Klue says hackers stole credential from 2022 that led to customer data breaches

Market research platform Klue suffered a significant breach in June 2026 caused by a credential from a 2022 pilot program that was never decommissioned, exposing sensitive data from multiple cybersecurity customers including LastPass through stolen OAuth tokens. The incident exposes critical gaps in IT security practices—specifically credential lifecycle management, vendor access controls, and monitoring—raising concerns across the industry about how SaaS providers safeguard their customers' authentication keys and cloud infrastructure access. For CIOs, this breach underscores the urgent need to audit legacy credentials, enforce strict credential rotation policies, and implement zero-trust access controls for all third-party integrations regardless of their status.

Zack WhittakerTechCrunch2 min read1 views
Read full article
Klue says hackers stole credential from 2022 that led to customer data breaches
It's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.