Cyber Incident Victim: Tanium
Timeline
Summary
Tanium disclosed that a breach at its third‑party intelligence provider Klue allowed attackers to obtain OAuth tokens and access Tanium’s Salesforce environment, where they exfiltrated business contact information such as names, email addresses, phone numbers, job titles and account details. The company stated that its own products and services were not affected, there was no evidence of lateral movement, and its ability to serve customers remained unchanged. Klue revoked the compromised credentials, disabled the affected integrations, and worked with CrowdStrike and law enforcement to investigate the incident, which was claimed by the extortion group Icarus.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The Vancouver‑based marketing intelligence platform Klue disclosed on June 22 2026 that it had suffered a cyberattack resulting in the theft of confidential client data. According to Klue representatives, the attackers gained entry on June 12 2026 by exploiting a legacy credential that was tied to an integration tool used to connect clients’ cloud data with Klue accounts. This compromised credential allowed the intruders to access internal databases, including Salesforce instances, and to exfiltrate business‑contact information such as full names, email addresses, phone numbers, job titles and some account details. The Icarus cybercriminal group claimed responsibility for the breach and posted a threat on its own site to release the stolen data on the open web by the following Monday if a ransom demand was not met. Klue has not disclosed how many of its hundreds of clients were affected, but it confirmed that several prominent cybersecurity and software firms were among the victims, namely HackerOne, Snyk, Recorded Future, Jamf, OneTrust, Tanium and Gong.

The stolen data consists primarily of business contact information, which security experts noted could be used as a foundation for more sophisticated phishing campaigns. The Klue incident fits a broader trend observed in recent months where threat actors target intermediary platforms that aggregate credentials or data for many organizations, seeking a higher payoff from a single breach. Similar patterns have been seen in earlier incidents involving the Snowflake and Tanstack platforms, where attackers leveraged access to a central service to reach numerous downstream clients. The exposure of contact details from multiple high‑profile security firms raises concerns about follow‑on social‑engineering attempts against those organizations and their customers.
In response to the breach, Klue engaged the cybersecurity firm CrowdStrike to lead an investigation and to mitigate the ongoing impact. As a precautionary measure, the company temporarily disabled all external integrations to prevent further unauthorized access to client environments. Klue has not publicly disclosed whether it intends to pay the ransom demanded by the Icarus group, nor has it provided a timeline for when the investigation might conclude. The company continues to monitor the situation and has not released additional details about the scope of data loss or any potential remediation steps beyond the isolation of integrations.
The incident remains under active investigation, with Klue working alongside external experts to assess the full extent of the data exposure and to implement further protective measures. No additional information about attacker motives, potential decryption keys, or the status of ransom negotiations has been made public at this time.
