By: Paul Black, CISO at Tanium
What happened?
Earlier this week, Tanium was made aware that Klue, a third-party platform that syncs battlecard and win/loss data with Salesforce through an OAuth integration, experienced a security breach that allowed the CRM data of Klue’s customers, including Tanium, to be exfiltrated from Salesforce. This supply chain attack impacted multiple organizations.
The Tanium security team immediately took corrective steps to remediate the issue and strengthen our defenses. Based on our investigation, the unauthorized party gained access to our Salesforce data. The impact did not affect Tanium’s products or cloud infrastructure in any way, and was contained to CRM data in Tanium’s Salesforce environment.
What information was involved?
Tanium’s investigation to date indicates that support information, passwords, and customer security data were not involved. The information that may have been compromised includes sales account data, such as opportunity names and values and other sales-related messaging, as well as business contact information stored in Salesforce, such as names, job titles, and email addresses, and in some cases phone numbers, social media contact details, and business addresses.
At this time, Tanium has no evidence that any of our customers’ other data has been accessed or misused.
What are we doing?
The Tanium security team took the following steps to contain and resolve the issue:
- Ensured that Klue’s OAuth integration was blocked and access to Tanium's Salesforce data has been disabled.
- Launched an extensive investigation to ensure all aspects of this event are fully understood and any additional mitigations which may be required have been identified and applied.
- Engaged directly with Klue's leadership to understand the root cause and confirm containment.
What we recommend you do
Given that the potentially exposed information includes names, email addresses, and phone numbers, Tanium recommends:
- Be alert to phishing and social engineering. If you receive unexpected communications claiming to be from Tanium, verify through your existing Tanium contacts before taking any action. Tanium will never contact anyone by phone to request a password or any other secure information.
- Report anything suspicious. If you receive a suspicious message referencing Tanium or your relationship with the company, please report it immediately using the contact details below.
No passwords or credentials need to be reset as a result of this incident.
For more information
If you have any questions or concerns, please do not hesitate to contact Tanium’s Global Support team at help.tanium.com.
To learn more about what Tanium does to secure our data and that of our customers, please visit our Security at Tanium page.
