AndroGuider | One Stop For The Techy You! LastPass Faces Another Breach: Customer Support Data Comp…
انتشار: 2026/06/23 18:35 UTC
AndroGuider | One Stop For The Techy You! LastPass Faces Another Breach: Customer Support Data Compromised Again ai4chat-files.s3.amazonaws.com/images/ima… TL;DR * LastPass has confirmed that hackers accessed customer names, email…upon learning of the incident:* Discontinued all employee access to Klue and removed Klue integrations from its Salesforce environment.* Rotated the compromised OAuth tokens and reviewed other integrations for unusual activity.* Engaged third‑party forensic investigators and law enforcement to support the investigation.* Coordinated with the broader security community through its Threat Intelligence, Mitigation, and Escalation (TIME) team to share tactics, techniques, and procedures used by the attackers.The company also said it is implementing additional safeguards and strengthening its protocols around third‑party integrations, credential management, and monitoring. Salesforce and LastPass have removed the Klue integration from affected environments, and Klue has committed to bolstering its own security controls in the wake of the breach. Implications for usersFor LastPass users, the primary risk is not that their passwords have been decrypted, but that their contact and support information can be used in targeted phishing and social engineering campaigns. Armed with names, email addresses, phone numbers, and details from support cases, attackers can craft highly convincing messages that appear to come from LastPass or related services.LastPass has advised users to:* Be cautious of unsolicited emails, calls, or messages referencing recent support cases or account issues.* Avoid clicking links or opening attachments in unexpected communications.* Never share their master password or two‑factor authentication codes with anyone.The company also encourages users to keep their contact details up to date and to monitor their accounts for any unusual activity. While the incident does not require users to change their master passwords, it underscores the importance of maintaining strong, unique passwords and enabling multi‑factor authentication wherever possible. Context within LastPass’s recent security historyThis latest incident comes as the second major security event tied to LastPass in recent years. In 2022, a separate breach involving a compromised senior DevOps engineer’s personal computer led to the unauthorized access and exfiltration of backup databases and copies of customer password vaults. That incident ultimately prompted regulatory action, including a £1.2 million fine by the UK Information Commissioner’s Office (ICO) and a reported $24.5 million settlement in related litigation.Analysts warn that the Klue‑linked breach, while less severe in terms of direct impact on vaults, reinforces concerns about LastPass’s reliance on complex third‑party integrations and its broader security culture. The fact that attackers were able to pivot from a market‑intelligence platform into a password manager’s Salesforce environment highlights how seemingly peripheral tools can become high‑value targets in a supply chain attack. What this means for the broader security industryThe Klue‑Salesforce‑LastPass chain is part of a broader pattern in which attackers exploit trusted integrations and OAuth‑based access to move laterally across organizations. Similar incidents have affected other security and technology firms that used Klue’s Salesforce integration, demonstrating how a single compromised credential or misconfigured integration can cascade into widespread data theft.Security teams are now reevaluating their use of third‑party integrations, tightening OAuth token policies, and enhancing monitoring for anomalous queries from external applications. The incident also underscores the need for robust supply chain risk management, including regular audits of vendor security practices and clear incident‑response playbooks for integration‑related breaches. Looking aheadLastPass has stated that remediation of the Klue‑related incident is complete and that there is no evidence of further unauthorized access. The company continues to notify affected customers and remains in contact with law enforcement and secu[...]