Klue, a Canadian market research company, disclosed that hackers used an old certificate dating back to 2022 this month to obtain access rights from their systems and to steal data from multiple business clients. The incident has affected the password management company LastPass and a number of cyber-security businesses.
Hackers borrow old vouchers to access the system.
Klue states that this certificate was initially provided to a third party in 2022 for a limited pilot project. According to the company, at this stage of the investigation, it was through this certificate that the attackers carried out the invasion.
However, Klue did not state the specific purpose, duration or identity of the recipient of the certificate. Similarly, the company did not explain why the certificate was not withdrawn after the pilot was completed.
Client cloud data is further down Load
According to the disclosure, Klue discovered anomalies on June 12th and made the first public incident last week. When hackers entered the Klue system, they obtained the OAuth token used to connect the client ' s external cloud services and databases, then downloaded the relevant data and sent the threat of extortion to the affected businesses.
Some of the clients known to have been affected include LastPass and several cyber-security companies. A hacker organization called Icarus has claimed the attack on the data leak website and threatened to disclose the stolen data if the ransom was not paid.
- Klue discovered the invasion on June 12th.
- Used documents date back to 2022
- The assailant obtained a client-related Oouth token
The source and management of the certificate remains in doubt
Klue only describes it in his blog as “a legacy document related to integrated services”, but does not indicate whether it is an employee account code or other type of access voucher. Nor does the company state whether the certificate was leaked from a third party or was stolen directly from Klue ' s own system.
These details relate to the reduction of the route of the attack and also affect external judgement of its internal security control. Since the certificate dated back several years, the incident also raised questions about its offline process and the management of historical access rights.
Company says they're reviewing access controls.
Klue indicated that the matter was still under investigation and that a comprehensive review of voucher management, vendor access controls, monitoring capacity and deployment security processes had been initiated.
At the time of the publication of the report, Klue had not indicated whether he had been in contact with hackers or whether he had disclosed that he was considering the payment of ransom.
