Fall 2024

Data Analyst Intern

Posted on 12/9/2023

Klue

Klue

51-200 employees

AI-driven competitive intelligence platform with insights

No salary listed

Vancouver, BC, Canada

All interviews will be conducted via video calls. The company works in a hybrid model of WFH (remote) and in-office.

All interviews will be conducted via video calls. The company works in a hybrid model of WFH (remote) and in-office.

All interviews will be conducted via video calls. The company works in a hybrid model of WFH (remote) and in-office.

Bachelor's, Master's, MBA, PharmD, PhD, Associate's, JD, MD, Bootcamp, Certification

Category
Data & Analytics
Required Skills
Python
Data Analysis

Get referred to Klue

See people who can refer or advise you

Requirements
  • Highly analytical and critical thinker
  • Ability to digest and communicate complex data
  • Experience with Excel and/or Python
Responsibilities
  • Ensure data providers and outsourced content creators deliver accurate data
  • Validate existing sources, outsourced content, and new potential data sources
  • Identify trends in data sets and develop unique solutions
  • Efficiency in data gathering and data cleaning
Desired Qualifications
  • Experience with analytics platforms
  • Experience with data cleaning initiatives and data gathering

Klue provides a platform that collects data from millions of sources to give businesses insights into their competitors, markets, and buyers. The software uses artificial intelligence to filter this data into a central hub where teams can access real-time tools like "battlecards" and newsletters to help sales representatives win deals. Unlike traditional research methods, Klue focuses on "competitive enablement" by connecting intelligence directly to sales results and providing tools to measure how these insights impact a company's total revenue. The company’s goal is to provide a comprehensive view of the competitive landscape so businesses can make informed strategic decisions and increase their win rates.

Company Size

51-200

Company Stage

Grant

Total Funding

$89.5M

Headquarters

Vancouver, Canada

Founded

2015

Get referred to Klue

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • June 2026 incident shows demand for vendor-risk tools that protect delegated SaaS access.
  • Klue kept core platform intact, limiting damage to integration-only workflows.
  • Compete Agent and the June 2026 win-loss suite deepen automation against manual CI teams.

What critics are saying

  • June 2026 Icarus breach exposed customer Salesforce data through dormant credentials and OAuth tokens.
  • Salesforce disabled Klue Battlecards integration in June 2026, threatening renewals and expansions.
  • A repeated identity lapse becomes existential if customers exit after another vendor compromise.

What makes Klue unique

  • Klue owns competitive enablement, battlecards, and win-loss workflows in one enterprise suite.
  • Compete Agent, launched July 2025, pushes competitor intel into Salesforce and Slack.
  • Its 500-plus customers and 250,000 users create sticky workflow depth.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive base compensation

Extended health & dental benefits

Unlimited vacation

Employee Stock Option Plan

Pension fund

Yearly fully-paid trips to Vancouver headquarters

Free access to an online learning tool offering many engineering courses

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

-9%

2 year growth

1%
LeMagIT
Jul 30th, 2026
Ransomware: the average amount paid rises, while the median falls.

Ransomware: the average amount paid rises, while the median falls. The average ransom paid increased quarter over quarter, while the median amount declined. This is notably due to a malicious actor focusing on law firms. Published on: July 30, 2026 On the ransomware front, the second quarter of 2026 brings a surprise. The average ransom amount rose 176% compared to the first quarter, reaching $1,880,612, while the median amount fell 50% to $150,000. The explanation? An unusual one: a ransomware group that chose to select its victims very meticulously, Silent Ransom Group. Also tracked under the name Luna Moth, this group focuses exclusively on law firms. By threatening to publicly disclose sensitive legal files, the group obtained large sums that significantly skewed the quarterly average, according to Coveware. At the same time, victims' awareness of the volatility of post-payment outcomes is on the rise. Victims recognize that payment does not guarantee data deletion. The attack against Klue in June illustrates this fragility: after a supposed payment to guarantee deletion, it turned out that another criminal group had kept the data and the victims' names, thus maintaining a persistent extortion threat. This risk had already been identified in the past, notably with LockBit. Identity as a privileged access vector. Initial access to information systems has evolved from a reliance on automated technical exploits to a strong reliance on identity. Attackers now favor access paths that seem legitimate, seeking to log in discreetly rather than force a noisy intrusion. The abuse of trusted identities is the dominant trend. Sophisticated social engineering methods, notably vishing, are frequently used to trick employees into obtaining credentials or remote access. In more aggressive operations, malicious actors have even carried out physical infiltration, posing as IT staff to gain direct access to workstations. The intrusion vector has thus expanded beyond simple VPN or RDP. It encompasses the abuse of legitimate authentication flows: password resets, helpdesk manipulation, OAuth grants, delegated applications, remote access portals, and third-party vendor sessions. The initial intrusion often resembles normal authentication or authorized administration, which complicates early detection. The victim profile remains focused on the mid-market. The professional services sector, including law firms, is particularly vulnerable due to the sensitive nature of client information they hold. Coveware notes that company size is not a reliable indicator of extortion risk; exposure is more linked to identity compromise, data sensitivity, and third-party dependencies.

Ironside IT
Jul 27th, 2026
Hackers hack hackers in bizarre data theft.

Hackers hack hackers in bizarre data theft. Posted by ironsideit On July 27, 2026 Most businesses spend time protecting their own networks, but what about the vendors that have access to your data? Whether it's your CRM, payroll provider, document management platform, or marketing software, every third-party application you connect to your business becomes part of your cybersecurity strategy. A recent breach involving competitive intelligence platform Klue is a reminder that your organization's security is only as strong as the weakest vendor in your technology ecosystem. What happened? According to reports, the cybercriminal group known as Icarus gained access to Klue using an old login associated with a pilot project that had never been removed. Once inside, the attackers stole OAuth tokens - digital credentials that allow connected applications to access other business systems without repeatedly asking users to log in. Those tokens reportedly provided access to customer data connected through third-party integrations, including Salesforce environments used by some Klue customers. In an unusual twist, another cybercriminal group then compromised Icarus itself and stole the stolen data, launching a second round of extortion attempts. While the story is unusual, the underlying lesson is not. Old accounts, forgotten integrations, and excessive permissions remain some of the most common ways attackers gain access to business systems. Why this matters to every business. Even if your company has never used Klue, you're likely connected to dozens - or even hundreds - of third-party applications. Examples include: * Microsoft 365 * Salesforce * HubSpot * QuickBooks * DocuSign * Zoom * Dropbox * Slack * Payroll providers * Industry-specific business applications Each integration creates another pathway into your environment. If one vendor experiences a security incident, your business could also be affected depending on the level of access you've granted. This is why cybersecurity is no longer just about protecting your own network. It's also about understanding and managing third-party risk. The hidden risk of forgotten accounts. One of the most concerning details from the Klue breach is that the attackers reportedly used an old credential tied to an abandoned project. This happens more often than many businesses realize. Former employees, old test accounts, pilot projects, and unused integrations frequently remain active long after they've been forgotten. Every unused account represents another opportunity for attackers. Regular account reviews help identify: * Former employee accounts * Shared logins * Test environments * Legacy applications * Unused integrations * Excessive user permissions Removing unnecessary access is one of the simplest ways to reduce cyber risk. Many businesses connect applications to Microsoft 365, Salesforce, Google Workspace, and other cloud platforms with just a few clicks. Over time, these integrations accumulate. Ask yourself: * Does this application still need access? * Does it require this level of permission? * Who approved the connection? * When was it last reviewed? Applications should only have the minimum permissions necessary to perform their intended function. Strengthen your vendor security strategy. Reducing third-party risk starts with visibility. Some best practices include: * Maintain an inventory of software vendors and integrations. * Remove unused applications and inactive accounts. * Require multi-factor authentication (MFA) wherever possible. * Regularly review OAuth permissions. * Monitor for unusual login activity. * Ask vendors about their cybersecurity practices before sharing sensitive information. * Include third-party risk reviews as part of your annual cybersecurity assessment. These simple steps can significantly reduce your organization's exposure. Cybersecurity doesn't stop at your front door. Today's businesses rely on dozens of technology vendors every day. While these tools improve productivity, they also expand your attack surface. The Klue incident is another reminder that cybercriminals are constantly looking for overlooked accounts, excessive permissions, and trusted third-party connections to gain access to valuable business data. A proactive cybersecurity strategy includes protecting not only your own systems but also understanding the risks introduced by every vendor you trust. Is your business managing third-party risk? At Ironside IT, Ironside IT help businesses throughout South Jersey, the Greater Philadelphia area, and Delaware identify security gaps, secure Microsoft 365 environments, review third-party integrations, and build layered cybersecurity strategies that reduce risk. If you're unsure how many applications have access to your business data - or whether those permissions are still necessary - now is a great time to take a closer look.

CSO Online
Jul 27th, 2026
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk.

When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk. Jul 27, 2026 8 mins A strategic overview of the Klue compromise for cybersecurity, risk management and executive leadership professionals. In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain breach evolved into an exceptional case in which a second criminal group claimed to have compromised the first extortion crew and pilfered data that had already been stolen. The result was not simply another ransomware story. It exposed fundamental weaknesses in SaaS integrations, identity-based trust, third-party risk management and executive decision-making. Scene of the crime. Founded in 2015, Klue, a Vancouver, British Columbia-based software-as-a-service (SaaS) company, provides an AI-powered competitive intelligence platform that serves more than 500 customers and employs more than 200 people across North America and Europe. The company has raised approximately $81 million in venture funding. The platform helps organizations monitor competitors, analyze market signals and distribute insights across sales, marketing, product and executive teams. By aggregating public sources, internal knowledge, and third-party data, Klue turns fragmented information into actionable intelligence that supports faster strategic decisions, stronger competitive positioning, and more effective product planning. Klue's "Battlecards app" integrates with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack, syncing account records, deal data, contact information and call transcripts. Cause of the breach. Klue occupies a privileged position within customer environments since it integrates with platforms such as Salesforce and other collaboration ecosystems. Those integrations rely heavily on OAuth tokens that permit trusted, authenticated access without repeatedly requesting credential inputs. Attackers from the Icarus criminal group discovered an unused but still-active service account credential originally created for a pilot project. That unused, forgotten credential provided an entry point into Klue's integration infrastructure. Rather than stealing passwords, the attackers harvested OAuth tokens. This distinction matters. Modern identity-based attacks increasingly focus on session tokens and application trust relationships instead of credential theft. Once valid OAuth tokens were obtained, the attackers effectively inherited the permissions granted to Klue within customer environments. They executed extensive Salesforce API queries over a period of hours, extracting customer relationship management data including contact information, quotes, pricing information, sales communications and account records. Continuance of the breach. The most unusual aspect of the incident emerged after the initial compromise. Icarus allegedly informed Klue that another criminal group had obtained sample data after compromising Icarus' servers. That second group reportedly attempted to directly extort affected organizations independently while advising victims not to trust Icarus. Whether every claim can ultimately be verified is less important than the strategic lesson it illustrates. Stolen data can itself become a target inside criminal ecosystems. This development fundamentally alters the traditional ransomware decision model. Organizations have long debated whether paying a ransom increases the likelihood that stolen information will remain private. But the Klue breach illustrates an even more troubling possibility. Even if an organization believed the original attackers would honor an agreement to delete stolen information, the criminals may no longer control the data. If threat actors maintain poor operational security, expose infrastructure or suffer compromises themselves, victims may face repeated extortion campaigns despite paying the initial demand. CISO perspective. From a CISO perspective, this incident reinforces an uncomfortable reality: identity has become the new perimeter. Security investments focused exclusively on endpoint protection or network segmentation provide little protection when a trusted SaaS application already possesses legitimate access to enterprise data. The breach also demonstrates how seemingly insignificant technical oversight becomes enterprise risk. The root cause was not an advanced zero-day exploit. Instead, an inactive credential remained enabled years after its intended purpose had ended. Security professionals routinely discuss attack surface reduction, yet dormant service accounts, forgotten API keys and obsolete integrations continue to exist inside many organizations. CSO smart answers. Explore related questions. Governance failures frequently create greater exposure than sophisticated malware. Klue reportedly detected suspicious activity quickly, revoked credentials, removed malicious code and engaged incident response specialists and law enforcement. These actions reflect mature incident response processes. Nevertheless, the downstream impact extended well beyond Klue because customers had delegated trusted access to the platform. The compromise therefore became a supply-chain event in which one vendor's security weakness propagated risk across numerous downstream organizations. Executive perspectives. For executive leadership, the incident raises broader governance questions. Vendor risk assessments often emphasize compliance certifications, questionnaires and contractual commitments. Far less attention is devoted to lifecycle management of privileged service accounts, continuous credential governance or monitoring of delegated application permissions. Executives should ask whether critical SaaS providers regularly eliminate dormant credentials, rotate secrets and continuously validate privileged integrations rather than relying solely on annual audits. Executives therefore should recognize that ransom payments cannot reliably purchase exclusivity or certainty. Cyber extortion increasingly resembles a fragmented marketplace in which multiple actors may possess copies of the same information. Risk decisions should be evaluated with that possibility explicitly acknowledged. Several practical lessons emerge: * Organizations should inventory every SaaS integration possessing privileged API access and regularly validate business justification. * Privileged service accounts require formal ownership, expiration policies and automated deprovisioning. * OAuth tokens deserve the same governance attention historically applied to passwords and certificates. * Organizations should continuously monitor abnormal API behavior capable of revealing high-volume data extraction. In the Klue breach, Icarus attackers were allegedly executing approximately 1,000 queries within a fifteen-minute timeframe against one environment. * Third-party risk programs should evaluate operational security practices surrounding identity governance rather than treating compliance certifications as sufficient evidence of resilience. Board of director perspective. Boards also should broaden the metrics they receive from security leadership. Instead of measuring only phishing click rates or vulnerability counts, executives should understand how many privileged SaaS integrations exist, how many dormant service accounts remain active, how frequently application permissions are reviewed, and how rapidly suspicious API activity can be detected and contained. These indicators more directly reflect organizational exposure in cloud-centric environments. The Klue incident represents more than just another breach. It demonstrates that modern enterprises inherit both the strengths and weaknesses of every trusted integration within their digital ecosystem. It also reveals that cybercriminal organizations are neither unified nor necessarily competent custodians of stolen information. When attackers become victims themselves, organizations discover that extortion risk does not end with the initial compromise. Afterthoughts. * As identified on the Ransomware Live website, Icarus is a relatively new ransom group whose criminal activity was first identified in May 2026. To date, they have victimized twelve entities across three countries: the United States, Canada and Indonesia. Csoonline may not know the entirety of the blast radius caused by the Klue breach, but it is significant, with allegedly 195 victims. * For this article, I accessed Klue's impressive Trust Center. Klue boasts badges for SOC 2, GDPR and CCPA compliance. Additionally, Klue identifies nearly 50 security controls spread across infrastructure security, organizational security, product security and internal security procedures. The Klue Trust Center also provides a notice dated May 6, 2026, announcing that they completed their SOC 2 Type 2 audit for the period of March 16, 2025, to March 15, 2026. It should be noted that SOC 2 Type 2 compliance should be audited and renewed on an annual basis. According to Klue's update, they are not SOC 2 Type 2 compliant. * In reviewing Klue's Leadership website page, there is no one identified on the team with a CISO title. I also conducted a LinkedIn and internet search and I could not find a Klue employee with a CISO or similar title responsible for enterprise cybersecurity. For CISOs, executives and boards, the lesson is straightforward. Trust relationships require continuous governance, identity is now a primary attack surface and organizations must assume that once data leaves their control, no criminal promise can restore certainty. In an era where even hackers can be hacked, resilience - not misplaced trust - remains the only sustainable defense.

Salesforce Ben
Jul 1st, 2026
Salesforce OAuth attacks are getting worse: hackers hacking hackers.

Salesforce OAuth attacks are getting worse: hackers hacking hackers. By Henry Martin July 01, 2026 Salesforce integrator Klue's OAuth hacking situation has taken a bizarre turn with the threat actor responsible for the breach apparently claiming to have also been hacked. AI competitive intelligence platform Klue - which integrates with Salesforce to simplify CRM usage - suffered the breach in June, and a number of peculiar events have taken place in the following days. The original hacking group, identified as 'Icarus', was threatening Klue with releasing the stolen data in a bid to extort the company, according to TechCrunch, which reports that Klue has been negotiating with Icarus. But in a strange twist, it has now been claimed that Icarus has warned Klue about a second hacker threatening its customers after stealing Klue's customer data directly from Icarus. Let's take a look at what happened. The early days of the hack. In June, cybersecurity company Reliaquest noticed a compromised integration between Klue and Salesforce. This was used to exfiltrate CRM data using OAuth tokens and automated REST API queries. The activity resembled the 2025 and 2026 third-party OAuth-abuse campaigns against Salesforce, which the ShinyHunters hacking group took credit for. The integration with Klue was used as an entry point to reach a Salesforce environment and accessible CRM data. Account records, contact details, and deal outcomes may have been accessed, it is understood. Salesforce issued a security advisory on June 17 outlining that integration with the Klue Battlecards app had been disabled. The company said in a statement: "Salesforce took this action because our security teams recently detected unusual activity involving the app that may have resulted in unauthorized access to a subset of customer data via the app's connection to Salesforce." Salesforce stressed that the issue is limited to Klue's app connection and does not arise from a vulnerability within the Salesforce platform. Reliaquest outlined how attackers authenticated to their targets' Klue integration service accounts, generated OAuth tokens, and ran automated scripts to pull "large volumes" of Salesforce records through the REST API over an approximate 24-hour period. As we wrote at the time, this incident - along with the previous Salesloft and Gainsight exploits - is a clear indication that any top-ranked app vendor with integrations to enterprise SaaS and application platforms should consider itself a target of threat groups. "The OAuth-abuse playbook is repeatable, effective, and now widely adopted," Reliaquest said. So who hacked the hackers? June 22. In an update posted on June 22, Reliaquest said that a Telegram account claiming to be the ShinyHunters hacking group was taking responsibility for the Klue breach. ShinyHunters were one of the big names believed to be behind the large wave of Salesforce data theft attacks last year. The Telegram account claiming to be the ShinyHunters said that "a number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated", and advised Klue to contact them for a "swift resolution". A Session Messenger ID attributed to the Icarus data extortion group was included in the post, suggesting a potential relationship between the two groups, but this has not been verified. Reliaquest said that it is possible that an unrelated actor is leveraging ShinyHunters' reputation to amplify extortion pressure. Cybersecurity firm Huntress was among the Klue customers affected by the breach. They also posted a blog, dated June 22, outlining that Icarus listed data for Huntress and "several other companies" that were impacted on its data leak website. Huntress said in their statement that their company's affected files are limited to Salesforce data, including business contact information, business names, products trialled/used, subscription details, and sales-related communications with customers and partners, as well as opportunity notes. "As expected, no data associated with Huntress products or infrastructure, or any telemetry, passwords, or payment card data was impacted, based on current evidence," Huntress said. June 24. Two days later, on June 24, Huntress said they were aware of new activity related to the Klue incident. Huntress said: "A separate unauthorized party has claimed access to data associated with the incident and has made statements regarding potential disclosure. "At this time, these claims remain unverified, and our team is actively investigating in coordination with security researchers." They added that the unverified claims included supposed plans to publish sample information about companies that have engaged with the original Icarus threat actor, including the names of nearly 200 companies. Following that, the unauthorized party claims that information about the victims will be released daily, unless a "compromise" is made. June 25. Then, on June 25, TechCrunch reported that Klue was communicating with hackers and said it believed the group was deleting the stolen data. In an update shared privately with its customers, Klue reportedly said: "We continue to communicate with the threat actor we have been in contact with ('Icarus'). "Icarus told us they are taking steps to delete the data taken from Klue customers. The Icarus site remains down, and we have indications that Icarus is indeed taking steps to delete data taken from Klue customers." TechCrunch claimed the email had been verified with multiple sources. We have not independently verified that Klue paid Icarus. SF Ben has contacted Klue for comment. Cyber Daily reports that the second hacker is now extorting Klue's customers, and Icarus asked the company to pass on a message to not pay this "other party". CISO at Acronis, Gerald Beuchelt, said that the incident demonstrates the challenges of the simple mantra of 'don't negotiate with cyber criminals', calling it "tone-deaf advice". Beuchelt added: "If a hospital is locked out of its systems, this can be a life and death situation, and if it's data that's compromised, it could be incredibly sensitive, and you may owe it to the people whose data it is to do what you can to keep that private. "However, there is the simple fact that when you're dealing with criminals, you don't necessarily get what you pay for. If you can possibly avoid it, you're better off not negotiating and just restoring via backups." What to do now. If you're concerned you may be at risk of the gaps exploited in these incidents, Reliaquest recommends revoking and rotating credentials and tokens. Reset and reissue everything tied to the Klue integration. This includes the service-account password, refresh tokens, client secrets, and active OAuth grants. You need to revoke the refresh token, not just reset a password, to sever persistent access. Next, review Salesforce API activity. Look for unusual REST API query volume, repeated pagination through large result sets, the Python-urllib user-agent, and access from unfamiliar IP addresses. Also, lock down API access to known infrastructure. Enforce IP allowlisting on third-party integration accounts and connected apps. Be sure to apply the same restriction to SIEM and SOAR APIs - meaning requests from outside approved sources are blocked and alerted. Final thoughts. A breach rarely ends when the first intrusion is contained. As this incident seems to demonstrate, it can spiral into an ongoing nightmare with no clear resolution, and a fog of war muddying the details. What began as a fairly typical OAuth-token abuse case has evolved into something altogether more challenging - and at least a little confusing - for Klue. Whether Icarus, ShinyHunters, and this apparent "second hacker" really are different actors, overlapping personas, or just one unified group amplifying pressure by pretending to be several parties, the ambiguity is in itself a driver of fear and urgency - which likely only benefits the extortionists. The author. Henry Martin. Henry is a Tech Reporter at Salesforce Ben.

LogicMonitor
Jun 26th, 2026
Security advisory: third-party security incident involving Klue.

Security advisory: third-party security incident involving Klue. Information regarding a third-party Klue security incident involving Catchpoint's Salesforce environment, including scope, data involved, and response measures. June 26, 2026 LogicMonitor Security Team Get the latest blogs, whitepapers, eGuides, and more straight into your inbox. This site is protected by reCAPTCHA. What happened? Klue recently disclosed a security incident involving its platform, a third-party competitive intelligence solution that was integrated with Catchpoint's Salesforce environment. According to Klue, attackers compromised its integration infrastructure and used stolen OAuth credentials to gain unauthorized access to data available through connected Salesforce integrations. Upon learning of the incident, LogicMonitor immediately activated its incident response procedures and began working with Klue, Salesforce, and other relevant parties to investigate the matter. Its investigation has confirmed that unauthorized access to the Catchpoint Salesforce environment occurred. The Klue integration has since been removed, the unauthorized access has been contained, and its investigation into the full scope of the incident remains ongoing. The incident was limited to the Catchpoint Salesforce environment. LogicMonitor's primary Salesforce environment was not impacted. What information was involved? While the investigation is ongoing, at this time the data accessed appears to be limited to business relationship and sales activity data stored in Catchpoint's Salesforce environment. This includes business contact information, such as names, business email addresses, phone numbers, account information, sales opportunities, quotes, and other CRM records. By design, LogicMonitor, including Catchpoint, maintains secure and logical separation between its CRM systems and production systems. Salesforce is used to manage customer relationships and sales activity and does not store customer monitoring data, production systems data, authentication credentials, payment information, or other operational customer data. As a result, this information was not accessible through the Klue integration. Is there any action customers need to take? At this time, no action is required. LogicMonitor is communicating directly with affected customers and working with them in accordance with applicable laws and its contractual commitments. What is LogicMonitor doing? LogicMonitor is conducting a comprehensive investigation and forensic assessment to validate the full scope and extent of customer impact. LogicMonitor is closely monitoring the situation, implementing additional security measures as appropriate, and will provide further updates as new information becomes available. By LogicMonitor Security Team Disclaimer: The views expressed on this blog are those of the author and do not necessarily reflect the views of LogicMonitor or its affiliates.

INACTIVE