LastPass confirms data breach after hacker compromises supply chain — here's what we know

LastPass confirms data breach after hacker compromises supply chain — here’s what we know | Daily Reports Online

Share


  • LastPass confirmed a supply chain breach via Klue, where stolen OAuth tokens let attackers access its Salesforce environment
  • Customer names, contact details, and CRM data were exposed, but master passwords were not; phishing risk remains high
  • Threat actor Icarus claimed responsibility; other firms including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity also impacted

Password manager LastPass confirmed that it lost sensitive customer data in a supply chain attack that struck a third party.


As LastPass explained in a newly released incident report, unnamed threat actors first targeted Klue, a third-party market intelligence platform that integrates with its Salesforce and Gong systems. After obtaining its OAuth tokens, the attackers were able to access LastPass’ Salesforce environment and exfiltrate sensitive data stored there.


Similar Posts