AUTO-UPDATED

LastPass notifies users of yet another data breach

LastPass has notified customers that a data breach at its third-party partner Klue exposed business contact information and support case data, though user password vaults remain secure.

Key Points

  • The breach involved unauthorized access to customer names, phone numbers, email addresses, and physical addresses stored within the Klue platform.
  • LastPass responded by revoking employee access to Klue, rotating exposed API tokens, and launching a formal investigation with Salesforce.
  • Compromised data originated from integrations between Klue, Salesforce, and Gong systems.
  • LastPass warned users to remain vigilant against potential phishing attempts and social engineering attacks using the stolen contact details.
  • The company released specific IP addresses and malicious email domains to help organizations identify and block related security threats.

Why it Matters

This incident highlights the ongoing security risks associated with third-party vendor integrations and the potential for supply chain vulnerabilities to expose sensitive customer data. Users should exercise increased caution regarding unsolicited communications, as the leaked contact information could be leveraged for targeted phishing campaigns.
9to5Mac Published by Marcus Mendes
Read original