Thursday, 23 July 2026 · Europe
EUR/USD 1.139 EUR/GBP 0.8532 EUR/CHF 0.9295 EUR/PLN 4.327 All rates →
Sign in · Join
EUROPES The European Report
European Edition Thursday, 23 July 2026
LATEST
Tech & Startups

Klue data breach descends into multi-gang extortion

Klue data breach descends into multi-gang extortion

A cyberattack on market research firm Klue has evolved into a complex double-extortion scheme, exposing the severe supply chain risks facing businesses that rely on third-party cloud vendors.

Market research provider Klue is advising its clients not to pay ransoms to a new hacking group that has entered the fray following a major data breach earlier this month. The original attackers, a group known as Icarus, appear to be deleting the stolen information. However, a second criminal gang now claims to have hijacked the data and is directly threatening Klue’s customers.

This second group claims to have accessed the stolen files after an alleged operational security failure by an Icarus operator. According to the new gang, this operator is a teenager based in the UK or a neighbouring country who made a mistake that exposed the server. The gang has published a list of 195 supposedly affected companies and issued a blunt threat: “Pay the ransom or we will leak everything if you no pay us.”

Klue confirmed on Monday that Icarus broke into its systems on June 12, compromising an unspecified amount of customer data. The victim list includes major technology and cybersecurity firms such as LastPass, Snyk, Recorded Future, OneTrust, HackerOne, and Jamf.

The initial compromise was traced to a 2022 third-party credential that was part of a limited pilot program. Klue has not explained why this access key remained active for four years. The hackers exploited this dormant entry point to steal customer authentication keys, known as OAuth tokens, which they then used to access the cloud environments and databases of Klue’s clients.

In a private update to customers on Wednesday night, Klue stated: “We continue to communicate with the threat actor we have been in contact with (‘Icarus’).” The company added that the Icarus website is down and that there are indications the group is following through on deleting the data.

For businesses across Europe, the incident underscores a critical vulnerability in the software supply chain. Companies routinely share sensitive cloud access with third-party vendors, but a failure to revoke old credentials can give criminals the keys to multiple corporate networks simultaneously.

Klue is now attempting to manage the fallout from this cascading security failure. The company warned clients that the second gang likely only holds partial data samples, stating: “Icarus told us that the other party has only samples of data for a subset of customers, not all of the data. Icarus has asked us to inform Klue customers to not make payment to this other party.” Klue has urged any contacted customers to demand randomized data samples as proof before taking any action.

More from Tech & Startups