CSIDB logo
Incident

Gong

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 21:58

Linked entities

Victim
Gong
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Gong disclosed that attackers accessed internal licensed user data for a subset of its customers who used the Klue integration, exposing usernames, business titles and email addresses. The breach originated from a compromise of Klue’s platform, where threat actors used a legacy credential to gain entry to client cloud data, including Salesforce instances, and exfiltrated business contact information such as names, email addresses, phone numbers and job titles. The Icarus cybercriminal group claimed responsibility for the intrusion and began posting portions of the stolen data on a leak site. Gong blocked the suspicious IP addresses provided by Klue and confirmed that some customer data had been compromised after investigating the associated activity.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 12, 2026, attackers gained entry to Klue’s systems by exploiting a legacy credential tied to an integration tool that connects clients’ cloud data with Klue accounts. This breach allowed the threat actors to access databases such as Salesforce used by Klue’s customers. The cybercriminal group Icarus claimed responsibility for the intrusion and threatened to publish stolen data unless a ransom was paid. In response, Klue engaged the cybersecurity firm CrowdStrike to investigate and temporarily disabled all external integrations to protect client data.

Klue later notified Gong of four suspicious IP addresses associated with the breach. Gong blocked those IP addresses and investigated the activity linked to them. Through this investigation Gong determined that some customer data had been compromised. The compromised data consisted of usernames, user business titles, and user emails for a subset of Gong customers who had enabled the Klue integration, and Gong disclosed these findings in a blog post.

Other companies affected by the Klue breach included Huntress, LastPass, and several other cybersecurity firms, with Icarus posting portions of the stolen data on its dark web leak site. Huntress confirmed that the leaked files contained Salesforce data such as business contact information but noted that no product infrastructure, telemetry, passwords, or payment card information was accessed. LastPass stated that while its Salesforce instance was accessed, its customer vaults remained secure and its products and services were unaffected. Gong’s statement emphasized that its own products, services, and infrastructure were not impacted by the incident.

Sources

Sources available to members: 2 sources.

CSIDB