Cambridge Mercantile Corp.
Jun 2026 · Graded Verified · Financial Services · Government record
Cambridge Mercantile Corp.Jun 2026
breach at U.S.A.
Not yet quantified
VVerifiedCorpay's own network stayed untouched; the exposure ran through Klue, the market intelligence platform wired into its CRM, where an unauthorized party sat inside the integration infrastructure for two days in June 2026. Names, email addresses, and physical addresses were pulled out of the vendor's side of that connection. Corpay never lost control of its network. It lost control of the security boundary the moment a third-party integration became a second entrance into its customer data.
Financial Services
California AG breach notification
Initial attack type third-party or supply chain confirmed · Impact data theft confirmed
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.