Snyk experienced a minor incident on June 19, 2026 affecting Snyk AppRisk and Snyk AppRisk and 1 more component, lasting 18d 16h. The incident has been resolved; the full update timeline is below.
Affected components
Update timeline
- investigating Jun 19, 2026, 11:15 PM UTC
We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future (https://www.recordedfuture.com/blog/klue-security-incident), Tanium (https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/), Huntress (https://www.huntress.com/blog/klue-breach-investigation), and Jamf (https://www.jamf.com/blog/klue-incident/) have been impacted and have shared updates publicly. Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved. Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.
- monitoring Jun 22, 2026, 10:12 PM UTC
We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future, Tanium, Huntress, and Jamf have been impacted and have shared updates publicly. Currently, based on the actions we have taken to date and the advice of our third-party experts, we do not believe that impacted data will be made public or further misused. Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved. Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.
- resolved Jul 08, 2026, 03:26 PM UTC
Our forensic investigation into the June 2026 Klue/Salesforce incident, conducted in partnership with Mandiant, is now complete. The investigation confirmed that the impact was limited to business CRM data. No evidence of impact to the Snyk platform, and any sensitive data within, was found. All impacted customers were notified directly and the data involved is consistent with what was disclosed in our June 22 blog post (https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/).