Skip to content
Tech News
← Back to articles

LastPass confirms data breach in Klue supply chain attack

read original more articles
Why This Matters

The LastPass data breach highlights the growing risks associated with supply chain attacks and third-party integrations, emphasizing the need for robust security measures across interconnected platforms. For consumers and the industry, it underscores the importance of vigilance and proactive security practices to protect sensitive personal and corporate data.

Key Takeaways

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month.

The password management platform says its products, services, and infrastructure were not affected by the incident and that customer vaults remained secure.

“On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams, which integrates with our Salesforce and Gong systems,” LastPass says.

"We immediately launched an investigation and learned that, as part of this incident, an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.”

“The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.”

The investigation into the incident did not reveal any evidence that the attacker accessed Gong-related data, which typically includes customer calls and emails.

According to LastPass, the following data may have been exposed:

Customer names

Phone numbers

Email addresses

... continue reading