Tech

Klue data breach exposes customer secrets via dormant 2022 credential

Hackers exploited a legacy credential from a 2022 pilot to extort corporate clients, raising urgent questions about credential lifecycle management in the cybersecurity sector.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
Klue says hackers stole credential from 2022 that led to customer data breaches
Vancouver-based market research firm admits legacy access key, unused for four years, facilitated OAuth token theft affecting LastPass and other tech firms.

Market research company Klue has confirmed that hackers exploited a legacy credential from a 2022 limited pilot to steal data from corporate customers, including password manager maker LastPass. The Vancouver-based firm detected the intrusion on June 12 and first disclosed it last Friday. Hackers accessed OAuth tokens stored by Klue to download customer data from other clouds and databases, subsequently extorting the affected companies. A hacking group called Icarus has claimed responsibility and threatened to release the data unless a ransom is paid. Klue is conducting a review of its credential management and security processes.

The breach highlights a significant lapse in access control, as the credential used by the attackers originated from a pilot program concluded years ago. Klue spokesperson Katie Berg stated the credential was originally provided to a third party in 2022 for a limited pilot. However, the company has not explained why the credential was not revoked after the pilot concluded, nor has it identified the third party involved or the purpose of the pilot. This lack of transparency has raised concerns among investors and industry peers regarding the firm’s security posture.

Hackers gained access to OAuth tokens, which serve as keys for accessing customers’ data stored in other clouds and databases. By leveraging these tokens, attackers were able to download sensitive information from corporate clients, including several cybersecurity companies. The stolen data was subsequently used to extort the affected firms, with the hacking group Icarus threatening to publish the information publicly if their demands were not met.

Further details regarding the nature of the breach remain sparse. Klue has not specified whether the stolen credential was an employee’s username and password or if it was stolen from the third party rather than Klue’s own systems. The company also declined to comment on whether it has had contact with the hackers or if it plans to pay their demands. These omissions leave critical gaps in understanding how the intrusion occurred and the full scope of the vulnerability.

In response to the incident, Klue announced it is conducting a comprehensive review of its credential management, vendor-access controls, monitoring capabilities, and deployment security processes. The incident underscores the risks associated with legacy access keys in complex digital ecosystems, particularly when oversight lapses allow dormant credentials to remain active for extended periods. As investigations continue, the market remains watchful for further disclosures regarding the extent of the data compromise.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon