← Bynder

2026 Bynder — Klue integration compromise; Salesforce business contacts exfiltrated (no DAM platform data)

2026 Unknown records affected Share on X

Data compromised

Business contact information only per Bynder: name, job title, employer, business email address, and business telephone number exfiltrated from Salesforce; investigation found no sensitive personal data and no data stored in the Bynder platform was involved

Technical writeup

Bynder customer security notice (June 2026, Marciano Kruithof, VP Information Security). Bynder identified and investigated a security incident involving a compromised third-party integration with Klue Competitive Intelligence—the same mid-June 2026 OAuth token-theft supply-chain campaign documented across the Klue ecosystem (see klue-oauth-supply-chain2026). The investigation confirmed unauthorized access to Bynder’s Salesforce environment and exfiltration of business contact data limited to name, job title, employer, business email address, and business telephone number; Bynder found no evidence that sensitive personal data was involved and stated explicitly that no data stored in the Bynder digital asset management platform was involved. Bynder contained the incident, revoked affected integration credentials, and completed its internal investigation while awaiting Klue’s root cause analysis. Following the incident, Bynder’s CEO was contacted by the threat actor (Icarus) who attempted to negotiate; Bynder refused and is working with relevant authorities. Contact: [email protected]. BreachHistory indexes recordsAffected 0 pending a disclosed contact-row count.

Root cause

Compromised third-party Klue Competitive Intelligence integration; stolen OAuth tokens used for unauthorized Salesforce access (Icarus supply-chain campaign)

References