
LastPass discloses another data breach via Klue supply chain attack, customer data exposed
Another day, another data breach for the widely-known password manager… LastPass has disclosed yet another data breach stemming from a security incident at Klue, a third-party market intelligence provider integrated with LastPass’s Salesforce and Gong platforms. The incident, which occurred in early June, impacted multiple companies, including LastPass.
During their investigation, LastPass found that an unauthorized party obtained OAuth authorization tokens managed by Klue for several clients. Using these tokens, the threat actor was able to access customer data that LastPass maintained within its Salesforce environment.
At this stage, the data accessed was limited to business contact information and basic customer relationship management records, such as customer names, phone numbers, email addresses, physical addresses, as well as support and sales case information. LastPass has stated that there is no indication that customer vaults, the company’s main products, or infrastructure were affected. Additionally, no Gong-related data was accessed during the breach.
Once notified, LastPass completed its remediation steps, including rotating all exposed Klue OAuth tokens and restricting further access. Following these actions, LastPass advises customers to remain vigilant for potential phishing or social engineering efforts that may use the leaked contact details.


Comments
It was hacked a few years ago, and now it's been hacked again.
2011 security incident 2015 security breach 2017 security vulnerabilities in the Android app 2021 third-party trackers and security incident 2022 customer data and partially-encrypted vault theft 2024 leakage via injection attacks 2025 DOM-based extension clickjacking 2026 ETH Zurich security analysis 2026 Klue supply chain data breach https://en.wikipedia.org/wiki/LastPass#Security_incidents