the leak was described as significant given the number of high‑profile organizations that rely on Klue for market intelligence and the sensitivity of the contact data involved.

In response to the intrusion, Klue engaged the cybersecurity firm CrowdStrike to conduct an investigation and to help mitigate the consequences of the breach. As a precautionary measure, the company disabled all external integrations while the investigation proceeded, aiming to prevent further unauthorized access. Klue has not disclosed whether any ransom payment was made to Icarus, nor has it provided a precise count of how many HackerOne records were affected, stating only that the firm confirmed its data was among those stolen. The incident remains under review, with both Klue and its customers monitoring for any signs of the leaked data being misused.

Sources

Sources available to members: 2 sources.

CSIDB