Open report — full analysis, no account required.

Sign up to generate reports and read filings that aren't on the open list.

Sign up free

Get notified when EGHT files again. Create a free account and we'll email you the moment its next filing is analyzed.

Get filing alerts

Critical incident detected

Data breach / PII exposure

Time-sensitive event — see the red-flag panel below for the source-quoted detail.

Red Flags Detected

  • Third-party Integration Vulnerability Exploited (new) — Attacker gained unauthorized access through a third-party application (Klue) connected to the company's core CRM system, exposing weaknesses in vendor security controls.
  • Competitively Sensitive Customer Data Exfiltrated (new) — Contract details, sales opportunities, and customer contact information were extracted, creating potential competitive disadvantage and phishing risk for 8x8's customer base.
NASDAQ: EGHT 8X8 INC /DE/ 8-K

8x8 discloses cybersecurity breach exposing customer sales and contact data

Filed June 23, 2026 · Period ending June 17, 2026 · ~1 min read

4 key changes 2 high relevance 2 red flags 1 section

Key Changes

  • high

    Unauthorized attacker exploited third-party Klue integration to access 8x8's Salesforce CRM on June 11-12, extracting customer contract details, sales opportunities, and business contact information.

  • high

    Compromised data includes competitively sensitive information on current, former, and prospective customers: fragmented contract terms, sales team notes, names, business addresses, phone numbers, and email addresses.

  • medium

    Investigation indicates breach was isolated to Salesforce data accessible through the Klue integration; the compromised integration has been disabled and unauthorized access removed.

  • medium

    Customer service and core systems remain fully operational with no disruption; management does not expect material impact on financial results, though investigation continues.

Summary

8x8 disclosed a cybersecurity incident in which an unauthorized attacker exploited a third-party integration (Klue Labs) connected to the company's Salesforce CRM system. Over June 11-12, 2026, the attacker extracted competitively sensitive customer information including contract details, sales opportunities, internal sales notes, and business contact data for current, former, and prospective customers.

The company was notified on June 13 and has since disabled the compromised integration and removed unauthorized access. The breach raises two concerns for investors. First, the vulnerability in a third-party integration point exposes weaknesses in 8x8's vendor security controls—a risk that extends beyond this single incident to the broader ecosystem of connected applications.

Second, the exfiltrated data could be weaponized by competitors or used in targeted phishing campaigns against 8x8's customer base, potentially affecting customer relationships and competitive positioning. While management states the incident has not disrupted operations or customer service and is not expected to materially impact financial results, the investigation remains ongoing. Investors should watch for any customer churn signals in upcoming quarters and details on the enhanced security measures being implemented to prevent similar third-party integration breaches.

Section-by-Section Diff

Event · Item 1.05

~800 words

Item 1.05 filed; see Key Changes for terms.

4 Added
Added Cybersecurity breach via third-party integration high

Added in current filing · verify on EDGAR →

On June 13, 2026, 8x8, Inc. (the “Company” or “we”) was informed that an unauthorized third party threat actor exploited the Klue Labs, Inc. (“Klue”) third-party application programming integration connected to the Company's Salesforce, Inc. (“Salesforce”) customer relationship management system. The threat actor gained unauthorized access and exfiltrated certain information from 8x8’s Salesforce system. This unauthorized access occurred between June 11 and 12, 2026.

An unauthorized attacker exploited a third-party integration (Klue) connected to 8x8's Salesforce CRM system and extracted customer data over a two-day period in mid-June 2026. The company was notified one day after the breach ended. The compromised integration has been disabled and unauthorized access removed.

Added Data exfiltrated in breach high

Added in current filing · verify on EDGAR →

The threat actor exfiltrated certain competitively sensitive information about current, former and prospective customers of the Company, including fragmented contract and opportunity information, sales team notes, and contact information (names, business addresses, phone numbers and email addresses of the customers).

The breach exposed competitively sensitive customer information including contract details, sales opportunities, internal sales notes, and business contact information for current, former, and prospective customers. This data could potentially be used by competitors or for targeted phishing attacks against 8x8's customer base.

Added Scope and impact assessment medium

Added in current filing · verify on EDGAR →

Our investigation to date indicates that this incident was isolated to information stored in 8x8’s Salesforce system that was accessible through the Klue integration. The Company has and continues to implement additional security measures to reduce the risk of similar unauthorized access in the future.

The company's investigation indicates the breach was limited to data accessible through the specific Klue integration and did not spread to other systems. 8x8 is implementing additional security controls to prevent similar third-party integration vulnerabilities.

Added Operational and financial impact medium

Added in current filing · verify on EDGAR →

As of the date of this report, other than the Company’s response and remediation activities, the incident has not had an impact on the Company’s business or operations. The Company’s ability to serve customers has not been impacted, and its information systems remain operational and undisrupted ... based on the investigation to date, the incident is not expected to have a material impact on the Company’s operations or the Company’s financial condition or results of operations.

The company states that customer service and core systems remain fully operational with no disruption. While the incident is reportable under SEC rules due to the nature of data accessed, management does not expect it to materially affect financial results or operations, though the investigation is ongoing.

Was this report useful?

Figures/quotes linked to EDGAR · Narrative written by AI · Jun 23, 2026 · How we verify