We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Claimed Data Breach at Klark.ai: The Real Risk for Small and Medium-Sized Businesses Using AI Tools

A hacker has claimed responsibility for stealing more than 140 GB of data from Klark.ai, a French AI platform dedicated to customer service. Approximately 500,000 people are reportedly affected, with support conversations, API keys, and a few IBANs among the stolen data. Here’s how to tell if your small business is indirectly at risk—and the three checks you should perform this week.

Claimed Data Breach at Klark.ai: The Real Risk for Small and Medium-Sized Businesses Using AI Tools

In summary: A hacker has claimed responsibility for stealing more than 140 GB of data from Klark.ai, a French AI platform used by customer service teams. For a small or medium-sized business, the immediate risk is not that its own information system will be compromised, but that its employees and customers will receive highly sophisticated phishing attempts.

What Happened

On August 23, 2026, an individual going by the pseudonym 0xSec posted a claim of responsibility targeting Klark.ai on a criminal forum. The incident was reported on August 24 by the monitoring sites Cyberattaque.org and FrenchBreaches, which track data breaches in France.

According to this claim, the attacker extracted more than 140 GB spread across four databases, comprising 162 CSV files, several of which contain more than two million lines. The number of individuals affected is estimated at around 500,000. The data in question includes names, email addresses, and phone numbers; password hashes; support conversations; technical logs; API keys and secrets; and some bank account information.

Klark.ai offers an AI that suggests responses to support agents and builds a knowledge base from the conversations it processes. This explains the broad scope of the platform: it hosts conversations from the customer service departments of its client companies. Several well-known brands appear in the conversation data. Their presence in these databases does not mean that their own information systems have been compromised.

Important note: At this point, these figures come from the hacker. The actual volume, the complete authenticity of the dataset, and the exact number of people affected have yet to be confirmed.

Does this apply to me?

Three exposure circles, from the most direct to the most indirect.

You use Klark.ai for your customer service. Your agents are likely listed in the exposed accounts, as are the conversations you’ve had with your customers. If a connector links the tool to your CRM, help desk, or email system, the API keys that have been claimed require immediate attention.

Your employees have communicated with a customer service team that uses the platform. Their contact information and the content of the conversation may be shared. An attacker who is familiar with the order, dispute, or ongoing request can write an email that is far more credible than a generic phishing email.

No one at your company has tampered with the tool. The risk becomes a statistical one, but it doesn't disappear: reusing passwords between personal and work accounts remains the most common point of entry.

To assess where you stand, the question to ask your teams isn’t “Are we using Klark?” but “Which AI tools currently have access to our customer data?” Many of these subscriptions are set up by business units without going through the IT department. This is exactly the topic we explore in our report on shadow AI in the workplace.

What to Do Now

1. Take inventory of the AI tools connected to your data. List the SaaS AI subscriptions used in customer service, marketing, and support—including those paid for with a corporate credit card outside the IT budget. For each one, note what data is being processed and which systems are connected. This inventory will serve you well long after this incident is over.

2. Rotate your API keys and review the access logs. If an affected tool has a token for your CRM, ERP, or Microsoft 365, revoke it and generate a new one. Then check for recent connections on your service accounts. A stolen key is often used weeks later, once attention has died down.

3. Notify the teams at risk, particularly support and accounting. Inform them that there will likely be an increase in messages referencing an actual order or case. Remind them of the rule that always applies: any request for payment, a change to bank account information, or the disclosure of login credentials must be verified through a different channel—using a known phone number—before taking any action.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

An AI platform that handles customer service inherently contains highly contextual data: who bought what, who filed a complaint about what, and using which phone number. When this type of tool is compromised, the raw material for targeted phishing ends up on the market—even for companies that have never heard of the software vendor.

The answer lies in two governance steps: knowing which AI tools have access to your data, and knowing how to quickly revoke their access. This is nothing insurmountable for an SME, provided it takes stock of its systems before an incident occurs rather than after.

Frequently asked questions

My company is mentioned in the conversations cited—have my servers been compromised? No. The data comes from the AI platform, not from the systems of the companies in question. The focus is on protecting your customers and employees, not on hacking into your systems.

Passwords are hashed—is that enough? It slows down an attacker, but doesn't stop them if the password is weak or already known. Change any passwords that have been reused elsewhere, and enable multi-factor authentication where it's missing.

Is notification to the CNIL required? If you are a data controller and the data breach affects your customers through a processor, the obligation to notify within 72 hours applies as soon as the risk to individuals is confirmed. First, ask the software vendor for written confirmation of the scope of the breach.

— Samir Amara, CEO — IT Systèmes

Our latest articles

See more
Logo de Microsoft 365 Copilot
Cybersecurity
Data & AI

Copilot et sur-partage : ce qu'il peut révéler dans Microsoft 365

Copilot ne crée pas de nouveaux accès, il révèle ceux qui existent : six situations de sur-partage à risque, comment les repérer et les corriger.
9/10/2026
illustration defender suite et purview suite
Cybersecurity

Defender Suite et Purview Suite : sécurité E5 pour Business Premium

Defender Suite et Purview Suite ajoutent à Business Premium la sécurité de niveau E5 : contenu, prix catalogue (10 $, 10 $, 15 $), six cas concrets et NIS2.
9/10/2026
Cybersecurity

Fuite Hauts-de-France : ce qu'une PME doit vérifier dans la foulée

Deux prestataires de la région Hauts-de-France auraient été piratés, avec des centaines de milliers de personnes potentiellement concernées selon les revendications de l'attaquant. Voici ce qui est connu, ce qui reste à confirmer et les trois vérifications à faire côté PME.
7/10/2026
Cybersecurity

LLMOps : définition et exploitation des agents IA en production

LLMOps : définition, différence avec le MLOps et l'AIOps, et les six briques pour exploiter un agent IA en production. Avec l'exemple de notre agent Helpy.
6/10/2026
Assistant IA symbolisé par un robot au-dessus d'une main devant un ordinateur portable
Cybersecurity

Sécuriser MCP en entreprise : risques et bonnes pratiques pour les DSI

Model Context Protocol (MCP) : les risques de sécurité pour l'entreprise (serveurs non vérifiés, droits trop larges, injections) et les bonnes pratiques.
5/10/2026
IT Systems Consultant showing a monitoring dashboard to a colleague
Cybersecurity

Superviser un agent IA en production : méthode et indicateurs

Superviser un agent IA en production : actions, erreurs, coûts, dérives, seuils de reprise en main et indicateurs. La méthode appliquée à notre agent Helpy.
2/10/2026