Observed Signal · May 28, 2021 · Data Breach · Source: OnlineMarketing.de · Impact: 2/5 · Sentiment: Negative
Klarna data leak exposed thousands of user accounts
A human error during a Klarna app update briefly exposed other users' accounts and personal data. The bug caused some users to access data such as phone numbers, purchase histories, and addresses, and the app was taken offline about 30 minutes after the issue was detected. Klarna stated the incident was fixed after roughly 31 minutes and is auditing which users were affected; authorities were informed. Klarna denied that credit card or bank details were exposed unencrypted, though some users asserted they could see such information. The company noted that publicly visible data were not considered 'sensitive' under GDPR, while stressing the seriousness of the incident and its commitment to restoring consumer trust.
Significant data exposure incident affecting Klarna users; substantial but not industry-shifting.
Track Klarna Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Data leak in Klarna app allowed access to other users' accounts and data due to a human error during an update.
- Bug fixed after about 31 minutes; app briefly offline to prevent further damage.
- Klarna stated around 9,500 customer accounts were affected; a spokesperson claimed up to 90,000 were affected.
- Authorities were informed; Klarna denied unencrypted exposure of credit card or bank details.
- Publicly visible data included personal information; Klarna said these were not 'sensitive' under GDPR.
Connected Companies & Entities
1 Entity mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Klaviyo leak exposed some sign-up passwords to advertisers
Security research by Melurna found that a misconfigured sign-up web form on Klaviyo’s site allowed new-customer sign-up information — including email addresses, passwords, company name, website and phone number — to be shared with third-party trackers and advertisers. The misconfiguration was present between at least February 2024 and November 2025, researchers told TechCrunch. Affected third parties reportedly included Facebook, Google, HubSpot, Microsoft/LinkedIn and X. Klaviyo said it fixed the issue and told TechCrunch the number of known affected individuals was fewer than 200 based on active logs; the company would not disclose how far back logs go or publicly share the customer notification. The findings were shared with TechCrunch ahead of a Def Con talk by the researchers.
LastPass Customer Data Stolen via Klue Breach
Password manager LastPass is handling a data breach after attackers accessed customer information by compromising a third‑party market intelligence platform, Klue. Klue detected unauthorized activity on 2026-06-12 and says attackers likely used old, compromised credentials for an integration service. Through that access, attackers viewed LastPass support tickets containing customer names, phone numbers, email addresses, home addresses, support-case details and sales-relevant information; payment data included in support tickets may also have been exposed. LastPass says its internal systems and user vaults were not compromised, and it is notifying affected users by email. Actions taken include suspending Klue employees’ access to LastPass data, rotating API access tokens, and planning additional protections. Users are advised to monitor payment activity and consider changing associated email addresses to reduce phishing risk.
Klue hack exposes customer data across cybersecurity firms
Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
