LastPass confirms data breach in Klue supply chain attack
LastPass confirmed that hackers accessed customer data from its Salesforce environment by stealing the company's OAuth tokens during the Klue supply chain attack. The breach exposed customer information through a third-party vendor compromise.
- Disclosed
- Last updated
- Blast radius
- LastPass customer data accessed via compromised Salesforce environment; OAuth tokens stolen from Klue supply chain attack
- Ecosystems
- Attack vectors
- Affected entities
- LastPassCustomer data accessed via Salesforce environment after OAuth token theft in Klue supply chain attack
LastPass announced a data breach affecting its customers following the Klue supply chain attack. Attackers stole LastPass OAuth tokens, which they then used to gain unauthorized access to the company's Salesforce environment.
The breach resulted in unauthorized access to customer data stored in the Salesforce instance. This incident represents a third-party vendor compromise, where the initial attack vector originated from a supply chain vulnerability at Klue, a third-party service provider.
LastPass has confirmed the incident and is working to remediate the unauthorized access and secure affected customer information.
Remediation
- Review and revoke OAuth tokens and API credentials used by third-party integrations
- Audit Salesforce access logs for unauthorized activity and data access
- Notify affected customers of the data breach and provide credit monitoring or identity protection services
- Implement stricter OAuth token management and rotation policies
- Review and strengthen authentication requirements for critical systems and integrations
- Conduct security assessment of third-party vendor integrations and their security posture
Sources
- LastPass confirms data breach in Klue supply chain attack · BleepingComputer
Cite this entry
"LastPass confirms data breach in Klue supply chain attack." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed June 23, 2026; last updated June 23, 2026. https://supplychainattack.org/incident/lastpass-confirms-data-breach-in-klue-supply-chain-attack-xn6omg
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- activehigh
Ernst & Young data breach claimed by ShinyHunters extortion gang
ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young, stating they obtained credentials for company systems via a supply-chain attack. The breach was recently disclosed and the threat actor is actively claiming the incident.
ShinyhuntersOtherThird-party vendor breach - containedhigh
Polymarket customers lose $3 million in supply-chain attack
Polymarket customers lost approximately $3 million after attackers injected malicious scripts into the platform's frontend following a breach at a third-party vendor. Polymarket announced it will fully reimburse affected customers.
OtherThird-party vendor breach - activehigh
Context.ai OAuth Token Compromise
Context.ai OAuth tokens were compromised, allowing attackers to conduct supply chain attacks through trusted SaaS integrations. Details on scope, timeline, and remediation steps are not provided in the source text.
OtherAccount takeoverThird-party vendor breach - activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover