← LastPass

2026 LastPass — Klue OAuth supply-chain breach; Salesforce CRM customer data accessed

2026 Unknown records affected Share on X

Data compromised

Customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM-related data per LastPass—no evidence Gong call/email data accessed; password vaults, products, and infrastructure unaffected

Technical writeup

Downstream Klue supply-chain victim — June 2026. LastPass disclosed June 23, 2026 that on June 12 it learned of the Klue (klue.com) security incident affecting the market-intelligence integration connected to LastPass Salesforce and Gong systems. Investigation found an unauthorized actor obtained OAuth tokens Klue held for customers and used them to access LastPass customer data within Salesforce—names, phones, emails, addresses, support cases, and CRM/sales data. LastPass found no evidence of Gong-related data access, stated password vaults and core infrastructure were not affected, disabled employee Klue access, rotated exposed API/OAuth tokens, and notified law enforcement. Icarus extortion actors previously emailed victims using spoofed domains (baccarat.com.au, robinskitchen.com.au, house.com.au). Part of klue-oauth-supply-chain2026. BreachHistory indexes recordsAffected 0 pending CRM row counts.

Root cause

Icarus actor compromised Klue June 11; stolen OAuth tokens used to access LastPass Salesforce environment (Klue market-intelligence integration)

References