LastPass data breach confirmed: Everything we know so far

0
63

LastPass data breach confirmed: Everything we know so far

A security breach at a third-party vendor has exposed customer data belonging to LastPass, the company confirmed this week, in the latest incident to put the beleaguered password manager back in the spotlight.

LastPass confirmed this week that hackers gained access through a company called Klue, a market intelligence tool that LastPass uses internally to track competitors and manage sales relationships. According to LastPass, an unauthorized actor obtained OAuth tokens that Klue held on behalf of its customers and used them to access LastPass customer data within its Salesforce environment.

The exposed information was limited to names, phone numbers, email addresses, physical addresses, and sales-related records. LastPass was emphatic that its core products and customer vaults, meaning passwords, were not affected.

Mashable Light Speed

The breach was not limited to LastPass. As BleepingComputer reported, a newly emerged extortion group calling itself Icarus has publicly claimed responsibility for the attack, describing it as a broad operation targeting multiple Klue customers. According to BleepingComputer's reporting, cybersecurity firms Huntress and ReliaQuest found that attackers exploited a compromised legacy credential to obtain OAuth tokens, then used Python scripts to query Salesforce's API and conduct large-scale data theft across numerous organizations. Confirmed victims include Recorded Future, Tanium, Jamf, Sprout Social, and Gong, among others.

Icarus is reportedly pressuring affected companies to make contact via the Session messaging platform or risk having their stolen data published.

LastPass says it has revoked Klue's access, notified law enforcement, and is cooperating with the broader security community through its internal threat intelligence team.

The company urged customers to remain alert to phishing and social engineering attempts that could exploit the exposed contact data. It reminded users that LastPass will never ask for a master password.

Cerca
Categorie
Leggi tutto
Altre informazioni
Key Trends Influencing the Automatic Colon Hydrotherapy Machine Market in the United States
The United States Automatic Colon Hydrotherapy Machine Market holds the largest share...
By Shubham Choudhry 2026-06-18 12:38:52 0 242
Giochi
Battlefield 6 Season 2 is well-packed with additions, but it's missing the killer element to lure me back in
Battlefield 6 Season 2 is well-packed with additions, but it's missing the killer element to lure...
By Test Blogger6 2026-02-12 18:00:15 0 2K
Giochi
The Batman adventures that defined a generation are now 87% off and you don't even need your Bat-Steam key discount spray - but you do need to be fast
The Batman adventures that defined a generation are now 87% off and you don't even need your...
By Test Blogger6 2026-02-21 09:00:12 0 2K
Altre informazioni
Substance Abuse and Addiction Treatment Market Size, Share, and Growth Opportunities 2025 –2032
 According to the latest report published by Data Bridge Market...
By Pooja Chincholkar 2026-06-09 05:20:24 0 288
Giochi
The next Diablo 4 class reveal has a date, but it's the promise of something new for D2 Resurrected that has me smiling
The next Diablo 4 class reveal has a date, but it's the promise of something new for D2...
By Test Blogger6 2026-02-06 18:00:37 0 2K