Market research firm Klue has confirmed that hackers accessed customer data from several cybersecurity companies by exploiting an obsolete 2022 credential. The breach, which was only discovered on June 12th, highlights potential long-term security issues and raises questions about the company’s management practices.
The stolen credentials allowed hackers to bypass Klue's systems and access other cloud and database resources belonging to its corporate clients. This incident has prompted Klue to conduct a thorough review of its credential management, vendor-access controls, monitoring capabilities, and deployment security processes.
Klue has not disclosed the nature or origin of the stolen credential, only that it was part of a limited pilot in 2022. The company’s spokesperson, Katie Berg, told TechCrunch that they would not divulge details such as the length of the pilot or who received the credential.
A hacking group called Icarus has taken credit for the breach and threatened to release stolen data unless a ransom is paid. Klue has yet to respond to these demands or confirm any contact with the hackers.







