We were recently notified that Klue, a third-party vendor, experienced a security incident in which attackers obtained the credentials Klue used to connect to certain Greenhouse business systems. Based on our investigation to date, the unauthorized access occurred on June 11, 2026, was scoped to Klue's integration, and did not involve Greenhouse's own infrastructure.
No Greenhouse product, hiring, or candidate data was affected. The data accessible was limited to business contact information held in our sales and customer relationship systems, specifically names and contact details, and our investigation has not identified any modification or deletion of data.
We acted quickly to secure unauthorized access, notified the relevant data protection authorities, and are working directly with Klue as its investigation continues.