Insurity incident

Notification of Salesforce / Klue Security Incident

Insurity is currently experiencing a minor incident affecting Insurity Public Cloud - US and Insurity Public Cloud - US and 1 more component, which began 71d ago. The vendor's full update timeline is below.

Started
Jun 18, 2026, 10:01 PM UTC
Resolved
Ongoing
Duration
● 70d 15h
Detected by Pingoru
Jun 18, 2026, 10:01 PM UTC

Affected components

Insurity Public Cloud - USInsurity Public Cloud - USInsurity Public Cloud - USInsurity Public Cloud - CanadaInsurity Public Cloud - USInsurity Public Cloud - USInsurity Public Cloud - CanadaInsurity Public Cloud - USInsurity Public Cloud - CanadaInsurity Public Cloud - US

Update timeline

  1. identified Jun 18, 2026, 10:01 PM UTC

    The following is an important message from Insurity Information Security. We are writing to inform you that we are actively investigating a security incident involving Klue and Salesforce. On June 16th, Salesforce notified Insurity of suspicious activity involving the Klue connected application used by Insurity. Following this notification, Insurity began investigating the validity and nature of this incident. While our investigation is ongoing, we can confirm at this time, that the Insurity cloud, managed infrastructure, and related systems have not been impacted by this incident. Our investigation is still ongoing and focused on whether any customer data held within Salesforce has been impacted at this time. This is unfortunately an incident that has impacted multiple Klue / Salesforce customers and we are working with the parties to gather additional details as they become available. We are treating this incident with urgency and will update you as additional details become available. Please do not hesitate to contact [email protected] if you have any questions.

  2. identified Jun 22, 2026, 03:05 PM UTC

    Update on the Salesforce / Klue Security Incident As an update to our prior notification regarding the Salesforce / Klue security incident, we wanted to share that our initial review of the exposed secrets (including credentials and keys) within Insurity’s CRM data has identified a very limited set of active credentials. We have taken the proactive step to rotate or reset all of these secrets. If you did not receive a direct message from Insurity regarding this incident, no secrets connected to your organization were impacted. Because the Salesforce / Klue event did not involve Insurity products, there are no Customer actions required to maintain the security of Insurity products. We recommend extra vigilance with respect to potential phishing and social engineering attempts because the accessed information came from Insurity’s CRM system and included business contact information. If you receive any messages that seem suspicious, please do not click links and provide any further information. We are committed to protecting our customers, maintaining transparency, and providing relevant updates. Thank you. Jay Wilson CIO & CISO

  3. identified Jul 09, 2026, 02:49 PM UTC

    Update on the Salesforce / Klue Security Incident We are continuing to work with our forensic partners regarding the Klue security incident, and our eDiscovery process remains ongoing. We will provide updates as soon as possible. Thank you for your patience. We are committed to protecting our customers, maintaining transparency, and providing relevant updates. Thank you. Jay Wilson CIO & CISO