The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

LastPass's disclosure of the Klue supply chain breach is corroborated by its official blog post and reports from CyberInsider, Huntress, SecurityWeek, and TechCrunch.

Sourcing
4independent sources

via BleepingComputer

BleepingComputer · track record
65Stories
100%Verified
2830d
All sources →
Home/Tech/LastPass confirms customer data accessed in Klue supply chain incident
VERIFIEDBy Xavier Rivera· ·1.5 min read

LastPass confirms customer data accessed in Klue supply chain incident

LastPass confirmed that customer names, phone numbers, addresses, support cases, and CRM data stored in Salesforce were accessed after Icarus stole OAuth tokens in the Klue supply chain attack on June 12. Core products, vaults, and Gong data stayed secure while multiple firms face heightened phishing risks.

Source:BleepingComputer
Post
LastPass confirms customer data accessed in Klue supply chain incident
TL;DRAI · 60 sec read

LastPass confirms attackers accessed customer data in its Salesforce setup after stealing OAuth tokens during the Klue supply chain attack. Exposed details include names, emails, addresses, phone numbers, and CRM records. The company revoked access and rotated tokens. The incident shows how third-party integrations can leak enterprise data without touching core password vaults.

LastPass disclosed that unauthorized parties reached customer information held in its Salesforce setup after obtaining the firm's OAuth tokens during the Klue supply chain attack earlier this month.

LastPass discloses the breach details. The password management company reported becoming aware of the Klue event on June 12 and promptly started an investigation. According to the firm, "an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass." Those credentials reportedly allowed access to LastPass customer data inside the Salesforce environment. The company stressed that its products, services, infrastructure, and customer vaults stayed untouched, with the probe finding no sign of access to Gong-linked records such as calls or emails.
an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass.

Exposed data types identified. Information that may have been viewed includes customer names, phone numbers, email addresses, physical addresses, support case details, and sales or CRM-related records. LastPass noted that attackers could exploit these details for phishing or social engineering. The firm urged caution with unexpected calls or messages that seek private information and warned against sharing master passwords with anyone.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Klue attack linked to Icarus group. The supply chain compromise was claimed by the Icarus extortion group, which breached the AI-powered market intelligence platform and took OAuth tokens used to link customer Salesforce environments. Multiple entities were hit, among them Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. The intruders extracted CRM data and began an extortion effort.
LastPass noted that attackers could exploit these details for phishing or social engineering.
Response measures and warnings issued. LastPass has cut employee access to Klue, rotated the exposed API and OAuth tokens, and contacted law enforcement as the inquiry proceeds. The company cautioned that the operators are sending messages from domains such as baccarat.com[.]au, robinskitchen.com[.]au, and house[.]com.au, adding that only official support channels can be trusted.
Broader implications for supply chain risks. Security teams continue to examine third-party integration weaknesses that tie into enterprise CRM platforms. The incident also affected other organizations beyond LastPass.

EXPERT TAKE

This incident underscores the persistent danger of OAuth token theft in supply chain compromises, where a single compromised integration can expose Salesforce data across dozens of security vendors without touching core product systems.

Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →

Reader-supported · Daily Brief

Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.

HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
LastPassDataBreachSupplyChainAttackCybersecurity
More fromBleepingComputer
  • CISA warns of actively exploited RCE flaws in Joomla extensions

    Tech · 2d
  • OpenAI Temporarily Drops 5-Hour Cap on GPT-5.6 Sol

    Tech · 3d
  • Progress tells ShareFile on-premises users to power down servers over reported threat

    Tech · 5d
More inTech
  • TSMC profit surges 77% as Arizona spending swells by $100 billion

    Tech · 39m
  • China's CXMT Doubles IPO Target to $8.55 Billion

    Tech · 16h
  • CISA Adds KNX Protocol CVE-2023-4346 to KEV Catalog

    Tech · 20h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
SubscribeCircuitry Brief

Daily brief at 7 AM ET. Top tech stories, every morning.

MORE IN TECH

TSMC profit surges 77% as Arizona spending swells by $100 billion

TSMC posted a 77.4% year-on-year profit increase to NT$706.56 billion and raised its capital spending outlook while announcing another $100 billion for Arizona fabs. The results underscore sustained AI demand that now dominates 66% of its platform revenue.

China's CXMT Doubles IPO Target to $8.55 Billion

ChangXin Memory Technologies expects to raise 57.9 billion yuan ($8.55 billion) in its Shanghai STAR Market IPO after doubling its original target. The world's fourth-largest DRAM chipmaker will list on July 27, advancing China's push for semiconductor self-reliance.

CISA Adds KNX Protocol CVE-2023-4346 to KEV Catalog

CISA added CVE-2023-4346 affecting KNX Association KNX Protocol Connection Authorization Option 1 to its Known Exploited Vulnerabilities catalog on 2026-07-15. Federal agencies must finish remediation by 2026-07-29. The overly restrictive account lockout mechanism could let attackers purge devices and set a BCU key when extra security options remain disabled, so organizations must apply vendor mitigations under BOD 26-04.