{"id":2013693,"date":"2026-06-25T16:40:15","date_gmt":"2026-06-25T13:40:15","guid":{"rendered":"https:\/\/analyse.optim.biz\/?p=2013693"},"modified":"2026-06-25T16:40:15","modified_gmt":"2026-06-25T13:40:15","slug":"hacked-klue-says-criminals-are-deleting-stolen-customer-data-but-now-other-hackers-are-making-threats","status":"publish","type":"post","link":"https:\/\/analyse.optim.biz\/?p=2013693","title":{"rendered":"Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats"},"content":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/techcrunch.com\/wp-content\/uploads\/2024\/06\/date-breach-overview-2024.jpg?resize=1200,675&#8243;]<\/p>\n<div class=\"entry-content wp-block-post-content is-layout-constrained wp-block-post-content-is-layout-constrained\">\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Market research provider Klue, which was hacked earlier this month in a breach that allowed cybercriminals to steal reams of data belonging to several of its customers, said that it is communicating with the hackers. The company also said it believes the group is deleting the stolen data, TechCrunch has learned.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe continue to communicate with the threat actor we have been in contact with (\u2018Icarus\u2019),\u201d the company wrote in an update shared privately on Wednesday night with its customers, which TechCrunch has seen and verified with multiple sources. \u201cIcarus told us they are taking steps to delete the data taken from Klue customers. The Icarus site remains down and we have indications that Icarus is indeed taking steps to delete data taken from Klue customers.\u201d<\/p>\n<p class=\"wp-block-paragraph\">On Monday, Klue confirmed that hackers broke into its systems on June 12 and stole an unspecified amount of data from an unspecified number of its customers. Since then, several Klue customers have confirmed they were affected by the breach, including Gong, Jamf, HackerOne, Huntress, Insurity, LastPass, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">At the time, the hacking group Icarus was threatening Klue to release the stolen customers\u2019 data in an attempt to extort the company.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">As of Thursday morning, when TechCrunch checked, the Icarus website appears to be down, which is also what Klue privately told its customers.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about the Klue breach? Or about the cybercrime group Icarus? We\u2019d love to hear from you. From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.\t\t<\/p><\/div>\n<p class=\"wp-block-paragraph\">While all this seems to point to a resolution, the hack got messier in the last couple of days. According to Klue, Icarus told the company that there is a second gang of hackers that is trying to extort its customers directly.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">This unnamed gang posted a list of allegedly affected companies on its own website, which TechCrunch has seen, where they claimed to have stolen Klue\u2019s customer data directly from Icarus. The hackers also alleged that Klue paid an \u201cIcarus operator who is a teenager living somewhere in the UK or adjacent countries.\u201d TechCrunch has obtained no independent verification that Klue paid Icarus, nor could we determine why the Icarus website is down. A Klue spokesperson did not immediately respond to a request for comment.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">According to the hackers, this person made a mistake that allowed them to connect to the server where the operator was keeping the stolen Klue\u2019s customer data.<\/p>\n<p class=\"wp-block-paragraph\">\u201cPay the ransom or we will leak everything if you no pay us,\u201d the cybercriminals wrote in a message on the site, where they claimed there are 195 affected Klue customers in total.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In its Thursday update to customers, Klue said: \u201cIcarus told us that the other party has only samples of data for a subset of customers, not all of the data. Icarus has asked us to inform Klue customers to not make payment to this other party.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Klue suggested its customers who are in touch with this second group of hackers to ask for a random sample of data, as proof that the hackers really possess the data they claim to have.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The company previously said that the hackers stole customers\u2019 data by using a 2022 third-party credential that was part of a limited pilot. The hackers then used their access to Klue\u2019s systems to steal customers\u2019 authentication keys \u2014 known as OAuth tokens \u2014 and log into their clouds and databases. Klue has not provided more details about this stolen credential, such as who it was assigned to, or why it was not revoked in the last four years.<\/p>\n<p class=\"wp-block-paragraph\"><em>Update: The article added clarifying language that a communication shared privately with customers was viewed by TechCrunch and verified by multiple sources.<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>Correction: a previous verson of this article mentioned ReliaQuest as a victim of the Klue hack. ReliaQuest in fact was not a victim. <\/em><\/p>\n<\/div>\n<p>[analyse_source url=&#8221;https:\/\/techcrunch.com\/2026\/06\/25\/hacked-klue-says-criminals-are-deleting-stolen-customer-data-but-now-other-hackers-are-making-threats\/&#8221;]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[analyse_image type=&#8221;featured&#8221; src=&#8221;https:\/\/techcrunch.com\/wp-content\/uploads\/2024\/06\/date-breach-overview-2024.jpg?resize=1200,675&#8243;] Market research provider Klue, which was hacked earlier this month in a breach that allowed cybercriminals to steal reams of data belonging to several of its customers, said that it is communicating with the hackers. The company also said it believes the group is deleting the stolen data, TechCrunch has learned.\u00a0 \u201cWe [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[226,62],"class_list":["post-2013693","post","type-post","status-publish","format-standard","hentry","category-politics","tag-crawlmanager","tag-techcrunch-com"],"_links":{"self":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/2013693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2013693"}],"version-history":[{"count":0,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=\/wp\/v2\/posts\/2013693\/revisions"}],"wp:attachment":[{"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2013693"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2013693"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/analyse.optim.biz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2013693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}