LastPass confirms data breach in Klue supply chain attack

LastPass has confirmed a data breach connected to the Klue supply-chain attack, after attackers stole OAuth tokens and accessed LastPass customer data in its Salesforce environment. The company says vaults, products, and core services remained secure, but data such as customer names, phone numbers, email and physical addresses, support cases, and CRM records may have been exposed; Gong data was not accessed. The Icarus extortion group claimed the attack, which also impacted multiple other organizations. LastPass has disabled employee access to Klue, rotated the exposed tokens, and notified law enforcement. Users should beware phishing attempts and never share their master password.

TechLogHub
June 23, 2026
4 min read
0 views

Share Article

LastPass confirms data breach in Klue supply chain attack

LastPass Confirms Data Breach Linked to Klue Supply Chain Incident

Executive OverviewLastPass disclosed a data exposure tied to the Klue supply chain incident, where attackers stole OAuth tokens used to link Klue with Salesforce and Gong systems. The compromise appeared to affect customer data within LastPass’s Salesforce environment, while LastPass emphasizes that its own products, services, and vaults remained secure. The breach underscores the risk inherent in third-party integrations and the importance of monitoring access tokens used across connected platforms.

How the Incident Unfolded

  • Klue, a third-party market intelligence platform used by LastPass for go-to-market workflows, suffered a breach that exposed OAuth tokens tied to numerous customers.
  • An unauthorized actor obtained these OAuth tokens and leveraged them to access LastPass customer data inside the Salesforce environment linked to Klue.
  • Gong-related data, another integration point, did not show signs of compromise according to the investigation.
  • The attacker’s maneuvering appears to have been token-based rather than direct intrusion into LastPass’s core systems.

Data Potentially ExposedThe exposed data may include a range of personal and business information associated with customers and their records:

  • Customer names
  • Phone numbers
  • Email addresses
  • Physical addresses
  • Support case information
  • Sales and CRM-related dataThis combination of data could be used in phishing and social-engineering attempts, underscoring the need for vigilance when receiving unsolicited communications.

Scope and Affected EcosystemThe Klue supply chain incident affected multiple organizations beyond LastPass, illustrating how a breach in a third-party service can ripple across a broader ecosystem. Reported victims or participants in the wider attack include:

  • Recorded Future
  • Tanium
  • Jamf
  • Sprout Social
  • Gong
  • InsurityThe breadth of impact highlights the interconnectivity of modern enterprise environments and the challenges of isolating breaches that originate in vendor platforms.

Investigation Timeline and Immediate Mitigations

  • June 12: LastPass was alerted to the Klue incident and initiated an internal investigation to determine the scope and impact.
  • Credential exposure: The investigation identified that OAuth tokens held by Klue were accessed by an unauthorized actor, enabling access to LastPass customer data within Salesforce.
  • Containment actions: LastPass disabled employee access to Klue and rotated the exposed API/OAuth tokens to mitigate further risk.
  • Law enforcement: Authorities were notified as investigators continued to assess the breach.
  • Data access boundaries: The investigation did not indicate that Gong-specific data or other unrelated data repositories were accessed in this event.

Security and Communications Measures

  • Token hygiene and access controls: In response to the breach, LastPass took steps to rotate tokens and limit the blast radius of the compromised credentials.
  • Vendor communication and monitoring: The company issued warnings about the sender domains used by attackers to help customers recognize potentially fraudulent communications and emphasized using official support channels.
  • Customer data protection posture: While the incident involved external credentials, LastPass stressed that customer vaults and core platform security remained intact.

Operational and Industry Context

  • The Klue breach and its linkage to the Icarus extortion group illustrate a broader trend where threat actors leverage compromised credentials from one service to access data across connected platforms.
  • The event demonstrates how OAuth-based trust between services can become a single point of exposure if tokens are stolen and misused.
  • The incident adds to the growing narrative around supply chain risk, especially in environments where sales, marketing, and CRM tools are tightly integrated with security-critical services.

Key Takeaways and Reflections

  • Third-party integrations can become conduits for adversaries seeking access to sensitive customer data, even when core services remain secure.
  • OAuth tokens, while facilitating seamless connectivity, represent a potential vulnerability if not protected and rotated promptly after a suspected breach.
  • Proactive monitoring of cross-service activity and rapid containment of compromised tokens are essential to limit exposure when a supply chain event occurs.
  • Transparent communication about the scope of data exposure and the specific systems involved helps customers gauge risk and respond appropriately.

Contextual Notes

  • The attack originated from the Klue environment and was attributed to the Icarus extortion group, which has previously engaged in targeted data theft and ransom campaigns.
  • The exposure specifically involved LastPass customer data within Salesforce, whereas other data streams tied to Gong were not evidenced as affected in the initial assessment.
  • The broader set of organizations implicated by the Klue breach underscores the cascading risk inherent in interconnected enterprise architectures and vendor ecosystems.

Closing ObservationsThis incident reinforces the critical importance of robust vendor risk management, vigilant monitoring of token-based access across interconnected platforms, and clear incident response playbooks that address multi-vendor collaboration. As organizations increasingly rely on integrated tools and platforms to power sales, marketing, and customer support, the security community continues to advocate for layered protections, rapid credential rotation, and rigorous verification of communications originating from supported channels. The LastPass case serves as a reference point for ongoing discussions about supply chain resilience and the need for continuous assessment of trusted connections within modern enterprise environments.

Stay Updated

Get the next deep dive in your inbox

Subscribe for product analysis, engineering explainers, and practical guides published on TechLogHub.

See what launched this week

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.