Security

HubSpot says it’s investigating customer account hacks

Comment

An HubSpot logo at the Boston Convention and Exhibition Center on September 06, 2023.
Image Credits: Chance Yeh / Getty Images

Marketing and sales software giant HubSpot said on Friday that it’s investigating a cybersecurity incident.

On Friday, rumors of some kind of cyberattack against HubSpot began circulating on social media. When reached by TechCrunch on Friday, HubSpot’s chief information security officer Alyssa Robinson said in a statement that the company “identified a security incident that involved bad actors targeting a limited number of HubSpot customers and attempting to gain unauthorized access to their accounts.” 

Contact Us

Do you have more information about the HubSpot breach? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

“HubSpot triggered our incident response procedures, and since June 22 we have been contacting impacted customers and taking necessary steps to revoke the unauthorized access and protect our customers and their data,” said Robinson.

The company did not say, when asked by TechCrunch, if it has received any communication from the malicious actors.

HubSpot is a U.S.-based company that specializes in customer relationship management (CRM) and marketing automation software, and has a market cap of almost $30 billion as of Friday. 

At this point, it’s unclear what’s the extent of the incident and how many HubSpot customers were affected.

HubSpot says it has more than 216,000 corporate clients, and touts Discord, Eventbrite, Talkspace and others as big name customers.

UPDATE, July 1, 10:29 a.m. ET: After this story was published, HubSpot published a statement with more details about the incident. The company wrote that it believes the “the bad actors were able to gain unauthorized access to less than 50 HubSpot accounts,” and that as of 4:00 p.m. ET on Friday, June 28, “we have seen no new instances of unauthorized access in the last 24 hours, and we have contacted all impacted customers at this time.”

More TechCrunch

Microsoft has given its Copilot assistant on Windows a makeover — and a voice. Copilot can now read your screen, speak aloud, and more.

Microsoft Copilot can now read your screen, think deeply, and speak aloud to you

Microsoft has broadly launched Bing Generative Search, its answer to Google’s AI Overviews and other AI-powered search apps.

Microsoft brings AI-powered overviews to Bing

Microsoft is paying publishers for content as part of a new Copilot feature, Copilot Daily, that gives a spoken summary of current events.

Microsoft starts paying publishers for content surfaced by Copilot

Evil Corp maintains a “privileged” relationship with the Kremlin, and was often tasked with launching cyberattacks on behalf of Russia. 

UK unmasks LockBit ransomware affiliate as high-ranking hacker in Russia state-backed cybercrime gang

E-commerce giant eBay, facing stiff competition from newer rivals, has removed final-value sales fees for all items excluding cars sold domestically in the U.K. This mirrors a similar move the…

eBay removes UK seller fees to counter new wave of marketplace startups

Google is announcing new Chromebook models today with Samsung and Lenovo. With Samsung’s Galaxy Chromebook Plus model in particular, the company is also introducing a new multifunctional quick insert key.…

Google adds a multi-functional quick insert key and new AI features to Chromebook Plus

Anduril sued defense tech startup Salient Motion. It still raised $12 million with participation from Anduril investor a16z.

Palmer Luckey tried to crush aeronautics startup Salient Motion. But Anduril backer a16z invested.

The company laid out a plan it hopes will go a long way toward reversing fortunes and repairing relationships.

Sonos outlines turnaround plan following app disaster

A team of founders who sold their last company to Amazon to build a new unit within AWS is setting out to reinvent the tricky business of backing up organizations’…

Eon emerges from stealth with $127M to bring a fresh approach to backing up cloud infrastructure

Air Doctor’s platform helps travelers find doctors in other countries, and it has now raised $20 million in a Series B round after seeing strong traction. 

Air Doctor raises $20M to plug a gap in how people find doctors when they’re traveling

Featured Article

Sequoia backs Pydantic to expand beyond its open source data-validation framework

Sequoia is investing $12.5M in UK startup Pydantic to help it expand beyond its open source data-validation framework.

Sequoia backs Pydantic to expand beyond its open source data-validation framework

Invesco has raised the value of its stake in Swiggy, ascribing an implied valuation of about $13.3 billion to the Indian food delivery and quick-commerce startup.

Invesco raises its valuation of Swiggy to $13.3B

The world of WordPress, one of the most popular technologies for creating and hosting websites, is going through a very heated controversy. The core issue is the fight between WordPress…

The WordPress vs. WP Engine drama, explained

Anduril is expanding even further into the “ultimate high ground.”  The company, which is best known for AI-powered defense products that span air, land and sea, is partnering with satellite…

Anduril speeds up launch of defense payloads by buying Apex satellite buses off the shelf

With this merger, Dott and Tier didn’t want to build a conglomerate of micromobility services; the operation was all about scale.

Tier becomes Dott following the merger of the two micromobility companies

Meta’s AI-powered Ray-Bans have a discreet camera on the front, for taking photos not just when you ask them to, but also when their AI features trigger it with certain…

Meta won’t say whether it trains AI on smart glasses photos

A Y Combinator startup named PearAI launched with a tweet thread and YouTube video on Saturday and caused an immediate backlash.

Y Combinator is being criticized after it backed an AI startup that admits it basically cloned another AI startup

11x.ai, a startup that develops AI-powered sales development bots, has secured roughly $50 million in Series B funding, TechCrunch has learned. The new round was led by Andreessen Horowitz, valuing…

11x.ai, a developer of AI sales reps, has raised $50M Series B led by A16Z, sources say

Hello and welcome back to TechCrunch Space. Flagging again that the final agenda for the Space Stage at TechCrunch Disrupt is now live. I’ll be pushing this event for the…

TechCrunch Space: The dawn of the space age

VC Neil Mehta, the Greenoaks Capital co-founder tied to a growing number of building purchases across several blocks of San Francisco’s once-glittering Fillmore Street, defended himself on Monday via an…

The VC buying up prized real estate in SF says not to ‘listen to agitators’

Snapchat is quietly rolling out a new “Footsteps” feature to all iOS users this week, the company confirmed to TechCrunch on Monday. The new feature, which was previously only available…

Snapchat’s new Footsteps feature tracks your location history

SpaceX’s Falcon 9 rocket is grounded again after the vehicle’s second stage did not come down in the expected area of the ocean, following an otherwise successful mission that delivered…

After delivering astronauts to ISS, SpaceX’s Falcon 9 grounded after third anomaly in three months

We’ve compiled a list of iOS 18 apps that users can try in order to take advantage of the redesigned Control Center.

iOS 18 Control Center: 18 apps that add useful actions to your iPhone

General Motors’ self-driving subsidiary Cruise must pay a $1.5 million penalty to the National Highway Traffic Safety Administration, after its initial reports to the safety regulator about last year’s pedestrian…

Cruise gets $1.5 million penalty for keeping pedestrian crash details from safety regulator

A Waymo robotaxi got stuck making a U-turn in front of Vice President Kamala Harris’ motorcade Friday evening in San Francisco.  ABC 7 reported that a San Francisco police officer…

A Waymo robotaxi stalled in front of VP Harris’ motorcade

It’s been quite the year for game industry exec Pany Haritatos.  Last month, he quietly closed an oversubscribed $28 million from Netflix, Dell a16z, and others.

Series, a GenAI game development platform, has quietly raised $28M from Netflix, Dell, a16z, others

Featured Article

Think you need a VPN? Start here.

Not everyone actually needs to use a VPN. This simple guide will help you decide if you need a VPN for your situation.

Think you need a VPN? Start here.

Featured Article

How to make your own encrypted VPN server in 15 minutes

The best encrypted VPN is one that you have set up and secured yourself. Here’s how to get started.

How to make your own encrypted VPN server in 15 minutes

You probably don’t need a VPN. Instead, these free and open-source tools, and other services, can help protect your privacy online.

VPN providers don’t protect your privacy online. Here’s what can.

Last year, while opposing Reddit’s API changes, a large number of subreddits turned from public to private or turned NSFW (Not Safe for Work) to impact ads on the platform.…

Reddit communities will require permission while going private or switching to NSFW