Breach tracker

Breach report

LastPass says customer contact and support data was taken via Klue breach

ConfirmedDisclosed Updated United StatesTechnologyBy Vivek Kumar
Records UnknownCause Data theftAttributed / claimed Icarus
Conceptual illustration: Anonymous customer support tickets and a headset with small data fragments in the foreground; a securely closed, intact vault stays protected in the background. Headline: LASTPASS SUPPORT DATA.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

An attacker used OAuth tokens held by market-research vendor Klue to pull LastPass customer data from Salesforce. LastPass says vaults and its own systems were not affected.

What happened

Klue, a Vancouver-based market-intelligence company, says it identified unauthorised activity on 12 June 2026. An attacker used a compromised legacy credential tied to an integration service to obtain OAuth tokens (the access keys that let Klue connect to customers' cloud tools) and then read data inside connected customer environments, including Salesforce. LastPass was one of those customers. It told affected people that the attacker used the tokens to reach LastPass customer data in its Salesforce environment.

Confirmed vs. claimed

Confirmed by LastPass: customer names, phone numbers, email addresses and physical addresses were taken, along with support case and sales-related data. LastPass says its products and infrastructure were not affected and customer password vaults remain secure. It cut staff access to Klue and rotated exposed tokens.

Claimed: the Icarus extortion group took credit for the Klue breach and threatened to publish stolen data, according to TechCrunch. LastPass has not said how many customers are affected or what the support tickets contained.

Who is affected

LastPass customers who appear in its sales or support records, including those who opened support cases. LastPass has users worldwide, including in India. Other Klue customers, including several security firms, reported similar losses.

What to do

  • Expect phishing that mentions a past LastPass support case. LastPass says no one from the company will ever ask for your master password.
  • Do not install software or approve login prompts because of an unexpected call or email about your account.
  • If a support ticket held anything sensitive, such as a screenshot or recovery detail, change that credential.
  • Keep a long, unique master password and multi-factor authentication (MFA) on your vault.
  • See our guide on what to do after a data breach notice.

Sources

More breaches in United States