Market research provider Crew, which was hacked by cybercriminals earlier this month and was able to steal large amounts of data belonging to several customers, said it was communicating with the hackers. The company also said it believes the group is deleting stolen data, according to TechCrunch.
“We continue to communicate with the threat actor ('Icarus') with whom we have been in contact,” the company said in an update privately shared with customers Thursday night, seen by TechCrunch. “Icarus has told us that it is taking steps to delete data obtained from Klue customers. The Icarus site remains down and there are indications that Icarus is indeed taking steps to delete data obtained from Klue customers.”
Crews acknowledged Monday that hackers broke into its systems on June 12 and stole an unspecified amount of data from an unspecified number of customers. Multiple Klue customers have since acknowledged that they were affected by this breach, including Gong, Jamf, HackerOne, Huntress, Insurity, LastPass, OneTrust, Recorded Future, ReliaQuest, Snyk, Sprout Social, and Tanium.
At the time, the hacker group Icarus was blackmailing the crew into releasing stolen customer data in order to blackmail the company.
Icarus' website appears to be down, TechCrunch confirmed as of Thursday morning, something Klue privately communicated to customers.
Contact Us Do you have more information about the Klue breach? Or about the cybercriminal group Icarus? We'd love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely from any non-work device or network on Signal (+1 917 257 1382), Telegram and Keybase @lorenzofb, or email.
While all of this seems to point to a resolution, the hack has gotten even more troubling in recent days. Crews said Icarus told the company there was a second group of hackers attempting to directly extort customers.
The anonymous gang posted a list of allegedly affected companies on its own website, seen by TechCrunch, where they claimed to have stolen Klue customer data directly from Icarus. The hackers also claimed that the crew paid a “teenage Icarus operator somewhere in the UK or neighboring countries”. TechCrunch has not obtained independent evidence that Klue paid any funds to Icarus, and was unable to determine why the Icarus website went down. A Crew spokesperson did not respond to a request for comment.
According to the hackers, the individual made a mistake and was able to connect to the server where the operator stored stolen Crewe customer data.
“Pay the ransom or we will leak everything,” the cybercriminals wrote in a message on the site, claiming that a total of 195 Klue customers were affected.
“Icarus has told us that the other party only has a sample of some customers' data, not all of the data. Icarus has asked us to notify Klue's customers not to make payments to this party,” Klue said in an update to customers on Thursday.
Crews suggested that customers in contact with this second group of hackers request a random sample of their data as proof that they actually owned the data the hackers claimed to have.
The company previously announced that hackers stole customer data using 2022 third-party credentials that were part of a limited pilot. Hackers then used their access to Klue's systems to steal customer authentication keys, known as OAuth tokens, to log into clouds and databases. Crews has not released any details about the stolen credentials, including who they were assigned to or why they have not been revoked in the past four years.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

