Gong
Incident posture
Timeline
Summary
Gong disclosed that attackers accessed internal licensed user data for a subset of its customers who used the Klue integration, exposing usernames, business titles and email addresses. The breach originated from a compromise of Klue’s platform, where threat actors used a legacy credential to gain entry to client cloud data, including Salesforce instances, and exfiltrated business contact information such as names, email addresses, phone numbers and job titles. The Icarus cybercriminal group claimed responsibility for the intrusion and began posting portions of the stolen data on a leak site. Gong blocked the suspicious IP addresses provided by Klue and confirmed that some customer data had been compromised after investigating the associated activity.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 12, 2026, attackers gained entry to Klue’s systems by exploiting a legacy credential tied to an integration tool that connects clients’ cloud data with Klue accounts. This breach allowed the threat actors to access databases such as Salesforce used by Klue’s customers. The cybercriminal group Icarus claimed responsibility for the intrusion and threatened to publish stolen data unless a ransom was paid. In response, Klue engaged the cybersecurity firm CrowdStrike to investigate and temporarily disabled all external integrations to protect client data.
Klue later notified Gong of four suspicious IP addresses associated with the breach. Gong blocked those IP addresses and investigated the activity linked to them. Through this investigation Gong determined that some customer data had been compromised. The compromised data consisted of usernames, user business titles, and user emails for a subset of Gong customers who had enabled the Klue integration, and Gong disclosed these findings in a blog post.
Other companies affected by the Klue breach included Huntress, LastPass, and several other cybersecurity firms, with Icarus posting portions of the stolen data on its dark web leak site. Huntress confirmed that the leaked files contained Salesforce data such as business contact information but noted that no product infrastructure, telemetry, passwords, or payment card information was accessed. LastPass stated that while its Salesforce instance was accessed, its customer vaults remained secure and its products and services were unaffected. Gong’s statement emphasized that its own products, services, and infrastructure were not impacted by the incident.
Sources
Sources available to members: 2 sources.