In summary: A hacker has claimed responsibility for stealing more than 140 GB of data from Klark.ai, a French AI platform used by customer service teams. For a small or medium-sized business, the immediate risk is not that its own information system will be compromised, but that its employees and customers will receive highly sophisticated phishing attempts.
What Happened
On August 23, 2026, an individual going by the pseudonym 0xSec posted a claim of responsibility targeting Klark.ai on a criminal forum. The incident was reported on August 24 by the monitoring sites Cyberattaque.org and FrenchBreaches, which track data breaches in France.
According to this claim, the attacker extracted more than 140 GB spread across four databases, comprising 162 CSV files, several of which contain more than two million lines. The number of individuals affected is estimated at around 500,000. The data in question includes names, email addresses, and phone numbers; password hashes; support conversations; technical logs; API keys and secrets; and some bank account information.
Klark.ai offers an AI that suggests responses to support agents and builds a knowledge base from the conversations it processes. This explains the broad scope of the platform: it hosts conversations from the customer service departments of its client companies. Several well-known brands appear in the conversation data. Their presence in these databases does not mean that their own information systems have been compromised.
Important note: At this point, these figures come from the hacker. The actual volume, the complete authenticity of the dataset, and the exact number of people affected have yet to be confirmed.
Does this apply to me?
Three exposure circles, from the most direct to the most indirect.
You use Klark.ai for your customer service. Your agents are likely listed in the exposed accounts, as are the conversations you’ve had with your customers. If a connector links the tool to your CRM, help desk, or email system, the API keys that have been claimed require immediate attention.
Your employees have communicated with a customer service team that uses the platform. Their contact information and the content of the conversation may be shared. An attacker who is familiar with the order, dispute, or ongoing request can write an email that is far more credible than a generic phishing email.
No one at your company has tampered with the tool. The risk becomes a statistical one, but it doesn't disappear: reusing passwords between personal and work accounts remains the most common point of entry.
To assess where you stand, the question to ask your teams isn’t “Are we using Klark?” but “Which AI tools currently have access to our customer data?” Many of these subscriptions are set up by business units without going through the IT department. This is exactly the topic we explore in our report on shadow AI in the workplace.
What to Do Now
1. Take inventory of the AI tools connected to your data. List the SaaS AI subscriptions used in customer service, marketing, and support—including those paid for with a corporate credit card outside the IT budget. For each one, note what data is being processed and which systems are connected. This inventory will serve you well long after this incident is over.
2. Rotate your API keys and review the access logs. If an affected tool has a token for your CRM, ERP, or Microsoft 365, revoke it and generate a new one. Then check for recent connections on your service accounts. A stolen key is often used weeks later, once attention has died down.
3. Notify the teams at risk, particularly support and accounting. Inform them that there will likely be an increase in messages referencing an actual order or case. Remind them of the rule that always applies: any request for payment, a change to bank account information, or the disclosure of login credentials must be verified through a different channel—using a known phone number—before taking any action.
In a nutshell
An AI platform that handles customer service inherently contains highly contextual data: who bought what, who filed a complaint about what, and using which phone number. When this type of tool is compromised, the raw material for targeted phishing ends up on the market—even for companies that have never heard of the software vendor.
The answer lies in two governance steps: knowing which AI tools have access to your data, and knowing how to quickly revoke their access. This is nothing insurmountable for an SME, provided it takes stock of its systems before an incident occurs rather than after.
Frequently asked questions
My company is mentioned in the conversations cited—have my servers been compromised? No. The data comes from the AI platform, not from the systems of the companies in question. The focus is on protecting your customers and employees, not on hacking into your systems.
Passwords are hashed—is that enough? It slows down an attacker, but doesn't stop them if the password is weak or already known. Change any passwords that have been reused elsewhere, and enable multi-factor authentication where it's missing.
Is notification to the CNIL required? If you are a data controller and the data breach affects your customers through a processor, the obligation to notify within 72 hours applies as soon as the risk to individuals is confirmed. First, ask the software vendor for written confirmation of the scope of the breach.
— Samir Amara, CEO — IT Systèmes

.jpeg)




