Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LastPass, BeyondTrust Affected by Klue Data Breach

LastPass, BeyondTrust Affected by Klue Data Breach

Posted on June 24, 2026 By CWS

In a recent cybersecurity incident, LastPass and BeyondTrust have been identified as victims of a data breach originating from Klue’s compromised systems. The breach allowed unauthorized access to customers’ Salesforce data, following a hack by a group identifying as Icarus.

How the Breach Occurred

The threat actor Icarus exploited a legacy credential from Klue to infiltrate its systems and create OAuth tokens. These tokens enabled the attackers to penetrate third-party platforms that integrate with Klue, including Salesforce. Once inside, they extracted substantial data using automated processes.

Impact on Affected Companies

As a result of the breach, Salesforce and Gong have disabled their Klue integrations, affecting over a dozen organizations. Notifications from these companies indicate that the attackers only accessed external business data linked through Klue, leaving internal systems untouched.

LastPass confirmed that the compromised data was confined to business contact information, CRM data such as customer names, contact details, and sales-related information. The company has since disabled Klue access, rotated exposed tokens, and is cooperating with law enforcement and partners to investigate the breach.

Broader Consequences and Responses

The breach has also affected other companies, including 8×8 and Pendo, adding to a growing list of impacted organizations. Despite the breach, LastPass assured its users that their products and infrastructure remain secure, with no evidence of Gong-related data being accessed.

BeyondTrust reported similar data exposure from its Salesforce instance. Meanwhile, Icarus’s Tor-based leak site previously listed several organizations as victims, though the site is currently down.

Huntress estimates that more Klue customers may have been affected by the data breach, with additional disclosures anticipated.

As the investigation continues, it is evident that the breach highlights vulnerabilities in third-party integrations, prompting a need for enhanced security measures in interconnected digital ecosystems.

Security Week News Tags:BeyondTrust, business data, Cyberattack, cybersecurity incident, data breach, Icarus, Klue breach, LastPass, OAuth tokens, Salesforce

Post navigation

Previous Post: Fake Tax Notices Spread Malware to Windows Users
Next Post: Edge Extension Malware Exploits Chrome Protocol

Related Posts

Chrome 149 Update Fixes Record 429 Security Flaws Chrome 149 Update Fixes Record 429 Security Flaws Security Week News
In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked Security Week News
Armored Likho APT Threatens Global Government Sectors Armored Likho APT Threatens Global Government Sectors Security Week News
Proofpoint Completes .8 Billion Acquisition of Hornetsecurity  Proofpoint Completes $1.8 Billion Acquisition of Hornetsecurity  Security Week News
Cisco Firewall Flaw Exploited in Ransomware Attacks Cisco Firewall Flaw Exploited in Ransomware Attacks Security Week News
FBI Verifies Email Breach as US Offers Reward for Hackers FBI Verifies Email Breach as US Offers Reward for Hackers Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Malicious Extension Mimics Google Translate, Compromises Browsers
  • OpenAI’s Astra Sparks Cybersecurity Worries
  • Secure AI-Driven Development: Webinar Insights
  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Malicious Extension Mimics Google Translate, Compromises Browsers
  • OpenAI’s Astra Sparks Cybersecurity Worries
  • Secure AI-Driven Development: Webinar Insights
  • CEVA Logistics Breach Exposes Steam Hardware Buyers
  • Stealthium Enhances Security for AI Accelerators and Neo-Clouds

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark