[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fh0ur9EAXp1Wwg-1irlPvaBnbr3LuHQ3Jk2upv3ti0k0":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":25,"source":26,"isVerified":4,"isSpamList":27,"isSensitive":4,"severity":28,"processingStatus":29,"logoUrl":30,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a669b9399dbebb40fd85a9a","LastPassKlue2026","LastPass 2026 Klue Tedarik Zinciri Data Breach","lastpass-klue-2026","lastpass.com",{"name":12,"sector":13,"country":14,"website":10},"LastPass","Cybersecurity","United States","2026-06-12T00:00:00.000Z","2026-07-26T23:43:15.886Z",0,[19,20,21,22,23,24],"Customer names","Phone numbers","Email addresses","Physical addresses","Support case data","Sales and CRM data","\u003Cp>\u003Cstrong>The LastPass 2026 Klue data breach\u003C\u002Fstrong> is a supply-chain incident in which OAuth tokens stolen from third-party market-intelligence provider Klue were used to access LastPass customer data. LastPass learned of the Klue incident on June 12, 2026 and confirmed that an unauthorized actor used OAuth credentials Klue held for LastPass to enter the company's Salesforce environment and access customer information.\u003C\u002Fp>\n\u003Cp>LastPass's official incident statement is the primary source, and BleepingComputer independently reported the disclosure and Klue supply-chain context. The accessed scope includes customer names, phone numbers, email addresses, physical addresses, support-case data, and sales-related CRM information. Because the company published no affected-person or record count, LeakData keeps pwnCount at zero to represent an unknown total.\u003C\u002Fp>\n\u003Ch2>The Klue and OAuth Access Chain\u003C\u002Fh2>\n\u003Cp>Klue was a third-party platform used by LastPass go-to-market teams and integrated with Salesforce and Gong. According to LastPass, an unauthorized actor obtained OAuth tokens that Klue held for many customers. The actor used LastPass's credentials to access its Salesforce environment. The chain began with abuse of a trusted integration identity rather than an initial intrusion into LastPass's password-management product infrastructure.\u003C\u002Fp>\n\u003Cp>An OAuth token is not necessarily a password; it is a credential allowing an integrated application to access an API or service within previously granted permissions. Theft can let an actor operate within that allowed scope. LastPass did not disclose every Salesforce object, support case, or sales record opened, the first date of unauthorized access, or the amount of data copied.\u003C\u002Fp>\n\u003Ch2>Accessed Customer Data\u003C\u002Fh2>\n\u003Cp>The official statement describes the information as standard business-contact and customer-relationship-management data. Enumerated fields are customer names, phone numbers, email addresses, and physical addresses, together with support-case and sales-related data. LastPass did not say that every field existed for every customer or that every support case was accessed. LeakData limits its classes to these published categories.\u003C\u002Fp>\n\u003Cp>Support-case content can vary, and the company did not separately confirm message bodies, attachments, technical logs, or other specific fields. Passwords, master passwords, vault contents, payment data, and identity documents are therefore not added merely because they could theoretically appear in an unrelated support record. Customer scale, support-case totals, and the overall LastPass user count cannot substitute for a breach count.\u003C\u002Fp>\n\u003Ch2>Unaffected Products and Vaults\u003C\u002Fh2>\n\u003Cp>LastPass said the scope was limited to systems integrated with Klue and that LastPass products, services, and infrastructure were not affected in any way. Customer password vaults remained secure. This finding does not negate the confirmed access to Salesforce customer information; it places the event outside the core password-manager and encrypted vault-content environment.\u003C\u002Fp>\n\u003Cp>The investigation found no evidence that the actor accessed Gong-related data. Because Gong can contain customer calls and email content, that distinction is important. “No evidence” is the published investigative finding and means Gong data should not be listed as confirmed. No evidence was presented that LastPass master passwords, stored site passwords, or decryption keys were obtained.\u003C\u002Fp>\n\u003Ch2>LastPass's Response\u003C\u002Fh2>\n\u003Cp>LastPass discontinued all employee access to Klue, rotated the exposed API and OAuth tokens, and began a detailed investigation with contacts at Klue and Salesforce. It notified law enforcement and said it was cooperating. Direct remediation through token rotation was completed, while work continued on additional safeguards and stronger protocols to defend against similar third-party incidents.\u003C\u002Fp>\n\u003Cp>The company's threat-intelligence team said it was sharing tactics, techniques, and procedures with the wider security community to disrupt the campaign and support defenders. LastPass also published four IP addresses and three sender domains as indicators. Indicators can change over time and cannot by themselves prove that every message is malicious or safe.\u003C\u002Fp>\n\u003Ch2>Phishing and Social-Engineering Risk\u003C\u002Fh2>\n\u003Cp>Names, telephone numbers, emails, addresses, and support-case context can support highly convincing messages impersonating LastPass support. An actor might cite a real case or sales relationship and request a master password, multi-factor code, or login through a fake page. LastPass emphasized that nobody at the company will ask for a master password and that customers should trust only official support channels.\u003C\u002Fp>\n\u003Cp>Customers can verify unexpected calls, emails, and sensitive-information requests through a known LastPass support channel rather than a link or number in the message. The finding that vaults were unaffected does not automatically require changing every password stored in a vault. If information was entered on a suspicious page, however, the master password and affected account credentials should be replaced through the official application.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>This is not a direct compromise of LastPass's core password-manager infrastructure; it is access to Salesforce customer data using integration tokens stolen from Klue. A zero-person value means no verified total was disclosed, not that no customer was affected. Other Klue customer incidents are not added to this LastPass pwnCount, and LastPass's overall customer population is not used as scope.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that OAuth tokens held by Klue were obtained, names, phones, emails, addresses, support cases, and sales data in Salesforce were accessed, the tokens were rotated, and Klue access was discontinued. LastPass products, infrastructure, and password vaults were unaffected, and no evidence showed Gong access. Exact access timing, person count, record volume, and each case's contents remain undisclosed.\u003C\u002Fp>","Klue OAuth supply-chain breach",false,"Low","completed","\u002Fuploads\u002Flogo\u002Flastpass_com.svg"]