Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Incidents & Breaches Klue

Klue OAuth breach exposes Salesforce data in extortion campaign

A breach at market intelligence platform Klue has led to the theft of Salesforce CRM data from multiple organizations by the Icarus extortion group.

Klue OAuth breach exposes Salesforce data in extortion campaign
Mindaugas Skrupskelis · Pexels

Market intelligence platform Klue has confirmed a security breach involving its OAuth integrations, enabling the Icarus extortion group to steal Salesforce CRM data from multiple organizations. The incident, first reported on 17 June 2026, has prompted Salesforce to disable the Klue Battlecards integration as a precautionary measure while investigations are underway. Cybersecurity firms ReliaQuest and Huntress have both acknowledged their data was compromised in the attack, with Huntress confirming receipt of an extortion email from the threat actors.

What happened

The breach originated from a compromised backend system at Klue, where attackers exploited a dormant but still-active credential originally created for a prototype integration. According to Huntress, the threat actors pushed a malicious code update that harvested OAuth tokens used by Klue customers to integrate its Battlecards product with third-party platforms, including Salesforce. Once in possession of these tokens, the attackers used automated Python scripts to query Salesforce’s REST API for nearly 24 hours, exfiltrating data through endpoints such as /services/data/v59.0/sobjects and /services/data/v59.0/query.

ReliaQuest observed that the attackers initially conducted reconnaissance to map out Salesforce objects before rapidly extracting targeted data. In one case, nearly 1,000 queries were executed within a 15-minute window, suggesting a shift from stealth to speed. The stolen data includes business contacts, sales communications, price quotes, competitive intelligence reports, and account information. Huntress confirmed that no passwords, payment card details, or engineering systems were compromised.

Key facts
  • Attackers exploited a dormant Klue credential to push a malicious code update.
  • Salesforce disabled the Klue Battlecards integration on 17 June 2026.
  • Data exfiltration occurred via Salesforce’s REST API over ~24 hours.
  • Stolen data includes CRM records but excludes passwords and payment details.
  • Icarus extortion emails were sent using the alias "mr bean" and a Session Messenger ID.

Who is behind the attack

The campaign has been attributed to the Icarus extortion group, a relatively new threat actor that emerged in April 2026. BleepingComputer reported that Icarus has already begun sending extortion demands to affected Klue customers, with ransom notes including a Session Messenger ID for contact. The group’s data leak site features a post titled "Get Ready," hinting at further victim disclosures. While initial reports suggested possible links to the ShinyHunters group, BleepingComputer confirmed that Icarus is responsible for this campaign.

Huntress noted that the Session ID in later extortion emails matched the one listed on Icarus’s dark web leak site, reinforcing the attribution. At least one victim previously listed on the site has since been removed, potentially indicating ongoing negotiations.

Impact and response

Salesforce has temporarily disabled the Klue Battlecards integration to prevent further unauthorized access. In a statement, the company advised customers that the app would remain unavailable until the investigation concludes. Klue has also disabled integrations with HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack as part of its response.

Organizations using Klue integrations are advised to review logs for activity originating from the following IP addresses linked to the attack:

  • 138.226.246.94
  • 212.86.125.24
  • 213.111.148.90
  • 94.154.32.160
For professionals

For professionals: Security teams should revoke and rotate OAuth tokens associated with Klue integrations, terminate active sessions, and audit Salesforce logs for unusual API activity. The incident underscores the risks of dormant credentials and third-party integrations in SaaS environments.

What to watch

The Icarus group’s extortion campaign is ongoing, and further victim disclosures are likely. Organizations should monitor for updates from Klue and Salesforce regarding the restoration of integrations and any additional remediation steps. The incident also highlights the growing threat of OAuth-based attacks targeting SaaS platforms, which may prompt broader industry scrutiny of third-party app security.

Companies mentioned

Klue Huntress ReliaQuest Salesforce

Discussion · coming soon

Be the first to join the thread when community discussion launches.