LastPass data breach exposes customer data in Klue supply chain attack

Attackers stole OAuth tokens from Klue, exposing LastPass customer names, emails, and addresses in a supply chain breach.

By Central
LastPass breach through Klue highlights supply chain risks as OAuth tokens expose CRM data.
Highlights
  • Attackers used stolen OAuth tokens from Klue to access LastPass Salesforce data.
  • Exposed data includes customer names, emails, phone numbers, and CRM records.
  • The Icarus extortion group claimed responsibility for the Klue supply chain attack.

LastPass has confirmed that customer data was compromised after attackers stole OAuth tokens from Klue, a third-party market intelligence platform, in a supply chain attack that unfolded earlier this month. The breach exposed customer names, email addresses, phone numbers, physical addresses, and CRM-related data stored in LastPass’s Salesforce environment, though the company states that its core password management products, services, and customer vaults were not affected. The incident underscores the growing risk of supply chain attacks that target the integration layers between enterprise SaaS platforms.

How the Klue OAuth Compromise Led to LastPass Customer Data Exposure

On June 12th, LastPass was notified of a security incident at Klue, a market intelligence platform used by LastPass’s go-to-market teams. Klue integrates with LastPass’s Salesforce and Gong systems, and the attackers managed to steal OAuth tokens that Klue held for many of its customers, including LastPass. These tokens were then used to access LastPass customer data within the Salesforce environment.

The investigation found no evidence that the attacker accessed Gong-related data, which typically includes customer calls and emails. However, the OAuth-based access was sufficient to pull a range of personally identifiable information and CRM records from Salesforce.

Exposed Data Types and the Risk of Downstream Attacks

LastPass disclosed that the following categories of customer data were potentially accessed in the breach:

  • Customer names
  • Phone numbers
  • Email addresses
  • Physical addresses
  • Support case information
  • Sales and CRM-related data

This data set is highly valuable for phishing and social engineering campaigns. Attackers can use the exposed personal details to craft targeted messages that appear legitimate, potentially tricking users into revealing their master password or other sensitive credentials. LastPass has warned that users should remain cautious of unsolicited communications requesting sensitive information.

The Icarus Extortion Group and the Supply Chain Attack Chain

The Klue supply chain attack was claimed by the Icarus extortion group, which compromised Klue’s infrastructure using compromised legacy credentials for an integration service. This gave the group access to OAuth tokens linking Klue to various third-party services, including those belonging to LastPass and several other organizations.

The incident impacted multiple companies, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. The threat actor exfiltrated Customer Relationship Management data from connected environments and launched an extortion campaign against the affected organizations.

What Data Was Exposed in the LastPass Klue Breach?

The exposed data in the LastPass Klue breach includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related CRM data. The attackers obtained this information by using stolen OAuth tokens to access LastPass’s Salesforce environment. The company confirmed that no customer vaults, master passwords, or core password management infrastructure were compromised.

LastPass Response and Mitigation Steps

Upon discovering the breach, LastPass disabled employee access to Klue, rotated the exposed API and OAuth tokens, and notified law enforcement. The company also warned users about threat actors using the sender domains baccarat.com[.]au, robinskitchen.com[.]au, and house[.]com.au, emphasizing that only communications from official support channels should be trusted. The investigation is ongoing, and LastPass has not yet confirmed the total number of affected customers.

What Affected Users Should Do Now

Anyone who uses LastPass and may have interacted with its sales or support teams should take immediate precautions. Be extremely cautious of unsolicited phone calls, emails, or text messages that reference LastPass or request personal information. Do not share your master password with anyone, and enable two-factor authentication on your LastPass account if you have not already done so. Consider using a reputable, zero-knowledge password manager that encrypts data end-to-end and never stores your master password. Monitor your accounts and credit reports for signs of identity theft or unauthorized activity. Treat any communication requesting sensitive details with suspicion, and verify sender identities through official channels before responding.

Share This Article