Klue, a market intelligence software-as-a-service company, disclosed a data breach after attackers gained unauthorized access to its systems. The incident occurred between June 12-15, 2026, and involved the use of a compromised legacy credential to obtain OAuth tokens, which then allowed access to customer Salesforce data. OneTrust, a third party, confirmed that the incident was isolated to CRM-related data accessible through the Klue–Salesforce integration.
The exposed data types included business contact information such as names, email addresses, phone numbers, company names, titles, websites, industry, and region. Other exposed data included deal amounts, lost comments, lead sources, customer types, billing/shipping addresses, sales communications, CRM/account data, and support email/case data. Klue did not disclose a total number of affected individuals, but reports indicated nearly 200 organizations may have been affected. The incident did not expose passwords, payment card information, SSNs, medical data, or customer platform data.
While some affected companies have mailed notices to consumers, a total count of notified individuals has not been provided. The specific details of the data exposed were reportedly included in each affected individual's notification letter. Details regarding the exact number of individuals impacted may emerge as more notifications are processed.