Technology

LastPass Data Breach: Password Manager Hit by Supply Chain Attack; Customer Support Data Compromised

LastPass confirms a new data breach where customer support case data and CRM information were stolen from its Salesforce environment, stemming from a supply chain attack on its vendor, Klue. This marks the second significant breach for the password manager in recent years. While password vaults remain secure, exposed details like names and emails could be.

LastPass Data Breach: Password Manager Hit by Supply Chain Attack; Customer Support Data Compromised
LastPass Logo (Photo Credits: Official Website)
1
2
3
4
5

In a fresh blow to its reputation for safeguarding sensitive information, LastPass, the widely used password management service, has disclosed a new data breach. The company confirmed today, June 23, 2026, that an unauthorized actor gained access to its Salesforce environment, compromising customer support case data and other Customer Relationship Management (CRM) information. This breach originated from a supply chain attack on Klue (klue.com), a third-party market intelligence platform utilized by LastPass's go-to-market teams.

LastPass was first alerted to an incident at Klue on June 12, 2026. The investigation revealed that the attackers, identified as the 'Icarus' extortion group, exploited compromised legacy credentials to access Klue's infrastructure. From there, they obtained OAuth tokens that Klue held for many of its clients, including LastPass. These stolen tokens were then used to access customer data within LastPass's Salesforce system. Bajaj Auto Systems Hit by Ransomware Attack; Automaker Initiates Cybersecurity Protocols To Mitigate Impact.

Data Compromised and User Impact

The information exfiltrated primarily consists of business contact and CRM records. LastPass has confirmed that the exposed data includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related data. Crucially, LastPass has reiterated that there is no evidence of compromise to customer password vaults, master passwords, or its core products and services infrastructure. Furthermore, data related to its Gong integration was also unaffected.

While user passwords remain secure within their encrypted vaults, the stolen contact and support data present a significant risk. Cyber security experts warn that this type of information can be leveraged by attackers for sophisticated phishing campaigns, social engineering attacks, or even targeted extortion attempts against LastPass customers. Users are strongly advised to exercise extreme caution regarding unsolicited communications, whether by phone or email, especially if they request sensitive personal details.

LastPass's Response and Previous Incidents

Following the discovery, LastPass initiated an immediate investigation, disabled employee access to Klue, rotated all exposed API and OAuth tokens, and notified law enforcement. The company is also actively sharing threat intelligence through its Threat Intelligence, Mitigation, and Escalation (TIME) team to aid in disrupting the ongoing campaign and bolster industry-wide defenses.

This incident marks the second major data security setback for LastPass customers in recent years. The company faced a highly publicized series of breaches in 2022 and 2023, where attackers initially gained access to its development environment, stole source code, and later accessed customer vault backups (though encrypted master passwords remained uncompromised). These earlier breaches led to significant concerns within the cybersecurity community and prompted ongoing class-action lawsuits in various regions. Apple Confidential Documents Leaked on Dark Web Following Cyberattack on Manufacturing Partner Tata Electronics.

The recurrence of such incidents underscores the persistent challenges faced by even leading cybersecurity firms in defending against sophisticated supply chain attacks and highlights the need for continuous vigilance in protecting user data.

Disclaimer: AI tools assisted in compiling the foundational data and research for this report. The final content was reviewed, edited and verified by human editors at LatestLY.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (TechCrunch), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Jun 23, 2026 09:33 PM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).