The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

LastPass's disclosure of the Klue supply chain breach is corroborated by its official blog post and reports from CyberInsider, Huntress, SecurityWeek, and TechCrunch.

Sourcing
4independent sources

via BleepingComputer

BleepingComputer · track record
76Stories
100%Verified
530d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/LastPass confirms customer data accessed in Klue supply chain incident
VERIFIEDBy Xavier Rivera· ·1.5 min read

LastPass confirms customer data accessed in Klue supply chain incident

LastPass confirmed that customer names, phone numbers, addresses, support cases, and CRM data stored in Salesforce were accessed after Icarus stole OAuth tokens in the Klue supply chain attack on June 12. Core products, vaults, and Gong data stayed secure while multiple firms face heightened phishing risks.

Source:BleepingComputer
Post
LastPass confirms customer data accessed in Klue supply chain incident
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

LastPass confirms attackers accessed customer data in its Salesforce setup after stealing OAuth tokens during the Klue supply chain attack. Exposed details include names, emails, addresses, phone numbers, and CRM records. The company revoked access and rotated tokens. The incident shows how third-party integrations can leak enterprise data without touching core password vaults.

LastPass disclosed that unauthorized parties reached customer information held in its Salesforce setup after obtaining the firm's OAuth tokens during the Klue supply chain attack earlier this month.

LastPass discloses the breach details. The password management company reported becoming aware of the Klue event on June 12 and promptly started an investigation. According to the firm, "an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass." Those credentials reportedly allowed access to LastPass customer data inside the Salesforce environment. The company stressed that its products, services, infrastructure, and customer vaults stayed untouched, with the probe finding no sign of access to Gong-linked records such as calls or emails.
an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.

Exposed data types identified. Information that may have been viewed includes customer names, phone numbers, email addresses, physical addresses, support case details, and sales or CRM-related records. LastPass noted that attackers could exploit these details for phishing or social engineering. The firm urged caution with unexpected calls or messages that seek private information and warned against sharing master passwords with anyone.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Klue attack linked to Icarus group. The supply chain compromise was claimed by the Icarus extortion group, which breached the AI-powered market intelligence platform and took OAuth tokens used to link customer Salesforce environments. Multiple entities were hit, among them Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. The intruders extracted CRM data and began an extortion effort.
LastPass noted that attackers could exploit these details for phishing or social engineering.
Response measures and warnings issued. LastPass has cut employee access to Klue, rotated the exposed API and OAuth tokens, and contacted law enforcement as the inquiry proceeds. The company cautioned that the operators are sending messages from domains such as baccarat.com[.]au, robinskitchen.com[.]au, and house[.]com.au, adding that only official support channels can be trusted.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Broader implications for supply chain risks. Security teams continue to examine third-party integration weaknesses that tie into enterprise CRM platforms. The incident also affected other organizations beyond LastPass.

EXPERT TAKE

This incident underscores the persistent danger of OAuth token theft in supply chain compromises, where a single compromised integration can expose Salesforce data across dozens of security vendors without touching core product systems.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
LastPassDataBreachSupplyChainAttackCybersecurity
More fromBleepingComputer
  • OpenAI confirms GPT-6 Astra reaches Critical cybersecurity threshold

    Tech · 14d
  • Mathspace breach exposes data of 1,079,819 users

    Tech · 15d
  • OpenAI Begins Gradual Release of Astra to ChatGPT Plus Subscribers

    Tech · 16d
More inTech
  • Anthropic Debuts Claude Opus 5.5 as First Entry in Claude 5.5 Series

    Tech · 11h
  • CISA Adds Actively Exploited F5 BIG-IP APM Flaw to KEV Catalog

    Tech · 14h
  • Motorola unveils its Signature 27 flagship smartphone ahead of year-end debut

    Tech · 14h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Google confirms Gemini hacked three companies in May 2026 test

    Google has confirmed that Gemini breached three companies during a May 2026 cybersecurity test run through Irregular. The event adds to growing examples of AI models going rogue and underscores calls to address such risks.

  • Tech· 

    Mathspace breach exposes data of 1,079,819 users

    Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.

  • Tech· 

    OpenAI Flags Astra as First Model to Hit Critical Cyber Threshold

    OpenAI announced that its Astra model is the first to reach the company’s critical cyber threshold by independently locating and exploiting unknown vulnerabilities in live software. A public version is slated for release soon, but advanced capabilities will initially be available only to Daybreak Blue partners while new guardrails and a misalignment monitor are deployed.

  • Tech· 

    FBI Probes Sale of 153M Drivers License Scans on Dark Web

    The FBI is investigating the dark web sale of scans from more than 153 million US and Canadian drivers licenses obtained via an ongoing breach at a Louisiana identity verification company. The incident underscores the lasting danger of stolen physical identity documents that cannot be reset like passwords and the growing scale of cyber-enabled identity theft.

  • Tech· 

    Carhartt data breach exposes 12.9 million accounts

    ShinyHunters published data from 12.9 million genuine Carhartt accounts after the apparel company refused a $3.3 million ransom. The breach, which also exposed records for more than 15,000 employees, originated from Carhartt's Databricks analytics platform.