MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Klue integration compromise exposes customer data and disables integrations

Klue reported that an attacker used a previously compromised GitHub personal access token on 11 June 2026 to introduce unauthorized code into its integration service, harvest OAuth credentials and use those credentials to extract data from customer environments. Klue subsequently disabled affected integration infrastructure and rotated credentials. This represents compromise of a legitimate third-party software integration as well as temporary loss of that integration service.

73

Estimated severity

73 / 100

—

Source reliability

No information

Approximate Date

11/06/2026

Targeted Company

KLUE LABS

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Canada

CAN

Other Affected Countries

No other affected countries reported

Target country

Canada

Affected countries

Canada

Impacted regions

British Columbia · Canada

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impactService unavailability

Affected sectors

Technology & IT Services

Affected departments

Engineering & MaintenanceInformation Technology

Attack Profile

Attack types

Use of stolen credentialsSoftware supply chain compromiseData exfiltration

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.