2026 LastPass — Klue OAuth supply-chain breach; Salesforce CRM customer data accessed
Data compromised
Customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM-related data per LastPass—no evidence Gong call/email data accessed; password vaults, products, and infrastructure unaffected
Technical writeup
Downstream Klue supply-chain victim — June 2026. LastPass disclosed June 23, 2026 that on June 12 it learned of the Klue (klue.com) security incident affecting the market-intelligence integration connected to LastPass Salesforce and Gong systems. Investigation found an unauthorized actor obtained OAuth tokens Klue held for customers and used them to access LastPass customer data within Salesforce—names, phones, emails, addresses, support cases, and CRM/sales data. LastPass found no evidence of Gong-related data access, stated password vaults and core infrastructure were not affected, disabled employee Klue access, rotated exposed API/OAuth tokens, and notified law enforcement. Icarus extortion actors previously emailed victims using spoofed domains (baccarat.com.au, robinskitchen.com.au, house.com.au). Part of klue-oauth-supply-chain2026. BreachHistory indexes recordsAffected 0 pending CRM row counts.
Root cause
Icarus actor compromised Klue June 11; stolen OAuth tokens used to access LastPass Salesforce environment (Klue market-intelligence integration)
References
- https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/
- https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response
- https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- https://klue.com/blog/an-update-on-recent-klue-security-incident