FEDERALItem 1.05 · mandatoryHackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICLowContained
8X8 INC /DE/
bd_71ac962cb6631ae0 · schema v1 · pii pii-v1
Full breach record for 8X8 INC /DE/ →8x8, Inc. disclosed a cybersecurity incident involving unauthorized access to its Salesforce CRM system via a third-party integration with Klue Labs, Inc. The threat actor exploited the integration to exfiltrate customer contact information and contract details between June 11 and 12, 2026. 8x8 discovered the breach on June 13, 2026, disabled the integration, and is implementing additional security measures. The incident is not expected to have a material financial impact.
SEC clockMateriality determined Jun 17, 2026 → Filed Jun 23, 20266d ✓ SEC 4-day OK10 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1023731/000102373126000084/eght-20260617.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Jun 23, 2026
- Raw hash
- ba5fac3fdb4b8d5b314641c8018dfaad28d2aae01e1319323d7f9101987f625a
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- 8X8 INC /DE/norm: 8x8 inc de
- SEC CIK
- 0001023731
Victim entity
- Name
- 8X8 INC /DE/norm: 8x8 inc de
Incident
- Discovered
- Jun 13, 2026
- Materiality determined
- Jun 17, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying the relevant regulatory authorities
- Third party
- via Klue Labs, Inc.vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 10 days(10 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Jun 17, 2026→ Filed: Jun 23, 20266d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.