LastPass warns customers LastPass said its personal information and customer support data were stolen when hackers breached Klue, a competing information provider that held OAuth tokens to access LastPass’ Salesforce environment. The breach did not compromise LastPass’s infrastructure itself or its customers’ encrypted passwords. The stolen data includes names, phone numbers, email addresses, physical addresses, and the content of customer support interactions.
Klue disclosed the breach on June 12, when CEO Jason Smith confirmed that the attackers had gained access to OAuth tokens the company held on behalf of its customers. These tokens provided authenticated access to Salesforce environments where companies like LastPass store customer and support data. The hackers used the stolen tokens to extract files from multiple organizations at once.




