KLUE BREACH: SECOND HACKER GROUP EXTORTS CUSTOMERS AFTER STEALING FROM ICARUS
Market research provider Klue suffered a cyberattack earlier this month that affected multiple organisations including LastPass, Gong, Jamf, HackerOne and Huntress. The ransomware group Icarus claimed responsibility for stealing customer data and threatened to leak it unless Klue paid a ransom. Klue subsequently communicated with Icarus, which stated it was taking steps to delete the stolen data.
A second, unnamed hacker group has claimed to have broken into Icarus's systems and stolen the same customer data from Klue. This second group is now attempting to extort Klue customers directly by posting a list of affected companies on its own website. According to Klue's communications with customers, one Icarus operator accidentally permitted the second group to access the server hosting the stolen data. The second group also claimed that Klue had paid an Icarus operator to delete the data, though no evidence of payment has been presented.
Klue informed its customers on Wednesday night that Icarus told the company the unnamed group possessed only samples of the stolen data, not the complete dataset. Icarus requested that Klue instruct customers not to make payment to the second group. Klue's website for reporting breaches remains down, and the company has stated it has indications that Icarus is proceeding with data deletion.