Market research firm Crew admitted earlier this month that credentials dating back to 2022, which were part of a limited pilot, were used by hackers to steal large amounts of data from corporate customers, including several cybersecurity companies.
The new details suggest it may have taken years for Crew to retire the credentials used by the pilot, raising questions about the company's security posture and what steps it could have taken to prevent the breach of customer data.
The hack at Vancouver-based Crew, which the company detected on June 12 and first disclosed last Friday, allowed hackers to steal data from numerous of the company's customers, including password manager maker LastPass and several other cybersecurity companies. Hackers used access to Klue's systems that store keys, known as OAuth tokens, to access customer data stored in other clouds and databases and download that data to blackmail businesses.
Klue spokesperson Katie Berg told TechCrunch that the company's previous research shows that the credentials used by the hackers to steal customer data were “initially provided to third parties for limited pilot purposes in 2022.”
In response to questions from TechCrunch, Crews did not explain the purpose of the pilot or how long it would last, nor did he identify the third parties to which the company had provided credentials. Crews also did not say why the certification was not revoked after the pilot ended.
Crews did not respond to follow-up emails regarding the incident prior to publication.
The company says the investigation is continuing, but questions remain about the incident.
Klue did not specify what kind of credentials were stolen, only saying in a blog post that they were “legacy credentials associated with an integration service.” Crews also did not say whether the credentials were the employee's username and password, for example, or whether the company believes the credentials were stolen from a third party rather than from its own systems.
These details can be important to understanding how the breach was carried out and how to prevent the incident from happening again.
Klue's statement to TechCrunch added that the company is “undergoing a comprehensive review of our credential management, vendor access controls, monitoring capabilities, and deployment security processes,” but provided no further details.
A hacker group called Icarus took credit for the breach of the data breach site and publicly threatened to release the stolen data if a ransom was not paid.
Crews has not said whether it has had contact with the hackers or whether it intends to comply with their demands.
Do you know more about the Klue cyberattack? Is your company affected by a breach? We'd love to hear from you. To contact Zack Whittaker securely, please do so via Signal using username zackwhittaker.1337.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

