The hacker group was credited with the breach of market intelligence provider Crew, which allowed the hackers to steal large amounts of data from the company's corporate customers, including some of the biggest names in the cybersecurity industry.
Crew, a Vancouver-based company that allows companies to connect data to their systems for market research, said Friday that hackers stole data from an unspecified number of customers in a cyberattack a week ago. (Your blog contains a “noindex” code that tells search engines not to list the page in search results.)
Cybercrime group Icarus has accepted responsibility for the breach and said on its leak site that it will release the stolen data on Monday unless the company pays the hackers' ransom.
Crews did not say how many of its hundreds of customers would be affected. Several companies have acknowledged that their data was stolen during the attack, including Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.
This is the latest in a number of major hacking incidents in which hackers have targeted companies that hold keys to other companies' cloud databases. By infiltrating companies like Klue, hackers are betting that they can steal data from many organizations at once by compromising a single point of failure. In the past year alone, hackers have increasingly targeted similar middleware providers such as Gainsight and Salesloft to access data for hundreds of companies.
Klue said the hackers gained access to its systems on June 12 using “compromised legacy credentials” such as passwords and tokens associated with an integration tool that allows customers to link their cloud data to their Klue accounts.
Hackers were able to steal data from Klue's customer cloud, including the Salesforce database. Businesses often store their customers' personal information in Salesforce databases, making them the primary target.
According to various affected companies, much of the stolen data includes business contact information such as customer names, email addresses, phone numbers, job titles, and some account information.
It's not clear how the hackers obtained the compromised credentials or why crews didn't detect the theft sooner. Similar recent large-scale hacks involving compromised or misused credentials, such as Snowflake and Tanstack, have involved employees accidentally installing password-stealing malware on devices they use for work.
Crewe said it contacted incident response firm CrowdStrike and disconnected the integration to prevent further access to customer data.
When contacted by TechCrunch on Monday, Klue CEO Jason Smith did not immediately respond to a request for comment or answer questions about the incident, including whether the company had received any communications from the hackers, including a ransom demand.
Huntress, one of the security companies whose data was stolen in the hack, said in a summary of the incident that the hackers had contacted the company with a ransom note using an Australian company email address, and that its servers were likely being misused in the campaign.
Last June, Crew announced that it was preparing to lay off about 100 people, or about half its workforce, as it doubled down on its investment in AI. It's unclear whether the layoffs led to a decline in the company's security. It's unclear who, other than Smith, is responsible for cybersecurity at the company.
Crew does not currently list the person overseeing cybersecurity on its executive page.
Do you know more about the Klue cyberattack? Is your company affected by a breach? We'd love to hear from you. You can contact Zack Whittaker securely via Signal username zackwhittaker.1337 or by email at zack.whittaker@techcrunch.com.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

