Klue says hackers stole credential from 2022 that led to customer data breaches

Market research firm Klue confirmed that a legacy credential from a 2022 pilot program was exploited by hackers to access sensitive customer data. The breach impacted several cybersecurity companies, raising concerns about the firm's security practices.
Why it matters
This incident highlights the risks associated with failing to decommission legacy access tokens, which can lead to significant downstream data breaches for corporate clients.
Market research company Klue has confirmed that a credential dating back to 2022, which was part of a limited pilot, was used by hackers earlier this month to steal reams of data from its corporate customers, including several cybersecurity companies.
The report focuses on factual disclosure of the security incident and the company's lack of transparency regarding the timeline.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in