Market research provider Klue, which suffered a significant breach earlier this month that enabled cybercriminals to exfiltrate extensive data belonging to numerous high-profile cybersecurity clients, has informed customers that the primary hacking group, “Icarus,” is in the process of deleting the stolen information. However, the situation has escalated as a second, unidentified gang has now emerged with its own extortion threats, demanding payment directly from the affected companies.
Klue’s Private Update to Customers on Icarus Data Deletion
In a private communication shared with customers on Wednesday night, which TechCrunch has reviewed and verified with multiple sources, Klue stated that it is maintaining an open line of communication with the threat actor known as Icarus. The company reported that Icarus has indicated they are “taking steps to delete the data taken from Klue customers.” This claim is corroborated by the fact that the Icarus extortion website is currently offline, a point Klue also noted in its private advisory to clients.
The initial breach, which occurred on June 12, allowed attackers to steal a significant but undisclosed amount of data from an unspecified number of Klue’s clients. The company previously disclosed that the hackers gained initial access by exploiting a third-party credential from a 2022 pilot program. This foothold was then used to steal OAuth tokens, effectively allowing the attackers to authenticate into customer cloud environments and databases. A growing list of major technology and cybersecurity firms have since confirmed their data was compromised, including Gong, Jamf, HackerOne, Huntress, Insurity, LastPass, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.
Second Hacker Gang Makes Direct Extortion Demands
While the apparent takedown of the Icarus site suggests a potential de-escalation, the situation has taken a more complicated turn. According to Klue’s update, Icarus informed the company that a second, separate group of hackers is now actively attempting to extort Klue’s customers directly. This second gang has posted a list of allegedly affected companies on its own website and claims to have obtained the stolen Klue customer data directly from the Icarus operator.
The second gang alleges that the Icarus operator is “a teenager living somewhere in the UK or adjacent countries” and that a mistake made by this individual allowed them to connect to the server where the stolen data was stored. The gang is pressing for a ransom, posting a message that states: “Pay the ransom or we will leak everything if you no pay us.” The hackers claim that a total of 195 Klue customers were affected.
TechCrunch has not independently verified that Klue paid a ransom to Icarus, nor has it confirmed the identity or location of the Icarus operator. Klue did not immediately respond to a request for comment on these specific allegations.
Klue’s Guidance on the Secondary Threat
In its latest update, Klue attempted to mitigate the panic associated with this secondary threat. The company passed along a message from Icarus stating that “the other party has only samples of data for a subset of customers, not all of the data.” Icarus explicitly asked Klue to inform its customers not to make any payment to this second gang.
To help customers verify the credibility of any extortion attempts from this new group, Klue is advising affected clients who are contacted to request a random sample of data as proof of possession. This is a standard tactic used to distinguish between opportunists who may have only scraped a list of names from a leak site and actual threat actors holding the full dataset.
Key Questions Remain Unanswered About the Initial Breach
Despite the ongoing updates, several critical details about the root cause of the Klue breach remain unclear. The company has not provided additional context regarding the compromised 2022 third-party credential, specifically who it was assigned to or why it was not revoked in the four years following its creation. This lapse remains a significant point of concern for cybersecurity professionals evaluating the incident, as it highlights a failure to follow basic credential hygiene and lifecycle management.
What Affected Klue Customers Should Do Now
For users and organizations associated with any of the confirmed victim companies, the immediate priority is enhanced vigilance and proactive security hygiene. Given the complexity of this incident involving multiple threat actors, affected users should take the following steps without delay. First, assume that account credentials and session tokens may be compromised; immediately change all passwords associated with the affected services and enforce a company-wide password reset. Second, enable multi-factor authentication (MFA) on all accounts, prioritizing those that had data within Klue’s systems. Third, closely monitor financial accounts, cloud activity logs, and support tickets for any signs of unauthorized access, as threat actors often lurk before using stolen data. Fourth, be highly skeptical of any unsolicited communications—whether email, phone, or text—that claim to be from Klue, Icarus, or the new hacker gang, as these are likely phishing attempts aimed at compounding the breach damage. Finally, for organizations handling sensitive customer data, it is a recommended security practice to use a reputable no-log VPN service when conducting incident response communications on untrusted networks and to review all third-party integrations and standing OAuth tokens immediately to revoke any that are unnecessary or suspicious. Taking these measures now can significantly reduce the risk of further exploitation from this cascading security incident.