{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-23T09:52:30.189Z"
  },
  "data": {
    "id": "incident_statuspage_snyk_3gw3m2ppwbp3",
    "slug": "snyk-third-party-vendor-security-incident-klue-2026-06-19",
    "title": "Third-Party Vendor Security Incident (Klue)",
    "summary": "Third-Party Vendor Security Incident (Klue)",
    "status": "resolved",
    "severity": "minor",
    "startedAt": "2026-06-19T23:15:30.191+00:00",
    "updatedAt": "2026-07-08T15:26:44.328+00:00",
    "resolvedAt": "2026-07-08T15:26:44.3+00:00",
    "provider": {
      "slug": "snyk",
      "name": "Snyk"
    },
    "affectedServices": [
      {
        "slug": "snyk-apprisk",
        "name": "AppRisk"
      },
      {
        "slug": "snyk-scanning",
        "name": "Vulnerability scanning"
      }
    ],
    "links": {
      "html": "/incidents/snyk-third-party-vendor-security-incident-klue-2026-06-19",
      "api": "/api/v1/incidents/snyk-third-party-vendor-security-incident-klue-2026-06-19",
      "providerHtml": "/providers/snyk"
    },
    "impactSummary": "Snyk reported a minor event for the affected tracked services.",
    "source": {
      "id": "source_snyk_status",
      "kind": "official_api",
      "name": "Snyk Status",
      "checkedAt": "2026-07-23T09:50:14.172+00:00",
      "officialUrl": "https://status.snyk.io",
      "statusPageUrl": "https://status.snyk.io"
    },
    "updates": [
      {
        "id": "update_statuspage_snyk_3gw3m2ppwbp3_vt1ggxrl2l18",
        "status": "investigating",
        "body": "We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration.  Other security vendors, such as Recorded Future (https://www.recordedfuture.com/blog/klue-security-incident), Tanium (https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/), Huntress (https://www.huntress.com/blog/klue-breach-investigation), and Jamf (https://www.jamf.com/blog/klue-incident/) have been impacted and have shared updates publicly. \n\nOur investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved.\n\nUpon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.",
        "createdAt": "2026-06-19T23:15:30.35+00:00"
      },
      {
        "id": "update_statuspage_snyk_3gw3m2ppwbp3_sw9t70d2m6k6",
        "status": "monitoring",
        "body": "We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration.  Other security vendors, such as Recorded Future, Tanium, Huntress, and Jamf have been impacted and have shared updates publicly. \n\nOur investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved.\n\nUpon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.",
        "createdAt": "2026-06-22T22:12:45.314+00:00"
      },
      {
        "id": "update_statuspage_snyk_3gw3m2ppwbp3_1m6qqd5bc0zd",
        "status": "resolved",
        "body": "Our forensic investigation into the June 2026 Klue/Salesforce incident, conducted in partnership with Mandiant, is now complete. The investigation confirmed that the impact was limited to business CRM data. No evidence of impact to the Snyk platform, and any sensitive data within, was found. All impacted customers were notified directly and the data involved is consistent with what was disclosed in our June 22 blog post (https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/).",
        "createdAt": "2026-07-08T15:26:44.3+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}