LastPass Users Exposed in Supply Chain Breach

LastPass users face data exposure after attackers compromise Klue, a third-party AI platform, and steal sensitive contact information from Salesforce.

By Central
The supply chain attack on Klue leaked names, emails, and phone numbers but spared LastPass password vaults.
Highlights
  • Attackers stole access tokens from Klue to siphon LastPass customer data from Salesforce and other systems.
  • Exposed data includes names, phone numbers, email addresses, and support records, enabling targeted phishing campaigns.
  • LastPass confirmed no password vaults or master passwords were compromised in the breach.

LastPass customers are facing a fresh data exposure after a supply chain attack on Klue, an AI business intelligence platform, allowed attackers to siphon sensitive customer information from Salesforce and other integrated systems. The incident, which LastPass disclosed this week, exposes names, phone numbers, email addresses, physical addresses, support case records, and sales-related data—though the company stresses that password vaults and its own core infrastructure were not compromised. For a user base already wary after years of high-profile breaches, this latest event underscores how even indirect integrations can become vectors for data theft.

How the LastPass Supply Chain Breach Unfolded

The attack originated at Klue, a business intelligence firm that LastPass uses for various integrated services. According to disclosures from both companies, attackers compromised access tokens belonging to Klue customers—including LastPass—and then used those tokens to pull data from Salesforce and other linked platforms. This is a classic supply chain compromise: rather than breaching LastPass directly, the attackers targeted a third-party vendor with trusted access and leveraged that trust to exfiltrate data. LastPass published a notification on its blog confirming the incident and directing customers to Klue’s own security update for additional technical details.

What Data Was Exposed in the Klue Attack

The exposed data set includes names, phone numbers, email and physical addresses, support case histories, and sales records. Critically, LastPass has confirmed that no encrypted password vaults, master passwords, or authentication secrets were accessed. This distinction matters: while the exposed contact details are a serious privacy concern and a potent phishing enabler, the core asset that LastPass users rely on—their vault of credentials—remains intact. However, the breadth of personal information captured gives attackers a strong foundation for targeted social engineering campaigns.

What Affected Users Should Do Now

LastPass advised customers to remain vigilant against phishing and social engineering attempts that may leverage the exposed contact details. In its notification, the company warned: “Always exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information.” Users should treat any unexpected message referencing LastPass, Klue, or related services with heightened skepticism. Enabling multi-factor authentication on all accounts, using a zero-knowledge password manager to generate unique credentials for each service, and monitoring financial and account activity for anomalies are practical next steps. For communications over untrusted networks—such as public Wi-Fi—using a VPN with AES-256 encryption and a verified no-logs policy adds a layer of protection against interception.

A Broader Week in Cybersecurity

The LastPass incident arrives amid a series of significant security developments. Microsoft, Europol, and partners disrupted the infrastructure of the Amadey and StealC infostealers as part of Operation Endgame, seizing 326 servers and 142 domains and recovering up to 27 million stolen credentials. In Australia, ASIO disclosed that nation-state hackers had compromised a critical infrastructure provider, mapping networks and maintaining access with the apparent intent of sabotage. Meanwhile, former national security adviser John Bolton pleaded guilty to mishandling classified defense information, and the White House granted Anthropic permission to selectively restore its Claude Mythos 5 model. Each of these events reinforces the same reality: the threat landscape is broad, interconnected, and requires layered defenses.

Recommendation for LastPass Users and Beyond

If you are a LastPass user, the immediate priority is hardening your defenses against phishing. The exposed contact details give attackers everything they need to craft convincing impersonation attempts. Enable multi-factor authentication wherever supported, use a zero-knowledge password manager to maintain strong, unique credentials, and consider a reputable no-log VPN service for sensitive transactions on public networks. For all users, the supply chain attack on Klue is a reminder that trust extends beyond the primary service provider—vet the integrations and third-party access permissions tied to your critical accounts.

Share This Article