Cyber Incident Victim: Gong
Timeline
Summary
Gong disclosed that attackers who breached the Klue platform and used its OAuth tokens to access Salesforce data may have viewed internal licensed user data for a subset of its customers that relied on the Klue integration, specifically usernames, business titles and email addresses. After Klue supplied four suspicious IP addresses, Gong blocked them and investigated the associated activity, confirming that some customer data had been compromised. The Icarus extortion group claimed responsibility for the breach and posted portions of the stolen information on its dark web leak site, noting that the accessed data included business contact details that could be used for further social engineering attempts.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On June 12, 2026, attackers gained access to Klue's system by exploiting a legacy credential tied to an integration tool that connects clients' cloud data with Klue accounts. The breach allowed the attackers to reach databases such as Salesforce. The Icarus cybercriminal group claimed responsibility for the intrusion and announced on their leak site that they would publish the stolen data on the open web by a Monday deadline unless a ransom was paid. Klue did not disclose the exact number of its hundreds of clients that were affected. On June 21, 2026, Gong published a blog post stating that attackers may have accessed internal licensed user data for a subset of Gong customers that used the Klue integration. The Gong post specified that the accessed data included usernames, user business titles, and user emails. Gong said that Klue provided four suspicious IP addresses associated with the activity, which Gong subsequently blocked. After investigating the traffic from those IP addresses, Gong determined that some customer data had been compromised.

At the time of the leak site's update, six Klue customers were listed, and Gong was among the organizations named. Huntress, another Klue customer, confirmed that the data posted by Icarus matched the scope of its own investigation. Huntress stated that no product, infrastructure, telemetry, password, or payment card information was accessed in the breach. The Huntress data that was exposed consisted solely of Salesforce information, including full names, work emails, job titles, phone numbers, business addresses, business names, products trialed or used, subscription details such as units and pricing, and sales‑related communications like price quotes, contacts, tasks, and opportunity notes. LastPass disclosed that its Salesforce instance was affected but emphasized that its products, services, and infrastructure remained unaffected and that customer vaults stayed secure. In a separate incident from the previous year, Cloudflare reported discovering 104 API tokens stored in its Salesforce instance, which were contained in support case data files and were subsequently rotated.
Klue reported that the initial entry point was a legacy credential linked to an integration tool used to synchronize client cloud data with Klue accounts. After detecting the intrusion, Klue disabled the affected integration and began a forensic investigation with CrowdStrike.
