AndroGuider | One Stop For The Techy You!LastPass Faces Another Breach: Customer Support Data Compr…
انتشار: 2026/06/23 18:35 UTC
AndroGuider | One Stop For The Techy You!LastPass Faces Another Breach: Customer Support Data Compromised Againai4chat-files.s3.amazonaws.com/images/ima… TL;DR* LastPass has confirmed that hackers accessed customer names, email addresses, phone numbers, physical addresses, and sensitive customer support case data via a supply chain breach at market-intelligence platform Klue.* The attackers exploited stolen OAuth tokens linked to LastPass’s Salesforce environment, but the company insists its password vaults and core infrastructure remain secure and unaffected.* This incident marks the second major security event linked to LastPass in recent years, raising fresh questions about the password manager’s security posture and its reliance on third‑party integrations. LastPass Faces Another Breach: Customer Support Data Compromised AgainLastPass has disclosed a new data incident in which hackers obtained personal information and customer support case data through a breach at Klue, a third‑party market intelligence and competitive‑analysis platform used by LastPass’s go‑to‑market teams. The incident, first reported by Klue on June 12, involved attackers compromising Klue’s infrastructure and stealing OAuth tokens that granted access to various customer systems, including LastPass’s Salesforce environment.LastPass said it learned of the incident on the same day and immediately launched an investigation. The company emphasized that the breach originated with Klue and affected only systems integrated with Klue’s application, such as Salesforce and Gong, and that LastPass’s own products, services, and infrastructure were not directly compromised. What data was exposed?According to LastPass’s incident post and corroborating reports, the information accessed by the attackers was limited to standard business contact and CRM data, including:* Customer names* Phone numbers* Email addresses* Physical addresses* Customer support case data* Sales‑related records and account informationThe exact contents of the customer support tickets are not fully disclosed, but such records can contain fragments of sensitive or private information, such as support issues, technical details, and internal communications. LastPass has not revealed the number of affected customers, but it is notifying those whose information was accessed and urging them to remain vigilant for follow‑on attacks.Notably, LastPass stressed that customer vaults remain secure. The attackers did not gain access to encrypted password vaults, and there is no evidence they reached LastPass’s core password‑management infrastructure or the encrypted data stored within user vaults. How the breach happenedThe attack unfolded via a supply chain compromise at Klue. Security researchers and affected companies describe the incident as a “security domino effect,” beginning with attackers gaining access to Klue’s systems and then using stolen OAuth tokens to pivot into customer environments.In LastPass’s case, the threat actor leveraged OAuth tokens Klue held for LastPass to access its Salesforce environment. Salesforce is widely used for customer relationship management, storing contact details, account information, and support case histories. Because Klue integrated with LastPass’s Salesforce instance, the attackers could query and exfiltrate records from multiple organizations simultaneously.A hacking and extortion group calling itself Icarus has claimed responsibility for the attack, threatening to leak stolen data unless companies pay a ransom. LastPass has not indicated whether it has engaged with the group or paid any ransom, but it has confirmed that it has revoked the exposed OAuth tokens and taken steps to limit further access. Company response and remediation stepsLastPass outlined several immediate actions it took [...]