HebridesCyber
← back to Security Weekly

One Leaked Credential From 2022, ~200 Companies Breached: The Klue Supply-Chain Lesson

27 July 2026·1 min read

Market research vendor Klue was breached using a credential issued for a 2022 pilot — and the fallout hit customers including HackerOne, LastPass, and Jamf.

What happened

Market research provider Klue was compromised by an extortion group tracked as "Icarus," which broke in using a credential Klue had issued back in 2022 for a limited product pilot — and apparently never revoked. The fallout spread to roughly 200 of Klue's customers, several of them cybersecurity companies you'd expect to know better, including Jamf, HackerOne, and LastPass.

The uncomfortable lesson

The specific detail that matters here isn't the attacker's name — it's that the point of failure was a four-year-old credential from a pilot program nobody remembered to clean up. This is one of the most common ways breaches actually happen: not a sophisticated zero-day, but a forgotten API key, a test account with real permissions, or a contractor's access that was never revoked.

It's also a supply-chain story. None of Klue's affected customers did anything wrong themselves — they trusted a vendor, and the vendor's housekeeping failure became their incident to manage.

What to check in your own business

  • Inventory every third-party integration and API key your business has ever issued — most companies genuinely don't have a complete list.
  • Set expiry dates on pilot/trial credentials by default, so "temporary" access doesn't quietly become permanent.
  • Ask vendors about credential lifecycle policy before handing them data — "do you rotate and expire unused access?" is a fair question to ask any supplier.
  • Least privilege — a credential issued for a limited pilot should never have had the scope to cause a 200-company incident.

A CI/CD and secrets management review is specifically designed to catch exactly this class of problem before it becomes a headline.

Sources: roundup reporting via TechCrunch and TechRepublic

$ ./get-your-score

Get a free Security Score for your site

Automated TLS, headers, DNS, and exposure checks — results in under a minute.

Request a free scan