
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain breach evolved into an exceptional case in which a second criminal group claimed to have compromised the first extortion crew and pilfered data that had already been stolen. The result was not simply another ransomware story. It exposed fundamental weaknesses in SaaS integrations, identity-based trust, third-party risk management and executive decision-making.
Scene of the crime
Founded in 2015, Klue, a Vancouver, Br...