The Klue breach escalated into a rare double extortion: the original Icarus hacking group told Klue it is deleting the stolen customer data, but a second unnamed group has obtained samples and is directly demanding ra...
Research answer

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What are the details of the double extortion incident targeting Klue's breach victims, including. Article summary: Here are the verified details of the Klue double extortion incident, based on multiple authoritative cybersecurity sources and official statements from Klue.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layo
On June 12, 2026, market intelligence platform Klue identified unauthorized activity in its integration infrastructure. The breach was carried out by the Icarus extortion group, a new outfit with only two prior victims on its leak site . The attackers exploited a compromised legacy credential tied to an integration service account to gain access, then harvested OAuth tokens that customers used to connect Klue to third-party platforms, primarily Salesforce
. With those tokens, Icarus queried and bulk-exfiltrated Salesforce CRM data—including business contacts, opportunities, and sales-conversation data—from multiple customer environments
.
Icarus deleting stolen data. In a June 25 customer update reviewed by TechCrunch, Klue stated: "Icarus told us they are taking steps to delete the data taken from Klue customers. The Icarus site remains down and we have indications that Icarus is indeed taking steps to delete data taken from Klue customers" .
Second unnamed group emerges. Despite Icarus appearing to destroy the data, a second, unnamed hacking gang has obtained at least portions of the stolen information and is directly extorting Klue's customers . According to Klue's Thursday update, "Icarus told us that the other party has only samples of data and is opportunistically and fraudulently seeking payment directly from a number of our customers"
. This second group posted a list of allegedly affected companies on its own extortion site
.
Multiple reports confirm that approximately 195 organizations had data stolen. The Register reported "hundreds" of victims , with other sources specifying that 195 companies received direct extortion demands. Confirmed victims include Huntress, Recorded Future, HackerOne, Jamf, Tanium, Gong, OneTrust, Snyk, Sprout Social, Insurity, and others
. Notably, LastPass was not listed in any of the sourced disclosure lists, contrary to some early unverified claims.
Backed by CrowdStrike. Klue publicly confirmed it "engaged CrowdStrike" to support the investigation and validate response measures . The company took immediate steps: revoking affected credentials and tokens, removing unauthorized code, disabling impacted integrations, and notifying law enforcement
.
Advisory on the second extortion group. In its June 25 update, Klue advised customers not to pay the second unnamed group. Instead, Klue recommended affected customers request proof-of-data samples before engaging with any extortion demands—and to forward any such communications directly to Klue or law enforcement for verification . The company emphasized that the second group appears to possess only "samples" of data and is acting opportunistically and fraudulently
.
Ongoing remediation. Klue is conducting a full review of security controls, credential management, monitoring, and deployment processes to implement additional safeguards .
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The Klue breach escalated into a rare double extortion: the original Icarus hacking group told Klue it is deleting the stolen customer data, but a second unnamed group has obtained samples and is directly demanding ra...