Note: This blog post was updated on July 1st, 2026.
We’re sharing an update with customers on a known compromise involving third-party provider Klue’s integration with Salesforce. Tines was notified that it was among the organizations affected by this incident, which impacted Tines’ Salesforce instance and some of the CRM data it holds. We have confirmed that the Tines platform and customer environments were not impacted.
As security professionals, we know how frustrating these incidents can be, and are taking a rigorous approach to investigating this compromise. Our priority is transparency to our customers.
This post outlines key details of the incident and Tines’ response, and will be updated with any new details that emerge as our investigation continues.
What happened
On or about June 11th, a threat actor compromised market intelligence platform Klue’s systems. The threat actor then used credentials associated with Klue customers’ integrations to access Salesforce data across multiple organizations, including Tines.
Tines was notified that we were impacted by this incident, and initiated an investigation into this third-party incident and any impact on customers.
What is the impact?
Our initial investigation into the Klue incident has confirmed that the activity is limited to Salesforce business information. This information could include:
Business and account contact information
Account and opportunity information
Commercial communications stored in Salesforce
Sales-related records associated with customer or prospect relationships
Based on our investigation to date, we have found no evidence of unauthorized access to any information outside of Salesforce, including within Tines production systems, customer environments, workflow data or authentication credentials.
Next steps
Following our initial investigation, Tines took immediate action to address this issue, including:
Confirming the suspension of Klue’s access in Salesforce.
Requesting confirmation, details, and logs from Klue.
Reviewing available Salesforce logs and requesting further details on the Klue account activity from Salesforce.
Confirming there was no evidence of any unauthorized access to Tines’ production systems, customer environments, product infrastructure, or customer workflow data.
Guidelines to customers
Incidents such as these raise concerns about attempts at phishing and social engineering becoming more convincing. We recommend that customers remain vigilant and evaluate all unexpected communications referencing Tines, Salesforce, Klue, and any invoices, account changes, or payment activity related thereto
As a reminder, Tines will always contact you to confirm payment information and Tines will never ask you for passwords or credentials by email. If you receive a communication that appears to be from Tines and you are unsure whether it is legitimate, contact support@tines.com.
Our focus now
To ensure ongoing updates, we will continue to work with Klue, Salesforce, and other relevant parties to gather more information and continue to investigate this incident and its impact.
We are here to support our customers and encourage you to reach out with any questions or concerns you may have following this third-party compromise. Get in touch with your account team or support@tines.com.
Update July 1st, 2026
Tines has completed its investigation and incident review of the Klue-related Salesforce incident. Our investigation confirmed that Salesforce was the only Tines system affected, and there was no unauthorized access to the Tines platform, production systems, customer environments, tenants, workflows, automations, credentials, tokens, or secrets.
We also found no evidence of additional unauthorized access beyond the activity between June 11th and June 12th, 2026 involving the Klue Salesforce integration.
The affected information was limited to Salesforce CRM business information relating to Tines’ customers, prospects, and commercial relationships. This included business contact and account information, opportunity and sales-related records, commercial communications stored in Salesforce, and related CRM activity records. A limited number of Salesforce records included support-adjacent information. Salesforce is not Tines’ support ticketing platform or system of record for customer support, and any support-related information in Salesforce was incidental to Salesforce CRM activity.
Tines reviewed affected Salesforce records for sensitive customer information. In limited cases where potentially sensitive information was identified, Tines notified those customers directly.
Tines has completed remediation steps, including removing the Klue integration, confirming suspension of Klue-related Salesforce access, reviewing available Salesforce logs and activity, reviewing Salesforce connected applications and OAuth access, reviewing integration users and permissions, implementing additional CRM detections, and reviewing vendor offboarding controls.
We are not recommending rotation of Tines credentials, API keys, secrets, or tokens. The incident did not involve unauthorized access to Tines’ authentication systems, customer environments, workflows, production systems, or customer workflow data. The Tines platform continues to operate normally and customers do not need to take action to continue using Tines.
Customers with questions can contact customer-trust@tines.io. To receive future trust-related communications from Tines, please subscribe to Trust Center updates at trust.tines.com.
Frequently Asked Questions
Were customer environments, tenants, workflows, or live automations affected?
No. The Tines automation platform, live workflows, production environments, customer tenants, customer environments, credentials, secrets, tokens, automation data, and customer workflow data were not affected.
Do we need to rotate credentials or API keys for Tines?
No. We are not recommending rotation of Tines credentials, API keys, secrets, or tokens.
The incident did not involve unauthorized access to Tines production systems, customer environments, workflows, authentication systems, credentials, secrets, tokens, or customer workflow data.
Was any system outside Salesforce affected?
No. Salesforce was the only Tines system affected.
There was no unauthorized access to the Tines platform, production systems, customer environments, tenants, workflows, live automations, authentication systems, automation data, customer workflow data, source code, payment systems, financial systems, or other Tines infrastructure.
Were end users of Tines customers affected?
No. This incident did not involve information relating to the end users or customers of Tines’ customers.
The information involved was limited to data maintained within Tines’ Salesforce CRM relating to Tines’ customers and prospects, our commercial relationships with those organizations, and individuals who work with Tines or may work with Tines in the future.
What Salesforce information was affected?
The affected information was limited to Salesforce CRM business information, including:
Business and account contact information
Account and opportunity information
Sales-related records associated with customer or prospect relationships
Commercial communications stored in Salesforce
Related CRM activity records
Limited support-adjacent information incidentally stored in Salesforce
Did the affected Salesforce data include sensitive customer information?
Tines reviewed affected Salesforce records for sensitive customer information. In a small number of cases where sensitive information was identified, Tines notified those customers directly.
Are there any Indicators of Compromise you can share?
Yes. The following malicious IP addresses have been shared by Klue in this investigation:
138[.]226[.]246[.]94
212[.]86[.]125[.]24
213[.]111[.]148[.]90
94[.]154[.]32[.]160
185[.]156[.]46[.]164
Customers may also wish to review traffic to Salesforce involving the user agents Python-urllib/3.12 or Python-urllib/3.14, or Klue-related traffic that does not contain the expected user-agent header python-httpx/0.28.1.
What actions has Tines taken?
Tines has removed the Klue integration from its internal systems. Tines also reviewed available Salesforce logs and activity, requested additional details from Klue and Salesforce, reviewed Salesforce connected applications and OAuth access, reviewed integration users and permissions, implemented additional CRM detections, and reviewed vendor offboarding controls.
What actions do you recommend customers take?
Customers do not need to take action to continue using Tines.
We recommend remaining vigilant for unexpected communications referencing Tines, Salesforce, Klue, invoices, account changes, credential requests, or similar topics. Tines will not ask for financial information, passwords or other sensitive information via email.
How can I receive updates on this and other issues?
To receive trust-related communications from Tines, including updates on this incident, please subscribe to Trust Center updates at trust.tines.com.