The market research company Klue disclosed that it was in communication with Icarus, a hacker organization that had previously invaded its system. In an update sent to the client, the company indicated that the data stolen from the Klue client was being deleted. The update, seen by TechCrunch, also mentions that the Icarus website is currently inaccessible.

Second gang in.

However, this incident has not ended. Klue told his client that Icarus said another hacker group was trying to extort money directly from the affected client.

The unnamed group listed a group of companies allegedly affected on its website and claimed that its data was not directly from Klue but was retrieved from Icarus. The group also threatened to release all data if the companies concerned did not pay the ransom.

Klue says he only has a partial sample.

In its latest update, Klue indicated that according to Icarus, the second group had only a sample of some of its clients and not all of them. Icarus also requested Klue to inform the client not to pay the group.

At the same time, Klue recommended that, if a client had already contacted the second group, he should be asked to provide a random sample of data to confirm that he actually held the data he claimed.

Intruder path points to old documents

Klue had previously confirmed that hackers had entered its system on 12 June and had stolen a number of undisclosed client data, and that the number of affected clients had not been made public. A number of clients subsequently confirmed that they had been affected, including Gong, Jamf, HackerOne, LastPass, OneTrust, Reded Future, Snyk and Tanium.

The company had earlier stated that the attackers had used a 2022 third-party certificate. The voucher was originally used for a limited pilot project. After accessing the Klue system, hackers steal their OAuth tokens and further access to relevant cloud services and databases.

Klue has not yet explained to whom the old certificate was originally allocated, nor has it explained why it was not revoked in the past four years.

Additional information:TechCrunch states that it has not been possible to independently verify whether Klue paid Icarus the ransom, nor to confirm the specific reasons why Icarus is offline.