LastPass Customer Data Stolen in Third-Party Klue Breach

Hackers used stolen access tokens from market intelligence platform Klue to enter LastPass’s Salesforce environment and obtain customer information.

LastPass has confirmed that hackers accessed customer information stored in its Salesforce environment following a security breach at third-party tech provider Klue.

The password manager says the attackers obtained OAuth tokens that Klue used to connect with services belonging to its customers. Those tokens were then used to access data held within LastPass’ Salesforce account.

The exposed information may include customer names, email addresses, phone numbers, physical addresses, support case data and sales-related records. LastPass has not disclosed how many customers were affected or provided further details about what individual support cases may have contained.

LastPass Password Vaults Were Not Accessed

LastPass stressed that its password management products, services and internal infrastructure were not compromised during the incident. Customer vaults remain secure, and the company says it found no evidence that attackers accessed information through its Gong integration.

This makes the latest incident considerably different from the company’s major 2022 breach, during which attackers obtained customer account information and backups of encrypted password vaults.

The new exposure instead originated from Klue, a market intelligence platform used by LastPass’s sales and marketing teams. Klue integrated with the company’s Salesforce and Gong systems.

Klue identified unauthorised activity within part of its integration infrastructure on June 12. Its investigation found that an attacker gained entry using a compromised legacy credential associated with an integration service.

The attacker subsequently obtained OAuth tokens used to connect Klue with third-party platforms, including Salesforce, and accessed data belonging to several connected customers.

Klue says there is currently no evidence that content stored directly within its own platform was compromised.

LastPass Customers Should Watch for Phishing Attempts

Although passwords and vault data were not exposed, the stolen customer information could still be used for convincing phishing or social engineering attacks.

Access to names, contact information and previous support case details may allow attackers to impersonate LastPass representatives or reference genuine account issues when contacting victims.

LastPass is advising customers to be cautious of unexpected emails, phone calls and requests for sensitive information. The company also reiterated that its employees will never ask customers to reveal their master passwords.

Users should avoid clicking links in unsolicited messages claiming to be from LastPass and instead access their accounts or contact support through the official app or website.

LastPass says it has discontinued employee access to Klue, rotated the exposed access tokens and launched an investigation with Klue and Salesforce. It has also notified law enforcement and says it is implementing additional safeguards intended to prevent similar third-party incidents.

FAQ

Were LastPass Password Vaults Stolen in the Klue Breach?

No. LastPass says its products, services and infrastructure were not compromised, and customer password vaults remain secure.

What LastPass Customer Information Was Exposed?

The accessed data may include names, email addresses, phone numbers, physical addresses, customer support case information and sales-related records.

Should LastPass Users Change Their Master Passwords?

LastPass has not instructed customers to reset their master passwords because vault data was not accessed. Users should nevertheless remain alert for phishing messages and never disclose their master password to anyone.

NEWSLETTERS

Subscribe to our Newsletters

Two newsletters. Zero noise. Pick what lands in your inbox.

Unsubscribe anytime. We don’t share your email.

Discover more from Tbreak Media UAE

Subscribe now to keep reading and get access to the full archive.

Continue reading