LastPass confirmed a data breach originating from third-party vendor Klue, resulting in the unauthorized exposure of customer contact details and support records through compromised OAuth tokens and cloud integrations.
Key Points
- Hackers accessed LastPass customer data on June 12 by compromising a legacy credential at the competitive intelligence platform Klue.
- Stolen OAuth tokens granted attackers unauthorized access to LastPass’s connected Salesforce and Gong environments.
- Exposed information includes customer names, email addresses, phone numbers, physical addresses, and specific support case records.
- LastPass confirmed that its core infrastructure, encrypted password vaults, and user credentials remain secure and were not impacted.
- Salesforce disabled the affected Klue app connection after detecting suspicious activity within its platform.