Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LastPass Data Breach Exposes Customer Information via Klue

LastPass Data Breach Exposes Customer Information via Klue

Posted on June 23, 2026 By CWS

LastPass recently faced a security breach through its third-party vendor, Klue, compromising customer information stored within its Salesforce database. The incident, although not affecting LastPass’s core infrastructure or password vaults, highlights the vulnerabilities inherent in Software as a Service (SaaS) integrations and OAuth token misuse.

Incident Overview

On June 12, LastPass was alerted to unusual activities involving Klue, a market intelligence tool integrated with enterprise systems such as Salesforce. This breach allowed unauthorized access to customer data, though it did not impact the company’s core services.

The attackers exploited stored OAuth tokens to access LastPass’s Salesforce data, sidestepping traditional login procedures by leveraging API-based authentication trusted between services. This incident underscores the increasing exploitation of token-based trust mechanisms in supply chain attacks.

Data Exposure Details

According to LastPass, only systems connected to Klue were affected, and no core products or password vaults were compromised. The accessed data includes standard business information such as customer names, email addresses, and CRM-related data.

While no sensitive authentication data was leaked, the exposed data could be used for targeted phishing or social engineering schemes. There is no current evidence of data access from Gong systems during the breach.

Response and Future Measures

Immediately after detection, LastPass implemented incident response protocols, revoking employee access to Klue and rotating compromised API and OAuth tokens. A joint investigation with Klue and Salesforce is underway, and law enforcement has been notified.

To prevent similar incidents, LastPass is enhancing security measures around third-party integrations and token controls, reinforcing monitoring systems, and reassessing access dependencies. Customers are advised to remain vigilant against unsolicited communications and verify any suspicious interactions through official channels.

LastPass identified several indicators of compromise, including specific IP addresses and malicious email domains, advising security teams to monitor for these within their networks.

Cyber Security News Tags:API security, customer data, Cybersecurity, data breach, Klue, LastPass, OAuth tokens, Phishing, Salesforce, supply chain attack, threat intelligence

Post navigation

Previous Post: Critical Security Risks Uncovered in Dify AI Platform
Next Post: FFmpeg Vulnerability Enables Remote Code Execution

Related Posts

New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data New TAOTH Campaign Exploits End-of-Support Software to Distribute Malware and Collect Sensitive Data Cyber Security News
Tata Motors Data Leak – 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys Tata Motors Data Leak – 70+ TB of Sensitive Info and Test Drive Data Exposed via AWS Keys Cyber Security News
Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature Cyber Security News
Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials Cyber Security News
Senate Investigates Cisco Over Zero-Day Firewall Vulnerabilities Senate Investigates Cisco Over Zero-Day Firewall Vulnerabilities Cyber Security News
Crypto Scams Surge in Asia with Sophisticated Tactics Crypto Scams Surge in Asia with Sophisticated Tactics Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands
  • Critical Dify Vulnerabilities Risk AI Data Leakage
  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands
  • Critical Dify Vulnerabilities Risk AI Data Leakage
  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark