June 23, 2026: LastPass confirmed it was breached through the mid-June Klue OAuth supply-chain attack—the same Icarus campaign that hit Huntress, Tanium, Jamf, and other SaaS vendors. Hackers accessed customer CRM data in LastPass's Salesforce environment; the company says password vaults were not compromised.
What LastPass confirmed
On June 12, LastPass learned of an incident at Klue (klue.com), a third-party market-intelligence platform integrated with LastPass Salesforce and Gong systems. Per BleepingComputer and LastPass's blog, an unauthorized actor obtained OAuth tokens Klue held and used them to query LastPass customer data in Salesforce.
Potentially exposed categories:
- Customer names, phone numbers, email addresses, physical addresses
- Support case information
- Sales/CRM-related data
LastPass found no evidence that Gong call or email data was accessed. Products, services, infrastructure, and encrypted vaults remained secure per the company's statement.
Why this matters for a password manager
LastPass's 2022 vault breach still shadows the brand. This June 2026 incident is different—a downstream CRM exposure via a sales-intelligence vendor—not a vault crypto failure. Still, exposed names, emails, and support-case context fuel highly targeted phishing pretending to be LastPass support.
Icarus previously emailed victims with spoofed sender domains including baccarat.com.au, robinskitchen.com.au, and house.com.au. LastPass warned users to trust only official support channels and never share master passwords.
The wider Klue campaign
The parent incident is indexed at Klue OAuth supply chain 2026. Downstream rows include Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, and Bynder—all via stolen Klue integration tokens.
What LastPass users should do
- Do not share your master password with anyone contacting you by phone or email.
- Enable MFA on LastPass if not already active.
- Be skeptical of support emails citing real case numbers from the CRM leak.
- Rotate passwords on other sites if you reused your LastPass master password elsewhere (you should not).
Canonical record: LastPass Klue 2026 on BreachHistory.
Sources: BleepingComputer, LastPass blog