Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats

Market research platform Klue experienced a significant data breach affecting 12+ major enterprise customers, with stolen data now at risk from multiple threat actors following alleged negotiation breakdowns and credential misuse dating back to 2022. The incident demonstrates critical vulnerabilities in third-party credential management and highlights an emerging threat pattern where primary threat actors' stolen data becomes commodified by secondary criminal groups, creating compounded extortion risks across affected organizations. IT leaders must reassess their vendor security posture and implement stricter controls around legacy credentials and OAuth token access, as this breach illustrates how years-old security oversights can cascade into multi-stakeholder compromise.

Lorenzo Franceschi-BicchieraiTechCrunch2 min read
Read full article
Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats
Market research company Klue told customers that it believes the hacking group that stole their data is now deleting it. The company, however, warned about a second group of hackers wanting ransom.