The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

LastPass's disclosure of the Klue supply chain breach is corroborated by its official blog post and reports from CyberInsider, Huntress, SecurityWeek, and TechCrunch.

Sourcing
4independent sources

via BleepingComputer

BleepingComputer · track record
69Stories
100%Verified
830d
All sources →
Home/Tech/LastPass confirms customer data accessed in Klue supply chain incident
VERIFIEDBy Xavier Rivera· ·1.5 min read

LastPass confirms customer data accessed in Klue supply chain incident

LastPass confirmed that customer names, phone numbers, addresses, support cases, and CRM data stored in Salesforce were accessed after Icarus stole OAuth tokens in the Klue supply chain attack on June 12. Core products, vaults, and Gong data stayed secure while multiple firms face heightened phishing risks.

Source:BleepingComputer
Post
LastPass confirms customer data accessed in Klue supply chain incident
TL;DRAI · 60 sec read

LastPass confirms attackers accessed customer data in its Salesforce setup after stealing OAuth tokens during the Klue supply chain attack. Exposed details include names, emails, addresses, phone numbers, and CRM records. The company revoked access and rotated tokens. The incident shows how third-party integrations can leak enterprise data without touching core password vaults.

LastPass disclosed that unauthorized parties reached customer information held in its Salesforce setup after obtaining the firm's OAuth tokens during the Klue supply chain attack earlier this month.

LastPass discloses the breach details. The password management company reported becoming aware of the Klue event on June 12 and promptly started an investigation. According to the firm, "an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass." Those credentials reportedly allowed access to LastPass customer data inside the Salesforce environment. The company stressed that its products, services, infrastructure, and customer vaults stayed untouched, with the probe finding no sign of access to Gong-linked records such as calls or emails.
an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.

Exposed data types identified. Information that may have been viewed includes customer names, phone numbers, email addresses, physical addresses, support case details, and sales or CRM-related records. LastPass noted that attackers could exploit these details for phishing or social engineering. The firm urged caution with unexpected calls or messages that seek private information and warned against sharing master passwords with anyone.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Klue attack linked to Icarus group. The supply chain compromise was claimed by the Icarus extortion group, which breached the AI-powered market intelligence platform and took OAuth tokens used to link customer Salesforce environments. Multiple entities were hit, among them Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. The intruders extracted CRM data and began an extortion effort.
LastPass noted that attackers could exploit these details for phishing or social engineering.
Response measures and warnings issued. LastPass has cut employee access to Klue, rotated the exposed API and OAuth tokens, and contacted law enforcement as the inquiry proceeds. The company cautioned that the operators are sending messages from domains such as baccarat.com[.]au, robinskitchen.com[.]au, and house[.]com.au, adding that only official support channels can be trusted.
Broader implications for supply chain risks. Security teams continue to examine third-party integration weaknesses that tie into enterprise CRM platforms. The incident also affected other organizations beyond LastPass.

EXPERT TAKE

This incident underscores the persistent danger of OAuth token theft in supply chain compromises, where a single compromised integration can expose Salesforce data across dozens of security vendors without touching core product systems.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · The Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Two minutes, free forever.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
LastPassDataBreachSupplyChainAttackCybersecurity
More fromBleepingComputer
  • ChainDrop worm compromises over 1,300 npm packages totaling 2 billion downloads

    Tech · 3d
  • Anthropic confirms worldwide Claude outage

    Tech · 9d
  • MCBS breach impacts records of 1.26 million individuals

    Tech · 11d
More inTech
  • Tesla and SpaceX confirm Terafab chip fab in Texas

    Tech · 1d
  • OpenAI Urges Federal Judge to Throw Out Apple's Trade Secrets Complaint

    Tech · 2d
  • Meta introduces Muse Code, its terminal-based coding agent

    Tech · 2d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning. Free forever.

MORE IN TECH

Tesla and SpaceX confirm Terafab chip fab in Texas

Tesla and SpaceX have confirmed Grimes County, Texas as the site for their Terafab semiconductor megafactory, with the first phase costing roughly $16.8 billion. The project targets the largest chip manufacturing facility on the planet to supply over 1 terawatt of compute per year that exceeds current and future global production capacity.

OpenAI Urges Federal Judge to Throw Out Apple's Trade Secrets Complaint

OpenAI has filed a motion asking a federal judge to dismiss Apple's trade secrets lawsuit, describing the claims as meritless. The dispute, which follows a July suit and this week's injunction request from Apple, highlights tensions after their prior partnership on Siri and OpenAI's hardware push.

Meta introduces Muse Code, its terminal-based coding agent

Meta has released an early beta of Muse Code, a terminal-based coding agent driven by the updated Muse Spark 1.2 model and positioned against Anthropic's Claude Code and OpenAI's Codex. Substantially lower rates, including a contributor plan at $0.10 for every million tokens received, may encourage migration away from higher-priced options such as Anthropic's Sonnet 5.