Snyk incident

Third-Party Vendor Security Incident (Klue)

Snyk is currently experiencing a minor incident affecting Snyk AppRisk and Snyk AppRisk and 1 more component, which began 12h ago. The vendor's full update timeline is below.

Started
Jun 19, 2026, 11:15 PM UTC
Resolved
Ongoing
Duration
● 12h 6m
Detected by Pingoru
Jun 19, 2026, 11:15 PM UTC

Affected components

Snyk AppRiskSnyk AppRiskSnyk AppRiskSnyk AppRiskSnyk CodeSupport PortalSnyk CodeSnyk CodeSnyk CodeSnyk Code

Update timeline

  1. investigating Jun 19, 2026, 11:15 PM UTC

    We were notified of a security incident involving Klue, a market intelligence platform used by Snyk and a wide range of companies for competitive intelligence. An unauthorized party accessed data from Snyk's Salesforce environment through Klue's integration. Other security vendors, such as Recorded Future (https://www.recordedfuture.com/blog/klue-security-incident), Tanium (https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/), Huntress (https://www.huntress.com/blog/klue-breach-investigation), and Jamf (https://www.jamf.com/blog/klue-incident/) have been impacted and have shared updates publicly. Our investigation shows that, to our knowledge at this point in time, the impact was primarily limited to business data fields within the Salesforce environments. This includes customer business contact information and only the title and description from a limited subset of customer support cases. The body or contents of the support cases were not included nor did it affect Snyk's products. There was no impact on our ability to serve our customers. Snyk's platform, services, and infrastructure remain fully operational and were not involved. Upon notification from Klue, we promptly disabled the Klue integration in Salesforce and began our own review. We will post updates here as we learn more.