A third-party security breach at Klue, a market intelligence platform, allowed an unauthorized party to access data from Snyk's Salesforce environment, exposing customer business contact information and limited support case titles and descriptions. Snyk's platform, products, and infrastructure were not affected, and there was no disruption to customer service. Snyk disabled the Klue integration immediately upon notification, and a subsequent forensic investigation conducted with Mandiant confirmed the impact was confined to CRM business data, with all affected customers directly notified.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
Our forensic investigation into the June 2026 Klue/Salesforce incident, conducted in partnership with Mandiant, is now complete. The investigation confirmed that the impact was limited to business CRM data. No evidence of impact to the Snyk platform, and any sensitive data within, was found. All impacted customers were notified directly and the data involved is consistent with what was disclosed in our June 22 blog post (https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/).
We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future, Tanium, Huntress, and Jamf have been impacted and have shared updates publicly.
Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved.
Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.
We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future (https://www.recordedfuture.com/blog/klue-security-incident), Tanium (https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/), Huntress (https://www.huntress.com/blog/klue-breach-investigation), and Jamf (https://www.jamf.com/blog/klue-incident/) have been impacted and have shared updates publicly.
Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved.
Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with