Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedhigh

LastPass confirms data breach in Klue supply chain attack

LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
LastPass customer data accessed via compromised Salesforce environment; OAuth tokens stolen from Klue supply chain attack
Ecosystems
Attack vectors
Affected entities
  • LastPassCustomer data accessed via Salesforce environment after OAuth token theft in Klue supply chain attack

LastPass announced a data breach affecting its customers following the Klue supply chain attack. Attackers stole LastPass OAuth tokens, which they then used to gain unauthorized access to the company's Salesforce environment.

The breach resulted in unauthorized access to customer data stored in the Salesforce instance. This incident represents a third-party vendor compromise, where the initial attack vector originated from a supply chain vulnerability at Klue, a third-party service provider.

LastPass has confirmed the incident and is working to remediate the unauthorized access and secure affected customer information.

Remediation

  • Review and revoke OAuth tokens and API credentials used by third-party integrations
  • Audit Salesforce access logs for unauthorized activity and data access
  • Notify affected customers of the data breach and provide credit monitoring or identity protection services
  • Implement stricter OAuth token management and rotation policies
  • Review and strengthen authentication requirements for critical systems and integrations
  • Conduct security assessment of third-party vendor integrations and their security posture

Sources

  1. LastPass confirms data breach in Klue supply chain attack · BleepingComputer

Cite this entry

"LastPass confirms data breach in Klue supply chain attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 23, 2026; last updated June 23, 2026. https://supplychainattack.org/incident/lastpass-confirms-data-breach-in-klue-supply-chain-attack-xn6omg

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. activehigh

    Ernst & Young data breach claimed by ShinyHunters extortion gang

    ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.

    ShinyhuntersOtherThird-party vendor breach
  2. containedhigh

    Polymarket customers lose $3 million in supply-chain attack

    Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.

    OtherThird-party vendor breach
  3. activehigh

    Context.ai OAuth Token Compromise

    Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.

    OtherAccount takeoverThird-party vendor breach
  4. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover