
Business Software Company's Old Password Led to Customer Data Breach
Klue, a company that provides business software, let hackers access customer data using a login credential from 2022 that should have been deleted.
Source
TechCrunch Security
Original headline: Klue says hackers stole credential from 2022 that led to customer data breaches
Plain-English summary by GetCyberRight. Read the full report at the source above.
Klue, a company that provides competitive intelligence software to businesses, has confirmed that hackers broke into systems containing customer data. The break-in happened because Klue failed to delete an old login credential from 2022 after a limited test project ended. Hackers found and used this old, forgotten password to access a system that held the keys to customer information. If your employer uses Klue for business intelligence or competitive research, your work-related data may have been accessed by hackers. This could include information your company stored in Klue's systems.
Even though this is a business-to-business service, the breach could affect individual employees whose information was in those systems.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Here's what you should do:
- Ask your company's IT department if your organization uses Klue and whether you've been affected by this breach.
- If your company confirms you're affected, find out exactly what type of information was exposed.
- Change passwords for any work accounts, especially if you've ever reused work passwords for personal accounts (which you should never do).
- Watch for suspicious emails that reference your workplace or projects you're working on, as hackers may use stolen business information for targeted scams. This breach teaches an important lesson about password and credential management. Just like businesses need to delete old access credentials, you should regularly review and remove old apps and services that have access to your personal accounts. Check your Google, Apple, Facebook, and other major accounts for connected apps and remove any you no longer use. These forgotten connections can become security risks over time, just like Klue's old credential became a doorway for hackers.
Curated from trusted cybersecurity sources by GetCyberRight
Source: TechCrunch SecurityStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Business Software Company's Old Login Credential Led to Customer Data Breach
Klue, a business intelligence company, failed to revoke an old credential from 2022, which hackers used to access systems containing customer data.
2 min read
Private Events Company Left Member Information Exposed Online
A website security mistake left personal details of Dialog members accessible without needing to hack anything. Here's what happened.
2 min read
Private Events Group Left Member Information Exposed Online
Dialog, a private events organization, left member details accessible due to a misconfigured website, not a hack as the company claimed.
2 min readThe New Reality: AI Is Changing Digital Safety Faster Than Families Can Keep Up
AI has rewritten the rules of digital safety. Old guidance still helps, but it no longer protects on its own. Here is what changed and what families should do about it.
6 min read