← HackerOne

2026 HackerOne — Klue OAuth supply-chain breach; Salesforce CRM business data accessed

2026 Unknown records affected Share on X

Data compromised

Business contact information from HackerOne's Salesforce CRM: names, email addresses, job titles, phone numbers, and business addresses; no hacker vulnerability report data or customer security data involved

Technical writeup

HackerOne confirmed its Salesforce CRM was accessed as part of the Klue supply-chain attack on June 11–12, 2026. Threat actor Icarus used compromised legacy Klue credentials to steal OAuth tokens connecting Klue's market-intelligence platform to customer Salesforce instances. HackerOne's internal platform, vulnerability reports, and customer security program data were unaffected; only business contact/CRM records were accessed. HackerOne published a security update at hackerone.com/security-updates/klue-2026-06. Icarus subsequently listed HackerOne among victims on its Tor-based leak site with a June 22 publication deadline. This is a separate incident from the earlier 2026 HackerOne / Navia BOLA breach affecting employee data.

Root cause

Klue market-intelligence platform breach (June 11–12, 2026) via compromised legacy credentials; OAuth tokens used to access HackerOne's Salesforce CRM

References