In June 2026, Huntress was impacted by a data breach originating from its third-party vendor, Klue, a market intelligence platform. An extortion group identified as Icarus was responsible for the incident. The breach was not a direct compromise of Huntress's systems, but rather a cascading effect from the Klue incident, which affected multiple downstream customers.
The compromised data types included business contact information (full names, work emails, job titles, phone numbers, business addresses), business names, subscription details, marketing/sales communications, and opportunity notes. The incident affected 845 partner organizations; specific individual counts have not been disclosed as the breach exposed CRM data, not a personal user database. No threat data, passwords, payment card information, engineering data, telemetry, or product/infrastructure data were compromised. The states affected are not explicitly listed, but the breach is considered a global third-party incident.
Details about data breaches can emerge over time as investigations continue, and notifications to affected parties may be delayed.