Breach taxonomy
Summary
A threat actor exploited the Klue Labs third-party API integration connected to 8x8's Salesforce CRM between June 11 and 12, 2026, gaining unauthorized access and exfiltrating competitively sensitive information about current, former and prospective customers, including fragmented contract and opportunity information, sales team notes, and customer contact information. 8x8 and Klue, with Salesforce support, disabled the compromised integration and removed the access.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized third party threat actor' with no attribution -> UNKNOWN.
MethodsData ExfilSupply ChainApp Exploit
Threat actor 'exploited the Klue Labs, Inc. third-party application programming integration connected to the Company's Salesforce system' and 'exfiltrated certain information' -> DATA-EXFIL + SUPPLY-CHAIN + APP-EXPLOIT.
AssetsConfidential BizPersonal Data
Exfiltrated data was 'competitively sensitive information about current, former and prospective customers' including contract/opportunity details -> CONFIDENTIAL-BIZ, plus customer names/addresses/phones/emails -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Only disclosed effect is theft of customer and business data with no operational impact -> INFO-PRIVACY-LOSS.
Impact
Incident isolated to Salesforce data reachable via one integration, no operational impact, but competitively sensitive customer data was exfiltrated and disclosed under Item 1.05 -> score 2.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 1.05. Material Cyber Security Incident. On June 13, 2026, 8x8, Inc. (the "Company") was informed that an unauthorized third party threat actor exploited the Klue Labs, Inc. ("Klue") third-party application programming integration connected to the Company's Salesforce, Inc. ("Salesforce") customer relationship management system. The threat actor gained unauthorized access and exfiltrated certain information from 8x8's Salesforce system. This unauthorized access occurred between June 11 and 12, 2026. Upon discovery, 8x8 and Klue, with support from Salesforce, took immediate steps to disable the compromised integration and removed the unauthorized access. The threat actor exfiltrated certain competitively sensitive information about current, former and prospective customers of the Company, including fragmented contract and opportunity information, sales team notes, and contact information (names, business addresses, phone numbers and email addresses of the customers). Our investigation to date indicates that this incident was isolated to information stored in 8x8's Salesforce system that was accessible through the Klue integration. The Company has and continues to implement additional security measures to reduce the risk of similar unauthorized access in the future.