Welcome to the Yext Trust Center – your gateway to understanding our commitment to data security, privacy, and compliance. In this page, you can access our compliance documentation, find answers to frequently asked questions about security and privacy, and learn about our security practices.
We prioritize transparency and strive to build trust with our customers. This portal is designed to provide the information and assurance you need to feel confident in our ability to protect your data and safeguard underlying assets.
- How frequently must mobile devices connecting to Yext's network be patched or updated?
- What are Yext's global office locations?
- Can your platform connect to third-party internal or external systems (e.g., CRM, helpdesk, BI tools)?
- Are your organization's incident response plans actively updated based on current cyber threat intelligence, actual incidents, or information-sharing?
- Does your organization use only non-deprecated encryption methods to encrypt client data at rest using Bank of America approved encryption methods?
Trust Center Updates
Klue Security Incident
In June, Yext was one of many companies affected by a security incident at Klue, a sales enablement and market intelligence platform. An attacker compromised Klue’s systems, exfiltrated the integration credentials Klue held for its customers, and used the credentials tied to Yext to read data from our internal Salesforce CRM.
We notified affected customers directly in June. This post shares a fuller public account: what happened, what was and was not affected, and what we have changed as a result. Conversations like this one are not easy, but you deserve clarity from us, and transparency is how we maintain your trust.
Summary of the events
-
A threat actor, purported to be the hacking group known as “Icarus”, compromised Klue and stole the credentials Klue used to connect to its customers’ systems, including Yext’s internal Salesforce CRM.
-
Using that stolen credential, the attacker ran read-only queries against our internal CRM during a single window of roughly 17 hours on June 11 and 12, 2026.
-
No data was created, changed, or deleted.
-
The Yext platform and products were not affected. No customer content, customer-facing systems, or end-user data was accessed.
-
We severed the Klue connection, notified affected customers and further strengthened our review and monitoring of third-party integrations.
What happened
Klue is a tool our go-to-market teams use for competitive and market intelligence. In order to provide these services, Klue connected to our Salesforce CRM via an integration credential to sync a limited set of records.
In mid-June, an attacker compromised Klue’s infrastructure and stole the credentials Klue held for its customer integrations. The attacker then used those credentials to query customer CRM environments directly. This affected many Klue customers and has been reported publicly across the industry. Link to Klue’s public security update
Our own logs tell us exactly what happened in our environment. The attacker used the stolen credentials to run read-only queries against our internal Salesforce CRM for roughly 17 hours spanning June 11 and 12. Salesforce spotted the suspicious activity and revoked the compromised application’s access, and Klue completed credential revocation on June 12. The unauthorized activity had already stopped early that day, and our logs confirm nothing occurred afterward. Because this incident was limited to our internal Salesforce CRM, the exposed data included business contact details for customers and prospects, such as names, work email addresses, phone numbers, and job titles.
Klue first notified us on June 13. On June 15, Klue provided the detailed indicators (the malicious IP addresses and integration activity logs) we needed to investigate our own environment. Our security team began a log-based investigation that day and confirmed on June 16 that data in our internal CRM had been accessed.
What was not affected
We know this is the section that matters most, so we want to be precise.
The activity was read-only: no records were created, changed, or deleted. The Yext platform, our products, and our infrastructure were not accessed. No customer content, customer-facing systems, or end-user data was accessed. The affected system is not used to store payment card data. And because our CRM is managed separately from other Yext systems, the stolen credential did not open a path into any other environment.
We also reviewed every other system Klue connected to within the Yext environment, including Google Workspace and Slack. We found no evidence of attacker activity in any of them. Salesforce was the only system affected.
How we investigated
We based every conclusion on our own evidence rather than relying on the vendor’s account alone. Our team pulled Salesforce’s access logs for the exposure window, correlated them against the indicators Klue provided, and then confirmed the findings against a second, independent Salesforce data source. Both sources told the same story: a bounded, read-only window of activity that ended on June 12.
Where the logs could not rule something out, we treated it as in scope.
What we have changed
The credential theft occurred outside our walls, but two opportunities are available to us: limiting what any single integration can access, and detecting misuse quickly. We have acted on both.
-
We fully severed the connection between Klue and our systems.
-
All 3rd party applications that connect to our critical systems must now pass a more extensive security review before connecting to a production system, and we are adding recurring integration reviews to our access review program.
-
We continue to expand our monitoring and detection capabilities of the CRM environment within our security tooling.
What you should watch for
Stolen business contact information is often used for phishing. In the coming months, treat unexpected emails that reference your relationship with Yext with extra care, especially messages about renewals, invoices, or account changes. Yext will never ask you for passwords or payment details over email. If something seems suspicious, verify it with your known Yext account contacts before acting.
Our commitment
Klue and the organizations affected by this incident, including Yext, were the targets of a crime. Supply chain attacks are an industry-wide reality, and any company can be affected by an upstream compromise. What we control is how we prepare, how we respond, and how plainly we communicate. This post is part of that commitment, and we will update it if our understanding changes.
If you have questions, please reach out to your Yext account team or contact us at security@yext.com.
npm Supply Chain Attack "Shai-Hulud"
A new npm supply chain attack, referred to as “Shai Hulud”, has been reported in the security community. This incident involves the publication of malicious versions of specific npm packages to the ecosystem.
At this time, Yext has not identified any impact on our systems or services. We are continuing to monitor the situation closely and will take immediate action if new information becomes available.
What you should know about this incident:
The attack involves a self-replicating worm that spreads through npm packages.
Its goal is to compromise downstream applications through malicious package versions.
The issue is industry-wide and not specific to Yext.
If you have questions, please get in touch with us at security@yext.com.
Important Security Notice: Protect Yourself from Impersonation & Phone Scams
There's an important security issue we want to bring to your attention. We've recently noticed a surge in impersonation, email phishing, and phone spoofing attacks that involve our company name and contact numbers.
In these attacks, bad actors:
-
Send emails or messages pretending to be from Yext HR, Finance, or other teams
-
Call from phone numbers that appear to be Yext numbers (caller ID spoofing)
-
Ask recipients to share sensitive information or send payments
These communications are fraudulent and are not coming from Yext.
If you get a fraudulent communication, please forward it to security@yext.com. If you have already interacted with one, contact your internal IT team and ask them to escalate the incident to us.




