← All filing news

8x8 reports unauthorized access to Salesforce system via compromised Klue integration

8x8 disclosed on June 23, 2026 that an unauthorized threat actor exploited a Klue Labs third-party application integration connected to the company's Salesforce customer relationship management system between June 11 and 12, 2026. The threat actor exfiltrated competitively sensitive information including fragmented contract and opportunity data, sales notes, and customer contact details. The company said it has disabled the compromised integration, taken remediation steps, and does not expect the incident to materially impact operations or financial condition, though it continues investigation and regulatory notification.

Key facts

  • Unauthorized access occurred June 11–12, 2026; disclosed June 13, 2026
  • Threat actor exploited Klue Labs integration to 8x8's Salesforce system
  • Exfiltrated data included contract information, sales notes, and customer contact details (names, business addresses, phone numbers, email addresses)
  • Company disabled compromised integration and removed unauthorized access
  • No impact reported on company's ability to serve customers or information system operations
  • Company in process of notifying relevant regulatory authorities
  • Investigation indicates incident was isolated to Salesforce information accessible through Klue integration

Why it matters

8x8 faces potential reputational and regulatory exposure from unauthorized disclosure of customer contract terms and contact data, and must manage notification obligations and investigation costs, though management currently assesses no material financial impact.

Share

Get this as a morning email

The day's newsworthy SEC filings in one free daily brief. No account needed.

Derived from 8-K filed 2026-06-23. Not investment advice. View the source filing on SEC.gov →