Canada
CAN
Klue reported that an attacker used a previously compromised GitHub personal access token on 11 June 2026 to introduce unauthorized code into its integration service, harvest OAuth credentials and use those credentials to extract data from customer environments. Klue subsequently disabled affected integration infrastructure and rotated credentials. This represents compromise of a legitimate third-party software integration as well as temporary loss of that integration service.
Estimated severity
73 / 100
Source reliability
No information
Approximate Date
11/06/2026
Targeted Company
KLUE LABS
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Canada
CAN
No other affected countries reported
Target country
Canada
Affected countries
Impacted regions
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Please rotate your phone