Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LastPass Data Breach Exposes Customer Information via Klue

LastPass Data Breach Exposes Customer Information via Klue

Posted on June 23, 2026 By CWS

LastPass recently faced a security breach through its third-party vendor, Klue, compromising customer information stored within its Salesforce database. The incident, although not affecting LastPass’s core infrastructure or password vaults, highlights the vulnerabilities inherent in Software as a Service (SaaS) integrations and OAuth token misuse.

Incident Overview

On June 12, LastPass was alerted to unusual activities involving Klue, a market intelligence tool integrated with enterprise systems such as Salesforce. This breach allowed unauthorized access to customer data, though it did not impact the company’s core services.

The attackers exploited stored OAuth tokens to access LastPass’s Salesforce data, sidestepping traditional login procedures by leveraging API-based authentication trusted between services. This incident underscores the increasing exploitation of token-based trust mechanisms in supply chain attacks.

Data Exposure Details

According to LastPass, only systems connected to Klue were affected, and no core products or password vaults were compromised. The accessed data includes standard business information such as customer names, email addresses, and CRM-related data.

While no sensitive authentication data was leaked, the exposed data could be used for targeted phishing or social engineering schemes. There is no current evidence of data access from Gong systems during the breach.

Response and Future Measures

Immediately after detection, LastPass implemented incident response protocols, revoking employee access to Klue and rotating compromised API and OAuth tokens. A joint investigation with Klue and Salesforce is underway, and law enforcement has been notified.

To prevent similar incidents, LastPass is enhancing security measures around third-party integrations and token controls, reinforcing monitoring systems, and reassessing access dependencies. Customers are advised to remain vigilant against unsolicited communications and verify any suspicious interactions through official channels.

LastPass identified several indicators of compromise, including specific IP addresses and malicious email domains, advising security teams to monitor for these within their networks.

Cyber Security News Tags:API security, customer data, Cybersecurity, data breach, Klue, LastPass, OAuth tokens, Phishing, Salesforce, supply chain attack, threat intelligence

Post navigation

Previous Post: Critical Security Risks Uncovered in Dify AI Platform
Next Post: FFmpeg Vulnerability Enables Remote Code Execution

Related Posts

Iranian Hackers Evade Detection with .NET Hijacking Iranian Hackers Evade Detection with .NET Hijacking Cyber Security News
Kimsuky Uses LNK Files to Deploy Python Backdoor Kimsuky Uses LNK Files to Deploy Python Backdoor Cyber Security News
LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data LexisNexis Risk Solutions Data Breach Exposes 364,000 individuals personal Data Cyber Security News
Rockwell ControlLogix Ethernet Vulnerability Let Attackers Execute Remote Code Rockwell ControlLogix Ethernet Vulnerability Let Attackers Execute Remote Code Cyber Security News
AI API Routers: Security Risks and Data Theft Concerns AI API Routers: Security Risks and Data Theft Concerns Cyber Security News
Malicious OpenVSX Extension Infects Multiple Code Editors Malicious OpenVSX Extension Infects Multiple Code Editors Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Boosts Post-Quantum Cryptography Efforts with New Order
  • Federal Push for Post-Quantum Security by 2030
  • Enhancing SOC Efficiency by Reducing IOC Noise
  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Boosts Post-Quantum Cryptography Efforts with New Order
  • Federal Push for Post-Quantum Security by 2030
  • Enhancing SOC Efficiency by Reducing IOC Noise
  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark