North America
Klue
In an ironic turn of events, cybersecurity firms themselves have become victims of a supply-chain attack following a breach of market intelligence platform Klue.
Vancouver-based market intelligence provider Klue disclosed on June 19 that hackers stole data from an undisclosed number of customers in a cyberattack between June 11 and 12. The incident affected Klue’s Salesforce integration, leading to data exfiltration from the Salesforce environments of multiple customers. According to the company, the attacker gained access through a compromised legacy credential, used it to obtain OAuth tokens that connected Klue to third-party platforms, including Salesforce, and then accessed data within the customer environments connected to those platforms. Notably, several cybersecurity companies were impacted, including HackerOne, Huntress, OneTrust and Snyk.
Klue said the intrusion was limited to Salesforce instances and did not involve customers’ own systems. Meanwhile, the cybercrime group Icarus has claimed responsibility for the attack and stated on its leak site that it will publish the stolen data if a ransom is not paid.
How it could affect your business
This incident highlights a growing reality in cybersecurity: the breach that hurts your organization most may not happen within your own environment at all. A compromise at a trusted vendor or service provider can create a pathway for attackers to access connected systems, applications or sensitive data. Organizations should regularly assess third-party risk, review and limit vendor access privileges, monitor integrations with external platforms and ensure suppliers follow strong security practices. Maintaining visibility into the broader supply chain is becoming just as important as securing internal systems.
