→ Back to Home
DevSecOps

LastPass Customer Data Exposed in Klue SaaS Supply Chain Attack

LastPass, a prominent password management service, recently disclosed that certain customer data was compromised following a sophisticated supply chain attack on Klue, a market intelligence platform used by LastPass's go-to-market teams. The incident, which came to light on June 12th, 2026, involved an extortion group known as "Icarus" exploiting vulnerabilities within Klue's SaaS infrastructure. According to reports, the attackers managed to compromise Klue's systems and subsequently leveraged pre-authorized Salesforce OAuth tokens. These tokens were then used to gain unauthorized access to and exfiltrate data from various Salesforce customer environments that integrated with Klue, including LastPass. Salesforce's native security controls reportedly failed to flag the intrusion because the OAuth sessions appeared legitimate, underscoring the challenge of detecting such nuanced supply chain compromises. The exposed information from LastPass's Salesforce environment included standard business contact details and CRM records. This encompassed customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related records. LastPass has warned that this exposed contact information could potentially be used in phishing or social engineering attacks, urging customers to remain vigilant against unsolicited communications. In response to the breach, LastPass promptly revoked employee access to Klue, rotated the compromised API tokens, and initiated a comprehensive investigation in collaboration with Klue and Salesforce. The company also notified law enforcement and released indicators of compromise to aid in broader defense efforts. While the incident is significant, LastPass clarified that its core products, services, infrastructure, and customer vaults were not directly affected by this particular attack. This event serves as a stark reminder of the escalating risks in software supply chain security, where a compromise in one vendor's system can have cascading effects across multiple organizations. It emphasizes the necessity for businesses to rigorously vet third-party integrations, implement stringent access controls, and continuously monitor for unusual activity, even from seemingly legitimate sources. The incident also highlights the growing trend of sophisticated threat actors targeting weaker links in the interconnected digital ecosystem.
#supply chain security#saas security#data breach#vulnerability management#third-party risk
Read original source