CrowdStrike Investigation Summary
Last week, I shared details about the security incident affecting our third-party integrations and committed to transparency on what we learned and what we’re doing about it.
We’ve stayed in close contact with affected customers throughout, sharing information and response strategies as they developed. We brought in CrowdStrike for a full, independent investigation, giving them broad access to all of our environments, systems, endpoints, backups, logs and engineering team to assess the scope of the incident. There were no constraints on their scope. CrowdStrike completed their investigation on June 30, 2026. Here’s a summary of what they found.
Investigation Findings
On June 11, 2026, a Threat Actor leveraged a previously compromised GitHub personal access token (PAT) to introduce unauthorized code into Klue’s integration service and collect third-party integration credentials including OAuth access and refresh tokens for Salesforce. On June 12, 2026, Salesforce notified Klue of suspected unauthorized third party activity originating from Klue’s API integration service. On the same morning as the notification from Salesforce, Klue disabled the affected GKE pods, disabled the compromised GitHub PATs, and rotated OAuth credentials. CrowdStrike did not identify evidence that the Threat Actor accessed Klue systems outside of those related to the integration service, nor how the Threat Actor initially obtained the PAT. There is no evidence of Threat Actor activity in the Klue environment after June 12, 2026. The CrowdStrike Falcon platform was deployed to the Klue environment, and the environment is being actively monitored by CrowdStrike.
The investigation also reinforced something we’ve believed from the beginning. Responding to an incident is not just about containment. It’s about understanding what happened, learning from it, and sharing how we and everyone in our community can further improve security.
Immediate Remediation: How We’ve Improved Our Security
We accelerated security hardening engineering efforts while continuing to support customers and re-enable integrations. Here’s what we’ve added to our existing security program:
Hardening GitHub Authentication
We disabled GitHub Personal Access Tokens (PATs) and migrated to alternative authentication mechanisms. Specific measures include:
- Organization-wide GitHub policies that block the use of PATs, covering both classic and fine-grained token types.
- Migration of existing workflows to alternative authentication mechanisms, including GitHub Apps and short-lived, automatically expiring credentials.
- Comprehensive automated secret scanning to augment existing regular secrets audits during penetration tests
Enhanced Monitoring and Detection
We strengthened the foundational monitoring layers of our stack by deploying:
- Enhanced audit logging across Klue GitHub and Google Cloud Platform environments.
- Additional CI/CD observability, including the use of StepSecurity Harden-Runner across workflows.
- Centralized existing logging silos by connecting them to a SIEM for automated anomaly detection.
- Dedicated endpoint detection and response (EDR) to expand existing endpoint visibility and threat detection.
Strengthened Secure Development and Deployment Practices
We hardened our software development and deployment pipeline through:
- Runtime network filtering and security monitoring applied to CI/CD workflows.
- Enforcement of an allowlist of approved GitHub Actions, so that only authorized actions can run in Klue pipelines.
These enhancements reflect how we operate: continuous review, continuous hardening. We’ll keep investing in the capabilities that make the platform you rely on more resilient.
Looking Ahead
Today’s update is a milestone, not the finish line. We’re focused on safely restoring integrations, supporting customers, and continuing to strengthen our security program. That work doesn’t stop when this investigation closes. Customer and partner collaboration helped us respond quickly, communicate openly, and make improvements. That kind of shared information benefits everyone connected to this. We’ll keep being transparent, keep sharing what we learn, and keep earning the trust you place in us.
![]() | Jason Smith CEO, Klue |






SHARE THIS POST