Some breaches are a story about sophisticated adversaries. This one is a story about a key that should have been thrown away years ago and wasn’t — and the roughly 200 companies that paid for that oversight.
According to TechCrunch, market research provider Klue was at the center of a mass data breach affecting close to 200 companies, among them security-industry names such as Jamf, HackerOne, and LastPass. Klue reportedly admitted that the extortion gang, dubbed Icarus, broke in using a credential the company had issued in 2022 for a limited pilot — implying Klue had around four years to decommission that credential before it was stolen and used. In the breach, Klue exposed the keys to its customers’ cloud services, allowing the attackers to reach in and steal data from those environments to extort the downstream companies.
The blast radius of one forgotten credential
This is a textbook third-party supply-chain cascade. Klue is a vendor; its customers trusted it with access into their cloud environments. When Klue got popped, that trust became the attack path: the intruders didn’t have to breach 200 companies individually, they breached one and inherited the keys to the rest. The single most damaging detail isn’t exotic malware — it’s a pilot credential from 2022 that never got revoked. Four years is not an oversight measured in hours; it’s a governance gap you could park a truck in.
TechCrunch reports the aftermath got messier still. Klue told customers it had reached an agreement with the hackers not to publish the stolen data — which strongly suggests a payment — but as part of that deal, the attackers conceded that yet another hacking group also held a portion of the data, and urged victims not to pay that second group. If you have ever wanted a crisp illustration of why paying an extortionist buys you a promise rather than a guarantee, here it is: you can pay for silence and still discover your data is sitting in someone else’s hands.
What to do about it
- Inventory and expire third-party access: Maintain a living inventory of every vendor credential, token, and integration into your environment, with mandatory expiration and periodic review — a pilot from years ago should not still be live.
- Scope vendor access tightly: Give vendors least-privilege, time-bound access to only what they need, and prefer short-lived credentials over standing keys.
- Rotate on vendor incidents: If a provider you’ve granted cloud access to is breached, revoke and rotate those keys immediately rather than waiting to be told you’re affected.
- Monitor for third-party misuse: Alert on unusual access via vendor integrations and service accounts, which often fly under the radar of user-focused monitoring.
- Plan for extortion honestly: Build an incident plan that treats “we paid and they promised” as the unreliable outcome it is; a promise from a criminal isn’t a control.
The outrage
Four years. A credential minted for a limited 2022 pilot was still valid, still trusted, and still capable of unlocking customers’ cloud data in 2026. Credential lifecycle management is not glamorous work — nobody gets a conference keynote for revoking old keys — but it is exactly the unglamorous work that stands between “a vendor had an incident” and “200 companies are on the phone with their lawyers.”
There’s an extra sting in seeing security-industry firms swept up through a shared vendor: it’s a reminder that your security posture is only as strong as the housekeeping of everyone you hand a key to. Klue’s customers did the reasonable thing by using a market-research vendor; they inherited the consequences of that vendor leaving a four-year-old door unlocked. Go audit your third-party credentials. The one you forgot about is the one that ends up in the headline.
Leave a Reply