Third-Party Vendor Security Incident (Klue)
Jun 19, 23:15 UTCJul 8, 15:26 UTC
Duration
18d 16h
Impact
Minor
Root cause
Not disclosed
Snyk, 90 days
18 incidents
Affected
Snyk AppRiskSnyk CodeSupport PortalSnyk ContainerSnyk IaCSnyk Open SourceSnyk LearnEvo by SnykSNYK-US-01 (app.snyk.io) - Snyk AppRiskSNYK-US-01 (app.snyk.io) - Snyk CodeSNYK-US-01 (app.snyk.io) - Snyk ContainerSNYK-US-01 (app.snyk.io) - Snyk IaCSNYK-US-01 (app.snyk.io) - Snyk Open SourceSNYK-US-01 (app.snyk.io) - Snyk Learn
Final update
Our forensic investigation into the June 2026 Klue/Salesforce incident, conducted in partnership with Mandiant, is now complete. The investigation confirmed that the impact was limited to business CRM data. No evidence of impact to the Snyk platform, and any sensitive data within, was found. All impacted customers were notified directly and the data involved is consistent with what was disclosed in our June 22 blog post (https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/).
Timeline
- Resolved · Jul 8, 15:26 UTC
Our forensic investigation into the June 2026 Klue/Salesforce incident, conducted in partnership with Mandiant, is now complete. The investigation confirmed that the impact was limited to business CRM data. No evidence of impact to the Snyk platform, and any sensitive data within, was found. All impacted customers were notified directly and the data involved is consistent with what was disclosed in our June 22 blog post (https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/).
- Monitoring · Jun 22, 22:12 UTC
We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future, Tanium, Huntress, and Jamf have been impacted and have shared updates publicly. Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved. Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.
- Investigating · Jun 19, 23:15 UTC
We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future (https://www.recordedfuture.com/blog/klue-security-incident), Tanium (https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/), Huntress (https://www.huntress.com/blog/klue-breach-investigation), and Jamf (https://www.jamf.com/blog/klue-incident/) have been impacted and have shared updates publicly. Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved. Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.
More from Snyk
Full history| Started | Incident | Impact | Duration |
|---|---|---|---|
| Sep 2114:43 UTC | Snyk Code Services Degraded in MT-US-01 | minor | 3h 24m |
| Sep 1806:40 UTC | Snyk Daily Recurring Tests Delayed | minor | 2d 23h |
| Sep 914:37 UTC | Imports and PR Checks Degraded | minor | 2h 25m |
| Aug 3014:32 UTC | Partial Broker Service Degradation | minor | 2d 16h |
| Aug 3012:20 UTC | Partial Broker Service Degradation | minor | 1h 12m |
| Aug 2012:42 UTC | Snyk Code Degradation | none | 0m |
From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.