LastPass Confirms Customer Support Data Stolen in Klue Supply Chain Breach

LastPass confirms customer support data exposure after the Klue supply chain cyberattack, highlighting the growing risks of third-party cybersecurity breaches

LastPass Confirms Customer Support Data Stolen in Klue Supply Chain Breach

LastPass has announced that some of its customer data was exposed to unauthorized access following a cyberattack on one of its third-party service providers, Klue. However, LastPass emphasized that its core infrastructure, password vaults, and user login credentials were not affected by the incident.

This event demonstrates once again that even when a company adheres to the highest security standards, vulnerabilities within partner companies and third-party services can threaten the security of customer data.

What Happened?

According to details released by LastPass, the company was notified on June 12, 2026, of a cyberattack on Klue.Investigations revealed that after breaching Klue's infrastructure, the attackers managed to steal stored OAuth tokens. These tokens allowed them to access a portion of LastPass data stored on the Salesforce platform.

LastPass stated that the attack did not directly target the company's own infrastructure but was carried out via one of the services it uses.

What Data Was Exposed?

LastPass said the following information may have been exposed in the incident:

Customer names
Email addresses
Phone numbers
Mailing addresses
Support case history
CRM and sales-related information


In contrast, the company emphasized that the following was safe:


User password vault
Master Password
Saved passwords
Bank card information
Encrypted user data

Why Support Case Data Matters

At first glance, leaking support files may seem less important than stealing passwords, but cybersecurity experts have a different view.

Support files typically contain information such as:

User account details
Account recovery requests
Correspondence history
Contact information
User technical issues


.Attackers can use this information to design highly convincing phishing or social engineering attacks and trick users.

A Supply Chain Attack, Not a Direct Hack

This incident is an example of a Supply Chain Attack.

In this type of attack, hackers target one of its business partners or service providers rather than directly infiltrating the main company.

Since many companies use cloud services, CRM, and SaaS software, infiltrating one service provider can be a way to access information from multiple companies.

In this case, the attackers also managed to access information belonging to multiple companies by abusing Klue’s access.

LastPass Responds

After becoming aware of the incident, LastPass took the following actions:

Revoked and replaced OAuth tokens
Discontinued employee access to Klue
Initiated an internal investigation
Notified affected customers
Warned of potential phishing attacks



The company reiterated that there is no evidence that attackers had access to users' password vaults.

Why This Matters for Cybersecurity

The recent attack shows that cybersecurity is no longer limited to protecting internal servers and networks.

Today, companies connect dozens or even hundreds of different cloud services to their systems, and each of these services can become a point of entry for attackers.

Experts recommend that organizations prioritize the following measures:

Regularly review OAuth permissions
Remove unnecessary permission
Continuously monitor APIs
Restrict access to third-party services
Evaluate the security of software vendors

Industry Impact

The Klue incident is just one example of a growing trend of supply chain attacks.

In recent years, cybercriminals have focused more on technology service providers rather than directly attacking large companies, as infiltrating one company can provide access to dozens of customers’ data.

This has made supply chain security one of the top priorities for CISOs in 2026.

Conclusion

Although LastPass said that sensitive user data and password vaults were not compromised in the incident, the leak of customer support information shows that even the most secure companies are not immune to risks posed by third-party services.

The incident once again reminds us of the importance of managing supply chain risk, monitoring cloud access, and assessing the security of suppliers.

As the use of SaaS services and APIs expands, similar attacks are expected to increase in the coming years, forcing companies to pay closer attention to the security of their technology partners.

FAQs

1. Was LastPass hacked directly?

No. The breach originated at third-party vendor Klue, not within LastPass's core infrastructure.

2. Were password vaults compromised?

No. LastPass says password vaults and master passwords were not affected.

3. What customer information was exposed?

Names, email addresses, phone numbers, postal addresses, support case data, and CRM-related records.

4. Why are support tickets valuable to attackers?

They may contain contextual information useful for phishing or social engineering attacks.

5. What should LastPass users do?

Be cautious of unexpected emails or calls claiming to be from LastPass, enable MFA where possible, and never share passwords or verification codes.

Share this article