Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025Industry stats Updated Jun 2026All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026.com + .net total 176.1M names in zone Verisign · Q1 2026.com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026No CMS detected 30% of all sites W3Techs · 17 Jun 2026Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026Apache on 24%–29% of sites W3Techs · Mar–Apr 2026LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTDFortune 500 95% publish DMARC · 80% enforced EasyDMARCFortune 500 62.7% use strict reject policy EasyDMARCInc. 5000 15.2% use strict reject policy EasyDMARCDeal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Incidents & Breaches

Klue OAuth breach exposes Salesforce data in extortion campaign

A breach at market intelligence platform Klue has led to the theft of Salesforce CRM data from multiple organizations by the Icarus extortion group.

Klue OAuth breach exposes Salesforce data in extortion campaign
Mindaugas Skrupskelis · Pexels

Market intelligence platform Klue has confirmed a security breach involving its OAuth integrations, enabling the Icarus extortion group to steal Salesforce CRM data from multiple organizations. The incident, first reported on 17 June 2026, has prompted Salesforce to disable the Klue Battlecards integration as a precautionary measure while investigations are underway. Cybersecurity firms ReliaQuest and Huntress have both acknowledged their data was compromised in the attack, with Huntress confirming receipt of an extortion email from the threat actors.

What happened

The breach originated from a compromised backend system at Klue, where attackers exploited a dormant but still-active credential originally created for a prototype integration. According to Huntress, the threat actors pushed a malicious code update that harvested OAuth tokens used by Klue customers to integrate its Battlecards product with third-party platforms, including Salesforce. Once in possession of these tokens, the attackers used automated Python scripts to query Salesforce’s REST API for nearly 24 hours, exfiltrating data through endpoints such as /services/data/v59.0/sobjects and /services/data/v59.0/query.

ReliaQuest observed that the attackers initially conducted reconnaissance to map out Salesforce objects before rapidly extracting targeted data. In one case, nearly 1,000 queries were executed within a 15-minute window, suggesting a shift from stealth to speed. The stolen data includes business contacts, sales communications, price quotes, competitive intelligence reports, and account information. Huntress confirmed that no passwords, payment card details, or engineering systems were compromised.

Key facts
  • Attackers exploited a dormant Klue credential to push a malicious code update.
  • Salesforce disabled the Klue Battlecards integration on 17 June 2026.
  • Data exfiltration occurred via Salesforce’s REST API over ~24 hours.
  • Stolen data includes CRM records but excludes passwords and payment details.
  • Icarus extortion emails were sent using the alias "mr bean" and a Session Messenger ID.

Who is behind the attack

The campaign has been attributed to the Icarus extortion group, a relatively new threat actor that emerged in April 2026. BleepingComputer reported that Icarus has already begun sending extortion demands to affected Klue customers, with ransom notes including a Session Messenger ID for contact. The group’s data leak site features a post titled "Get Ready," hinting at further victim disclosures. While initial reports suggested possible links to the ShinyHunters group, BleepingComputer confirmed that Icarus is responsible for this campaign.

Huntress noted that the Session ID in later extortion emails matched the one listed on Icarus’s dark web leak site, reinforcing the attribution. At least one victim previously listed on the site has since been removed, potentially indicating ongoing negotiations.

Impact and response

Salesforce has temporarily disabled the Klue Battlecards integration to prevent further unauthorized access. In a statement, the company advised customers that the app would remain unavailable until the investigation concludes. Klue has also disabled integrations with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack as part of its response.

Organizations using Klue integrations are advised to review logs for activity originating from the following IP addresses linked to the attack:

  • 138.226.246.94
  • 212.86.125.24
  • 213.111.148.90
  • 94.154.32.160
For professionals

For professionals: Security teams should revoke and rotate OAuth tokens associated with Klue integrations, terminate active sessions, and audit Salesforce logs for unusual API activity. The incident underscores the risks of dormant credentials and third-party integrations in SaaS environments.

What to watch

The Icarus group’s extortion campaign is ongoing, and further victim disclosures are likely. Organizations should monitor for updates from Klue and Salesforce regarding the restoration of integrations and any additional remediation steps. The incident also highlights the growing threat of OAuth-based attacks targeting SaaS platforms, which may prompt broader industry scrutiny of third-party app security.

Discussion · coming soon

Be the first to join the thread when community discussion launches.