---
title: "LastPass confirms data breach in Klue supply chain attack"
url: https://daily.dev/posts/lastpass-confirms-data-breach-in-klue-supply-chain-attack-vv50ily4v
source_url: https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack
type: article
source: "BleepingComputer"
published: 2026-06-23T14:02:10.277Z
updated: 2026-06-23T14:03:07.936Z
tags: ["cyber", "data-breach", "salesforce", "oauth"]
reading_time: 3
upvotes: 6
comments: 4
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# LastPass confirms data breach in Klue supply chain attack

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 6 upvotes · 4 comments

## Summary

LastPass confirmed that hackers accessed customer data stored in its Salesforce environment following the Klue supply chain attack on June 12th. The Icarus extortion group compromised Klue's infrastructure using legacy credentials, stealing OAuth tokens that connected Klue to its customers' Salesforce environments. Exposed data includes customer names, phone numbers, email addresses, physical addresses, support case information, and CRM data. LastPass states that its core products, services, and customer vaults were not affected. The company has disabled employee access to Klue, rotated exposed tokens, and notified law enforcement. Users are advised to be wary of phishing attempts and unsolicited communications, and to never share their master password.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack>

## Community discussion

Top comments from developers on daily.dev.

**@fabianletsch** · 1 upvotes

> One of those companies who 100% rely on a perfect security track record.
>
>
> This is devastating for their business even if this does not affect their core products.
>
>
> Switched off from them a long time ago.

**@randallb** · 0 upvotes

> the second breach of customer data with this company, only 4 years later
>
> can't help but notice that bitwarden isn't getting paid to be breach-free like lastpass

**@ankitkumawat93** · 0 upvotes

> This is very dangerous. we are getting attack even on most secure environments or websites. Is this effect of blindly using many AI tools ?

**@amizzo** · 0 upvotes

> Can't believe people still use/trust LastPass

## Similar posts on daily.dev

- [LastPass says hackers stole customer data through a supply chain breach at Klue](https://daily.dev/posts/lastpass-says-hackers-stole-customer-data-through-a-supply-chain-breach-at-klue-cot1tyrco) · The Next Web · 0 upvotes · 0 comments
- [Password manager maker LastPass says hackers stole customer support case data during Klue breach](https://daily.dev/posts/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach-n8k7j6rbl) · TechCrunch · 0 upvotes · 0 comments
- [Klue says the hackers who stole its customer data are deleting it, but a second group has emerged with extortion demands](https://daily.dev/posts/klue-says-the-hackers-who-stole-its-customer-data-are-deleting-it-but-a-second-group-has-emerged-wi-m10djzwxj) · The Next Web · 0 upvotes · 0 comments
- [Klue says hackers stole credential from 2022 that led to customer data breaches](https://daily.dev/posts/klue-says-hackers-stole-credential-from-2022-that-led-to-customer-data-breaches-vdzy86run) · TechCrunch · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#data-breach](https://daily.dev/tags/data-breach), [#salesforce](https://daily.dev/tags/salesforce), [#oauth](https://daily.dev/tags/oauth)

[View this post on daily.dev](https://daily.dev/posts/lastpass-confirms-data-breach-in-klue-supply-chain-attack-vv50ily4v)
