// threat intel

Icarus Gang Breaches Klue Cloud Services Using a 2022 Credential

Icarus Gang Breaches Klue Cloud Services Using a 2022 Credential — security advisory

An extortion group called Icarus reportedly broke into Klue’s systems using a credential issued back in 2022, exposing keys to customers’ cloud services and enabling data theft for extortion.

In the cloud, identity is the perimeter — a single leaked or stale key can be escalated into control of an entire environment.

Our analysis

The real story is not a zero-day — it is a governance failure. A 2022 credential still working in 2026 tells you everything: stale, long-lived, over-privileged credentials are the most common and least glamorous way cloud environments fall. Once inside, extortion crews head straight for customer keys because that maximises leverage. This is a preventable class of breach, and it is squarely within your control.

What you should do

  • Rotate credentials on a schedule and replace long-lived static keys with short-lived tokens.
  • Enforce least privilege and review IAM for unused or over-scoped access.
  • Monitor for anomalous use of old credentials and impossible-travel sign-ins.
  • Run periodic cloud configuration reviews and assumed-breach tests to find these paths before attackers do.

How AgentOffense helps: our cloud configuration review and AWS penetration testing map the privilege paths a stale credential could take, while an assumed breach assessment quantifies the blast radius.

Source: TechCrunch.

How one stale credential becomes total access

Cloud breaches rarely start with a zero-day. They start with a credential — leaked in an old breach, committed to a repo, or left in a config — that was never rotated. Once inside, attackers exploit over-broad IAM permissions to move from a single identity to the entire account: reading data, creating new access, and disabling logging.

The lesson is that identity, not the network perimeter, is the real boundary in the cloud. Least-privilege and ruthless credential rotation are what shrink the blast radius when — not if — a key leaks.

What this means for your business

A years-old credential breaching a cloud provider in 2026 is a stark lesson: stale, un-rotated keys are a standing invitation. In the cloud, one leaked credential often equals full account access because of over-broad permissions.

How to reduce your exposure

  • Rotate credentials and keys on a schedule; kill long-lived static secrets.
  • Apply least-privilege IAM and remove unused roles and access.
  • Enforce MFA everywhere and monitor for anomalous credential use.
  • Audit your cloud configuration against real attack paths.

Find over-permissive access before attackers do with cloud configuration review and identity & access testing — get a fixed-price quote.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement