All Posts

Cybersecurity

LastPass Confirms Customer Data Stolen in Klue Supply Chain Breach

LastPass Confirms Customer Data Stolen in Klue Supply Chain Breach

Bhavika J

Editorial Team

What happened

LastPass confirmed on June 23, 2026 that customer data was stolen from its Salesforce environment after attackers compromised Klue, a competitive intelligence vendor that integrates with Salesforce and Gong on behalf of its customers (TechCrunch, 2026). The stolen records include customer names, phone numbers, email addresses, physical addresses, and support case information pulled from LastPass's CRM. LastPass said its products, infrastructure and customer password vaults were not affected by the incident.

Klue separately confirmed the root cause the same day: attackers gained access to Klue's backend using a legacy API credential issued in 2022 for a prototype integration that was never launched, then used that foothold to harvest OAuth tokens connecting Klue to customer Salesforce and Gong instances (TechCrunch, 2026). Those tokens were then used to bulk-export CRM records directly from the affected companies' own Salesforce environments, without needing to breach each company individually.

BleepingComputer's reporting on the same day corroborates the token-theft mechanism and the Salesforce CRM scope of the exposure (BleepingComputer, 2026).

Who is affected

At least twelve organizations that use Klue's integration have confirmed they were hit: LastPass, HackerOne, Recorded Future, Tanium, Huntress, ReliaQuest, Jamf, Sprout Social, Gong, Insurity, OneTrust and Snyk (TechCrunch, 2026). Several of these are themselves security vendors, which means their own customers' contact and support-case data may be downstream of this exposure. The data taken varies by company but centers on CRM contents: names, contact details, support tickets, sales notes and, in some cases, pricing and opportunity records.

A group calling itself Icarus has publicly claimed the intrusion and is pressuring victims through direct extortion messages and a leak site, according to BleepingComputer's separate reporting on the Klue token theft (BleepingComputer, 2026). That claim has not been independently verified by any of the affected companies in their public statements, and none of LastPass's or Klue's own disclosures name the group. This is a self-attributed claim, not a confirmed finding.

What was not affected

LastPass was specific about the boundary of the exposure. The company said its password-manager product, core infrastructure and customer vaults were not touched, and that passwords, including master passwords, were not exposed. The stolen data sits entirely in the Salesforce CRM layer used for sales and support operations, separate from the product itself.

What affected customers should know

Anyone who has an open or recent support case with one of the twelve named companies should treat unsolicited calls or emails referencing that case, or their account details, with suspicion. The exposed data, including support case history and contact information, is the kind of detail that makes phone-based social engineering harder to spot, since a caller can reference a real ticket number or a real account issue. LastPass customers specifically should note that this does not require any vault or password action; the exposure is contact and case data, not credentials.

Vendor response

LastPass said it discontinued employee access to Klue, rotated API tokens exposed through the integration, and notified law enforcement (TechCrunch, 2026). Klue's disclosure did not specify a remediation timeline for restoring the integration to its other customers.

What happens next

The victim count traces back to a single compromised integration vendor, and Klue has other customers beyond the twelve confirmed so far, so the list is likely to grow as more companies audit their own Salesforce exposure. Watch for additional disclosures from Klue's customer base over the following weeks, and for any update from Klue on whether the 2022 legacy credential was an isolated gap or part of a broader pattern in how it manages decommissioned integrations.

Sources: TechCrunch · TechCrunch · BleepingComputer · BleepingComputer