2026 Gong — Klue OAuth supply-chain breach; licensed user data accessed via integration
Data compromised
Subset of Klue-integration customers: internal licensed user names, business titles, and business emails—no call recordings, customer transcripts, or direct Gong product breach per Office of the CISO
Technical writeup
Downstream Klue supply-chain victim — June 2026. Gong's Office of the CISO disclosed June 19 that Klue notified Gong of unauthorized access to its integration service; Gong confirmed a subset of customers using the Klue–Gong integration may have had licensed user data (names, business titles, emails) accessed based on Klue-provided suspicious IPs. Gong found no direct impact to call recordings or transcripts; revoked Klue tokens, blocked Klue API requests, and reached out to affected customers. Huntress separately confirmed Salesforce and Gong exfiltration paths in the broader campaign. Not a Gong platform breach—integration-layer only. See klue-oauth-supply-chain2026.
Root cause
Klue integration service compromise; unauthorized actor accessed Gong data for customers who connected Klue (Icarus supply-chain)