LastPass announced that cybercriminals gained access to customer data hosted in the Salesforce following an attack on the supply chain of its market intelligence platform Klue. While the password management company assures that its products, services and users’ password vaults remain secure, the incident brings to the fore the risks posed by interconnected services and external partners in the modern digital ecosystem.
LastPass was notified of the incident on June 12, when it became known that Klue, a service used by the company's sales and development teams, had been compromised by unauthorized actors.
How the attack started
The breach did not initially target LastPass. The attackers reportedly gained access to Klue using legacy credentials associated with an integration service. Through this access, they were able to steal OAuth tokens, which are special credentials that allow applications and services to communicate with each other without requiring constant password entry.
See also: Tata Electronics claims to expose Apple and Tesla
These tokens were used by many Klue customers to connect their Salesforce accounts. By obtaining them, the attackers gained access to some customer data LastPass located in the company's CRM environment.

What data may have been exposed
LastPass' investigation is still ongoing, but the company admits that various customer details may have been exposed, including names, phone numbers, email addresses, physical addresses, information related to support requests, and data related to sales and customer relationship management ( CRM ) activities .
The company emphasizes that there is no indication that the perpetrators gained access to data on the Gong platform , which typically includes recorded calls, emails and other communications with customers.
Most importantly, according to LastPass, users' master passwords and encrypted vaults remained outside the breach.
See also: Nearly 7,000 fake Amazon registered ahead of Prime Day 2026
Why CRM data is of great value to cybercriminals
Although no passwords or financial information were leaked, CRM data is considered particularly valuable in the world of cybercrime.
This information can be used for targeted phishing and social engineering. An attacker who knows a user's name, location, email address, or even past interactions with a company can create highly convincing scam messages.
In many cases, this type of data is used to send fake security alerts, deceptive account verification requests, or even phone scams that appear as official company communications.

The Icarus group behind the attack
The Icarus ransomware group claimed responsibility for the Klue attack , which allegedly stole data from multiple organizations and launched a blackmail campaign .
The incident didn't just affect LastPass. Organizations affected include Recorded Future, Tanium, Jamf, Sprout Social, Gong , and Insurity, demonstrating how far-reaching a supply chain attack can be.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
These attacks have become one of the biggest cybersecurity challenges, as cybercriminals no longer only attack their end targets, but also look for weak links between cooperating services and software vendors.
The measures taken by LastPass
After discovering the incident, LastPass announced that it disabled employee access to the Klue platform, replaced the exposed API and OAuth credentials , and notified relevant law enforcement authorities.
See also: Samsung KNOX: Eight-year-old vulnerability puts Galaxy devices at risk
At the same time, the company warned its customers about possible phishing attempts and pointed out that users should be extra cautious when dealing with any unsolicited communication via phone or email.
LastPass also reported that perpetrators are using specific domains to send misleading messages and advised customers to trust only the company's official support channels.

Another lesson for the era of interconnected services
The incident highlights a critical reality of the digital age: Even when a company implements strong protection mechanisms, its security depends largely on the level of protection of its partners and external services.
Supply chain attacks are emerging as one of the most significant risks to businesses, as a single breach can create ripple effects across dozens or even hundreds of organizations. For users, the best defense remains to be vigilant against suspicious communications and avoid sharing sensitive information, even when a message appears to come from a trusted source.
Source: www.bleepingcomputer.com
