LastPass – hacked….| again

LastPass warns customers LastPass said its personal information and customer support data were stolen when hackers breached Klue, a competing information provider that held OAuth tokens to access LastPass’ Salesforce environment. The breach did not compromise LastPass’s infrastructure itself or its customers’ encrypted passwords. The stolen data includes names, phone numbers, email addresses, physical addresses, and the content of customer support interactions.

Klue disclosed the breach on June 12, when CEO Jason Smith confirmed that the attackers had gained access to OAuth tokens the company held on behalf of its customers. These tokens provided authenticated access to Salesforce environments where companies like LastPass store customer and support data. The hackers used the stolen tokens to extract files from multiple organizations at once.

See more articles from iGuRu.gr when you search for news on Google.

A hacking group called Icarus claimed responsibility for the attack, threatening to release the stolen data unless the affected companies paid a ransom. LastPass did not disclose how many customers were affected, but said it was notifying those whose information was leaked. The company has about 33 million users and more than a million paying customers.

LastPass isn’t the only company to be hit. Supply chain attacks have become one of the defining cyber threats of 2026, and the Klue breach follows the same pattern: instead of attacking the target directly, the hackers compromised a trusted third-party vendor that held access credentials. Other companies affected by the Klue breach include HackerOne, Recorded Future, Tanium, Gong, Jamf, Snyk, OneTrust, Sprout Social, and Huntress.

The incident is particularly damaging for LastPass because of the company’s history. In 2022, hackers directly breached LastPass and stole all of its customers’ passwords. The breach eroded trust in the company and prompted a wave of customers to switch to competitors.

This time, LastPass stressed that its own systems were not compromised and that the attackers did not gain access to encrypted passwords. The distinction is important, but it does not provide security for customers whose personal information and the content of their support cases are now in the hands of a group of extortionists.


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).