{"id":61767,"date":"2026-07-02T05:07:44","date_gmt":"2026-07-02T09:07:44","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=61767"},"modified":"2026-07-02T05:07:44","modified_gmt":"2026-07-02T09:07:44","slug":"klue-icarus-data-breach-deletion-extortion","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/klue-icarus-data-breach-deletion-extortion\/","title":{"rendered":"Klue Hackers Delete Stolen Data as Second Gang Makes Extortion Threats"},"content":{"rendered":"<p>Market research provider <a href=\"https:\/\/overcentral.com\/en\/lastpass-klue-supply-chain-attack\/\" title=\"LastPass data breach exposes customer data in Klue supply chain attack\" data-iacss-internal=\"1\">Klue<\/a>, which suffered a significant breach earlier this month that enabled cybercriminals to exfiltrate extensive data belonging to numerous high-profile cybersecurity clients, has informed customers that the primary hacking group, &#8220;Icarus,&#8221; is in the process of deleting the stolen information. However, the situation has escalated as a second, unidentified gang has now emerged with its own extortion threats, demanding payment directly from the affected companies.<\/p>\n<h2>Klue\u2019s Private Update to Customers on Icarus Data Deletion<\/h2>\n<p>In a private communication shared with customers on Wednesday night, which <a href=\"https:\/\/techcrunch.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">TechCrunch<\/a> has reviewed and verified with multiple sources, Klue stated that it is maintaining an open line of communication with the threat actor known as Icarus. The company reported that Icarus has indicated they are \u201ctaking steps to delete the data taken from Klue customers.\u201d This claim is corroborated by the fact that the Icarus extortion website is currently offline, a point Klue also noted in its private advisory to clients.<\/p>\n<p>The initial breach, which occurred on June 12, allowed attackers to steal a significant but undisclosed amount of data from an unspecified number of Klue\u2019s clients. The company previously disclosed that the hackers gained initial access by exploiting a third-party credential from a 2022 pilot program. This foothold was then used to steal <a href=\"https:\/\/overcentral.com\/en\/klue-oauth-token-theft-icarus\/\" title=\"Klue confirms OAuth token theft in breach linked to Icarus group\" data-iacss-internal=\"1\">OAuth<\/a> tokens, effectively allowing the attackers to authenticate into customer cloud environments and databases. A growing list of major technology and cybersecurity firms have since confirmed their data was compromised, including Gong, Jamf, HackerOne, Huntress, Insurity, <a href=\"https:\/\/overcentral.com\/en\/lastpass-klue-supply-chain-hack\/\" title=\"LastPass Customer Support Data Stolen in Klue Supply Chain Hack\" data-iacss-internal=\"1\">LastPass<\/a>, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.<\/p>\n<h2>Second Hacker Gang Makes Direct Extortion Demands<\/h2>\n<p>While the apparent takedown of the Icarus site suggests a potential de-escalation, the situation has taken a more complicated turn. According to Klue\u2019s update, Icarus informed the company that a second, separate group of hackers is now actively attempting to extort Klue\u2019s customers directly. This second gang has posted a list of allegedly affected companies on its own website and claims to have obtained the stolen Klue customer data directly from the Icarus operator.<\/p>\n<p>The second gang alleges that the Icarus operator is \u201ca teenager living somewhere in the UK or adjacent countries\u201d and that a mistake made by this individual allowed them to connect to the server where the stolen data was stored. The gang is pressing for a ransom, posting a message that states: \u201cPay the ransom or we will leak everything if you no pay us.\u201d The hackers claim that a total of 195 Klue customers were affected.<\/p>\n<p>TechCrunch has not independently verified that Klue paid a ransom to Icarus, nor has it confirmed the identity or location of the Icarus operator. Klue did not immediately respond to a request for comment on these specific allegations.<\/p>\n<h3>Klue\u2019s Guidance on the Secondary Threat<\/h3>\n<p>In its latest update, Klue attempted to mitigate the panic associated with this secondary threat. The company passed along a message from Icarus stating that \u201cthe other party has only samples of data for a subset of customers, not all of the data.\u201d Icarus explicitly asked Klue to inform its customers not to make any payment to this second gang.<\/p>\n<p>To help customers verify the credibility of any extortion attempts from this new group, Klue is advising affected clients who are contacted to request a random sample of data as proof of possession. This is a standard tactic used to distinguish between opportunists who may have only scraped a list of names from a leak site and actual threat actors holding the full dataset.<\/p>\n<h2>Key Questions Remain Unanswered About the Initial Breach<\/h2>\n<p>Despite the ongoing updates, several critical details about the root cause of the Klue breach remain unclear. The company has not provided additional context regarding the compromised 2022 third-party credential, specifically who it was assigned to or why it was not revoked in the four years following its creation. This lapse remains a significant point of concern for cybersecurity professionals evaluating the incident, as it highlights a failure to follow basic credential hygiene and lifecycle management.<\/p>\n<h2>What Affected Klue Customers Should Do Now<\/h2>\n<p>For users and organizations associated with any of the confirmed victim companies, the immediate priority is enhanced vigilance and proactive security hygiene. Given the complexity of this incident involving multiple threat actors, affected users should take the following steps without delay. First, assume that account credentials and session tokens may be compromised; immediately change all passwords associated with the affected services and enforce a company-wide password reset. Second, enable multi-factor authentication (MFA) on all accounts, prioritizing those that had data within Klue\u2019s systems. Third, closely monitor financial accounts, cloud activity logs, and support tickets for any signs of unauthorized access, as threat actors often lurk before using stolen data. Fourth, be highly skeptical of any unsolicited communications\u2014whether email, phone, or text\u2014that claim to be from Klue, Icarus, or the new hacker gang, as these are likely phishing attempts aimed at compounding the breach damage. Finally, for organizations handling sensitive customer data, it is a recommended security practice to use a reputable no-log VPN service when conducting incident response communications on untrusted networks and to review all third-party integrations and standing OAuth tokens immediately to revoke any that are unnecessary or suspicious. Taking these measures now can significantly reduce the risk of further exploitation from this cascading security incident.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Market research provider Klue, which suffered a significant breach earlier this month that enabled cybercriminals to exfiltrate extensive data belonging to numerous high-profile cybersecurity clients, has informed customers that the primary hacking group, &#8220;Icarus,&#8221; is in the process of deleting the stolen information. However, the situation has escalated as a second, unidentified gang has now [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":84134,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/61767.png","fifu_image_alt":"Klue Hackers Delete Stolen Data as Second Gang Makes Extortion Threats","footnotes":""},"categories":[349],"tags":[],"class_list":["post-61767","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/61767.png","fifu_image_alt":"Klue Hackers Delete Stolen Data as Second Gang Makes Extortion Threats","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/61767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=61767"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/61767\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/84134"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=61767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=61767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=61767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}