AUTO-UPDATED

Another LastPass security breach traces back to a compromised vendor

LastPass confirmed a data breach originating from third-party vendor Klue, resulting in the unauthorized exposure of customer contact details and support records through compromised OAuth tokens and cloud integrations.

Key Points

  • Hackers accessed LastPass customer data on June 12 by compromising a legacy credential at the competitive intelligence platform Klue.
  • Stolen OAuth tokens granted attackers unauthorized access to LastPass’s connected Salesforce and Gong environments.
  • Exposed information includes customer names, email addresses, phone numbers, physical addresses, and specific support case records.
  • LastPass confirmed that its core infrastructure, encrypted password vaults, and user credentials remain secure and were not impacted.
  • Salesforce disabled the affected Klue app connection after detecting suspicious activity within its platform.

Why it Matters

This incident highlights the growing security risks associated with third-party vendor integrations and the potential for supply chain attacks to expose sensitive customer data. While core password vaults remain secure, the exposure of contact information increases the risk of targeted phishing and social engineering campaigns against affected users.
Android Authority Published by Jay Bonggolto
Read original