The recent breach of market intelligence platform Klue has taken on a new and even more troubling dimension. While the company announced that the Icarus hacking groupresponsible for the initial attack is now cooperating with the company and is in the process of deleting the stolen data, a second criminal group has suddenly emerged, claiming to be in possession of copies of the same files.

According to a private notification sent by Klue to its customers, the new perpetrators are attempting to directly blackmail the affected businesses, threatening to release the data if a ransom is not paid.
Icarus promises data deletion
In a statement to its customers, Klue revealed that it is in open communication with the Icarus group, which breached its systems on June 12. The attackers gained access by exploiting an old credential that had remained active since 2022.
See also: Hacker group claims to have breached Novo Nordisk and demands $25 million
The company claims that Icarus has informed it that it has already begun the process of deleting the data it obtained from its information systems. At the same time, the group's website remains down, which, according to Klue, is an indication that the process is ongoing.
However, in the cybersecurity world, such assurances are treated with great caution. There is no meaningful way to confirm that the data has actually been deleted or that it has not already been copied and shared with other criminal groups.
A second group complicates the situation
The biggest problem arose when Icarus itself informed Klue that a second group of hackers had gained access to the stolen files, exploiting a mistake allegedly made by the operator of the initial attack.
The new perpetrators published on their own website a list of companies they claim were affected by the incident and made clear threats of extortion.
They claim that a total of 195 Klue customers were affected by the breach. They also claimed that Klue paid a sum of money to the original administrator of Icarus, who is described as a teenager based in the UK. This information has not been independently verified.
See also: LastPass: Data breach via Klue supply chain attack

The well-known companies that were targeted
The breach has already created an extensive list of victims, which includes well-known technology and cybersecurity companies such as LastPass, HackerOne, Snyk, Gong, Jamf, OneTrust, Recorded Future, Sprout Social, and Tanium.
The incident highlights a phenomenon that will dominate cyberattacks in 2026: supply chain. Instead of attacking the end targets directly, cybercriminals compromised an external partner who had OAuth tokens and access rights to Salesforce environments .
This is a particularly effective tactic, as a single weak point can open the door to dozens or even hundreds of organizations at once.
Klue: An old credential became the cause of the crisis
Klue had previously revealed that initial access was achieved through a credential created in 2022 as part of a limited pilot program.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Although the specific integration was abandoned, the certificate was never revoked and remained active for about four years. The company has not clarified who had taken over its management or why it was not removed in time.
See also: Australia's largest bank reports increased costs and work chaos due to AI
The incident highlights one of the biggest problems in modern cybersecurity: forgotten credentials and inactive digital "doors" that remain open for years, making them ideal targets for attackers.

Why the violations never really end
Klue's case demonstrates that a cyberattack is not over once the original attacker is identified. Stolen data is often copied, sold or shared between different criminal groups, creating a continuous cycle of extortion and threats.
Despite Icarus’ assurances that the files will be deleted, Klue customers still face a difficult reality: no one can know for sure how many copies of the data are still in circulation and who owns it today. This is precisely what makes modern supply chain attacks one of the greatest challenges for the global business community.
