LastPass hit again — third-party vendor breach exposes customer contact data
LastPass is notifying customers that their personal information was exposed through a breach at Klue, a market-research vendor whose platform integrates with the company’s Salesforce and Gong systems. Attackers accessed standard CRM records — names, phone numbers, email addresses, physical addresses — along with support case and sales data. LastPass says encrypted password vaults were not touched in this incident, since the compromise lived entirely in a downstream partner’s environment rather than its own infrastructure.
In response, LastPass revoked employee access to Klue, rotated the exposed API tokens, alerted law enforcement, and opened an investigation alongside Klue and Salesforce. The company published indicators of compromise — four attacker IP addresses and three email sender domains (all .com.au) — so other organizations can hunt for the same activity in their own logs. Because the stolen data is exactly what’s useful for impersonation, LastPass is warning users to expect phishing and social-engineering attempts that reference real account details.
The episode adds to a long record of security trouble for the password manager, following the 2015 theft of authentication hashes and the far more damaging 2022 incident, in which a compromised developer account ultimately led to attackers exfiltrating encrypted vaults plus unencrypted customer metadata. While this latest breach is less severe, it underscores how third-party integrations extend a company’s attack surface well beyond its own controls — a recurring supply-chain weak point for firms whose entire value proposition is trust.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.