The LastPass breach linked to the Klue supply-chain attack demonstrates how stolen OAuth tokens can allow attackers to access enterprise cloud data without compromising employee passwords or the target company’s core infrastructure.
Attackers obtained OAuth tokens held by Klue, a third-party market intelligence provider, and used them to access LastPass customer information stored in Salesforce. The exposed data may include customer names, email addresses, phone numbers, physical addresses, support case information, and sales-related records.
LastPass stated that its password-management products, services, infrastructure, and customer vaults were not affected. There was also no evidence that data from its Gong integration was accessed.
Although password vaults remained secure, the exposed customer and support information may help attackers create convincing phishing and social-engineering campaigns. Messages could refer to genuine support cases, account details, or previous communications to appear legitimate.
Customers should remain cautious of unsolicited emails, calls, or messages claiming to come from LastPass. LastPass representatives will never request a customer’s master password, recovery key, or one-time authentication code.
The incident highlights the risks created by trusted SaaS integrations. Organizations should inventory connected applications, limit OAuth permissions, monitor unusual API activity, remove dormant integrations, and rapidly revoke tokens following a third-party compromise.
The key lesson is that an organization’s security boundary includes every external application authorized to access its cloud data. Attackers may not need to breach the main platform when a trusted integration already holds the keys.
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]
Source: LastPass confirms data breach in Klue supply chain attack via Bleeping Computer — published 23 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.