LastPass has notified customers that a data breach at its third-party partner Klue exposed business contact information and support case data, though user password vaults remain secure.
Key Points
- The breach involved unauthorized access to customer names, phone numbers, email addresses, and physical addresses stored within the Klue platform.
- LastPass responded by revoking employee access to Klue, rotating exposed API tokens, and launching a formal investigation with Salesforce.
- Compromised data originated from integrations between Klue, Salesforce, and Gong systems.
- LastPass warned users to remain vigilant against potential phishing attempts and social engineering attacks using the stolen contact details.
- The company released specific IP addresses and malicious email domains to help organizations identify and block related security threats.