LastPass is alerting customers after hackers accessed business contact details and support case records through Klue, a third-party market intelligence platform. The company says its own products, infrastructure, and customer password vaults were not affected.
TL;DR
- LastPass said hackers used exposed Klue OAuth tokens to access customer data in its Salesforce environment.
- The stolen data may include names, phone numbers, email addresses, physical addresses, support case data, and sales-related data.
- LastPass said customer vaults remain secure and its core infrastructure was not impacted.
How The Klue Breach Exposed LastPass Customer Support Data
Password manager company LastPass has confirmed that customer information was accessed during a wider breach at Klue, one of its third-party suppliers. According to LastPass, the incident originated at Klue, a market intelligence platform used by its go-to-market teams and integrated with its Salesforce and Gong systems.
LastPass said it was made aware of the incident on June 12 and immediately began investigating the matter. The company found that an unauthorized actor had obtained OAuth tokens held by Klue for multiple customers, including LastPass, and then used those credentials to access LastPass customer data within Salesforce.
The exposed information was limited to standard business contact details and customer relationship management data. This includes customer names, phone numbers, email addresses, physical addresses, customer support case data, and sales-related data.
LastPass Says Password Vaults And Core Systems Were Not Hit
The biggest concern for users of any password manager is whether stored credentials are at risk. On that front, LastPass said the scope of the breach was limited to systems connected to Klue’s application.
“It is important to note that the scope of this incident is limited to only those systems that integrate with Klue’s application. LastPass products, services, and infrastructure were not impacted in any way and customer vaults remain secure. There is also no evidence the threat actor accessed any Gong-related data,” the company said in its official release.
LastPass also said there is no evidence that the threat actor accessed Gong-related data. The company has rotated the exposed Klue OAuth tokens and discontinued employee access to Klue as part of its remediation.
What Customers Should Watch For After The LastPass Data Breach
While vaults were not affected, support case data could still carry risk. Customer support tickets often include details tied to billing, account access issues, or other sensitive conversations, which can make exposed CRM data useful for phishing or social engineering attempts.
LastPass has advised customers to remain cautious about unsolicited messages, calls, or requests for sensitive information. The company also reminded users: “Please remember that no one at LastPass will ever ask for your master password.”
Topics For More Insights
Why This Incident Adds Pressure On LastPass
The Klue incident adds another cybersecurity concern for LastPass after its major 2022 breach, when hackers stole encrypted customer password vaults. Although those vaults were protected by master passwords, attackers could attempt offline brute-force attacks against weaker passwords.
LastPass says it has notified law enforcement and is working through its Threat Intelligence, Mitigation, and Escalation team to share intelligence with the wider security community. The company says it is also adding safeguards to reduce the risk of similar third-party incidents.

