Security News

Cybersecurity news aggregator

HIGH Attacks Huntress

Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress

The article describes a data breach at Klue, a third-party platform, which exposed Salesforce data from numerous victim companies, including Huntress. The attack vector appears to be unauthorized access to Klue's systems, leading to the exfiltration of business contact information, sales communications, and subscription details. No specific vulnerability, CVSS score, affected software versions, patches, or technical workarounds are detailed in the provided article text.
Read Full Article →

Home Blog Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress Published: June 18, 2026 Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress By: Team Huntress Summarize with AI Summarize ChatGPT Claude Perplexity Google AI Update: 6/24/26 @ 8:15 PM ET We are aware of new activity related to the Klue incident and are continuing to monitor the situation closely. A separate unauthorized party has claimed access to data associated with the incident and has made statements regarding potential disclosure. At this time, these claims remain unverified, and our team is actively investigating in coordination with security researchers. The unverified claims include stated plans to publish sample information about companies that have engaged with the original Icarus threat actor, and includes the names of nearly 200 companies. Following that, the unauthorized party claims that information about the victims will be released daily, unless a “compromise” is made. We will provide further updates as new information becomes available. ——— Update: 6/22/26 @ 11:45 PM ET Publication of Stolen Data From Klue Breach On June 22, Icarus listed data for Huntress and several other companies that were impacted by the Klue breach on its data leak website. Tom Lawrence, Community Growth Strategist, shares recommendations to help prepare other businesses and individuals who have potentially been wrapped up in Klue’s breach. Huntress has investigated the data that was posted and can confirm that it is in line with the scope of information that we previously shared. The files for Huntress are limited to Salesforce data, which includes business contact information (e.g., full names, work emails, job title, phone number, and business addresses), business names, products trialed/used, subscription details (units, pricing), and sales-related communications (such as price quotes, contacts, and tasks) with Huntress customers and partners, as well as opportunity notes (i.e., free form fields where teammates can capture and track thoughts and next steps). As expected, no data associated with Huntress products or infrastructure, or any telemetry, passwords, or payment card data was impacted, based on current evidence. Figure 1b: The Icarus data leak site with data listed from companies on June 22, 2026 Technical Analysis of the Data Further investigation determined that many of the file headers listed were misleading. The specific contents of those files displayed only non-sensitive system logs and routine application metadata, and did not include customer information. Some filenames may also appear concerning at first glance. For example, a file named stripeGC_Stripe_Account_c.json was included in the dataset. Although the filename references Stripe, the associated integration had been installed but never implemented or actively used by Huntress. As a result, the file contained only limited metadata fields such as CreatedDate and LastModifiedDate and did not contain customer payment or credit card information. We believe this occurred because the threat actors conducted a bulk export of all accessible data, regardless of whether the files contained meaningful business or customer information. As a result, many of the files included in the dataset contained only benign system information or logs. Figure 2a: Details of Stripe .json file obtained from Klue breach Once the data was published on the leak site, Huntress researchers quickly flagged the data dump internally and pulled down the files to begin investigating and reviewing the data. The IP address that hosted the data leak files originates from an autonomous system number (AS200593) that is registered under the organizational name PROSPERO OOO and registered in the Russian Federation. AS200593 has been flagged by previous security researchers and carries a Censys BULLETPROOF designation. We have shared this clearnet IP address with the appropriate law enforcement agencies. What We Expect to Come Next As previously mentioned, other companies have made statements about being impacted by the Klue breach. Data relating to many of these companies has not been posted as of yet. Based on current activity, we anticipate that additional organizations may be impacted as this situation continues to evolve. Here are some steps that we hope can further help prepare businesses and individuals that have been impacted by the Klue breach: With the public data of impacted Klue downstream customers now actively being leaked, we strongly recommend against going digging through the raw leaked dataset. Accessing raw compromised data is risky as leak archives are often laced with malware. There are other, safer protective steps that individuals can take to verify their inclusion in the data: instead, confirm what was taken through your incident response team, your counsel, and a trusted intel partner. The threat actor will likely continue to post the data of the companies that it compromised from the Klue breach. Icarus will also likely continue to put pressure on impacted organizations to pay a ransom in exchange for not releasing their data. It’s important to remember that cybercriminals shouldn’t be trusted, and that should be a consideration in any sort of negotiation. In the coming weeks, impacted companies should keep a look out for potential phishing campaigns that use compromised, sales-specific data. Cybercriminals may pose as employees from Huntress or other impacted Klue customers and use stolen data to try to launch further attacks. Continue to use trusted and known channels for updates and communication. We are continuing to investigate this incident and will post more details as they become available. ——— Update: 6/19/26 @ 4:10 PM ET Quick update as we continue internal and external investigation with our DFIR. We would like to reiterate that NO Huntress products, infrastructure, telemetry, passwords, or payment card data were impacted. To confirm, the impacted data may consist of business names, products trialed/used, subscription details (units, pricing), business contact info (e.g., full names, work emails, job title, phone number, and business addresses), marketing/sales communications, and opportunity notes (i.e., free form fields where teammates can capture and track thoughts and next steps). We will continue to conduct our internal and external investigation, and as always, will provide more details as they become available. ——— Update: 6/19/26 @ 9:45 AM ET Klue Listed on Icarus’ Leak Site Icarus has officially listed Klue as one of their casualties. There is no download link provided as of yet and the size is listed as “-1GB”. This appears to confirm the attribution of who was behind the original attack, however. Figure 1a: Screenshot from Icarus’ leak site Text from the screenshot is as follows, misspellings intact: Description As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated. This leak/post is made to address this. We advice Klue to contact us for a swift resolution, in order not to affect the companies you work with. On the other note, if Klue doesnt want to accommodate this request, we advice the companies who want to protect their data to contact us via Session. In order to verify you're a representative of the company you claim to be, you will need to provide a certain value/field from a row on your SF. We wish for your cooperation, not your demise. Make the correct choice. Data Compromised data borrowed - not stolen No download links Official Statements from Affected Companies Klue has released an official update on the incident. Also other security vendors, such as Recorded Future , Tanium , and Jamf have since stepped forward and released official statements on how they’ve been impacted. We expect there will be more statements released as others who are affected verify which data may have been touched or taken by the attackers. Right now it remains unclear if other impacted companies (other than Klue) will be listed on the leak site at a later date. ——— *Editor’s note: On June 23, we clarified information regarding Huntress employee contact information accessed from Gong, and conversational data stored in Salesforce. Throughout 2026, the cybersecurity industry has seen a new surge of software supply chain attacks, presented in many shapes and sizes. We at Huntress have been a constant advocates of the mantra: it’s not a matter of if, or even when, an incident occurs -- but how you respond. We want to be transparent about a major supply chain attack that happened this week, which impacted us and other organizations. It supports our core values to put the community and transparency first. In this blog we will share what we know about the Klue incident, what we know about our incident, and what we know about the threat actor. As the industry works to understand the scope/impact of this incident, we are committed to working with Klue and others to communicate what happened and how impacted partners and customers can protect themselves. This post will continue to be updated as we have more information. Read on for our full report. — TL;DR : A threat actor compromised and exfiltrated data from customers of Klue, a market intelligence platform. Huntress is one of those customers of Klue, as are several other cybersecurity companies. Huntress believes in radical transparency about security incidents, including when it affects our company. The data that was copied from our Salesforce account includes business contacts, price quotes, and other sales-related data and messaging. No threat data, passwords, payment card information, or engineering data relating to the Huntress agent or telemetry we collect was affected. To be clear, Huntress found no indication of impact to Huntress products or infrastructure

Share this article