2026 Bynder — Klue integration compromise; Salesforce business contacts exfiltrated (no DAM platform data)
Data compromised
Business contact information only per Bynder: name, job title, employer, business email address, and business telephone number exfiltrated from Salesforce; investigation found no sensitive personal data and no data stored in the Bynder platform was involved
Technical writeup
Bynder customer security notice (June 2026, Marciano Kruithof, VP Information Security). Bynder identified and investigated a security incident involving a compromised third-party integration with Klue Competitive Intelligence—the same mid-June 2026 OAuth token-theft supply-chain campaign documented across the Klue ecosystem (see klue-oauth-supply-chain2026). The investigation confirmed unauthorized access to Bynder’s Salesforce environment and exfiltration of business contact data limited to name, job title, employer, business email address, and business telephone number; Bynder found no evidence that sensitive personal data was involved and stated explicitly that no data stored in the Bynder digital asset management platform was involved. Bynder contained the incident, revoked affected integration credentials, and completed its internal investigation while awaiting Klue’s root cause analysis. Following the incident, Bynder’s CEO was contacted by the threat actor (Icarus) who attempted to negotiate; Bynder refused and is working with relevant authorities. Contact: [email protected]. BreachHistory indexes recordsAffected 0 pending a disclosed contact-row count.
Root cause
Compromised third-party Klue Competitive Intelligence integration; stolen OAuth tokens used for unauthorized Salesforce access (Icarus supply-chain campaign)