Ransomware victim disclosure
← All victimsKlue.com
Claimed by Icarus · listed 5 hours ago
Status timeline
- ListedJun 19, 2026
- Data leakeddate unknown
At a glance
- Group
- Icarus
- Status
- Data leaked
- Country
- Canada
- Sector
- Technology
- Listed on leak site
- Jun 19, 2026
About the victim
AI dossier — public-source company profileKlue is a SaaS platform providing competitive intelligence and win-loss analysis tools for sales and marketing teams. The company operates in the B2B software sector and serves enterprise clients.
- Industry
- Competitive Intelligence & Sales Enablement Software
Attack summary
Severity: high — Confirmed exfiltration of sensitive business data (Salesforce CRM records) affecting multiple partner organizations; operational and reputational impact to downstream customers; extortion attempt underway.Icarus claims to have accessed Klue's Salesforce instance and exfiltrated data from partner company Salesforce instances connected to Klue. The group is threatening to publish the data unless Klue makes contact, framing the exfiltration as leverage for negotiation.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce instance data
- Partner company Salesforce records
- Customer relationship data
What the group claims
As you've probably already heard, ***.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated. This leak/post is made to address this. We advice Klue to contact us for a swift resolution, in order not to affect the companies you work with. On the other note, if Klue doesnt want to accommodate this request, we advice the companies who want to protect their data to contact us via Session. In order to verify you're a representative of the company you claim to be, you will need to provide a certain value/field from a row on your SF. We wish for your cooperation, not your demise. Make the correct choice. Data stolen: data borrowed - not stolen
Sources
- Victim siteKlue.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

