Published

LastPass Says Klue Supply Chain Attack Let Hackers Access Salesforce Customer CRM Data
Image: TechCrunch

Technology and Science · 23 June, 2026 · 2 min read

LastPass Says Klue Supply Chain Attack Let Hackers Access Salesforce Customer CRM Data

Happened

OAuth tokens stolen from Klue allowed unauthorized access to LastPass Salesforce Customer contact details and CRM data exposed in LastPass Salesforce environment

Split on

What Klue breach entry mechanism was reported.

Left out

8 of 10 outlets skipped it: lastPass published IOCs including IPs and malicious sender domains..

10outlets compared

AppleInsiderBleepingComputerCyber PressCybersecurity DiveCyberSecurityNewsFirstpostHackreadmezha.net

Same story, two versions

tap a side to read it in full

AppleInsiderAppleInsider

someone gained access through a compromised legacy credential tied to an integration service.
Read the original

BleepingComputerBleepingComputer

gained access to Klue's infrastructure using compromised legacy credentials for an integration service.
Read the original
VS

Both emphasize legacy-credential access; differences would matter if entry vector differed.

Klue OAuth Breach

LastPass confirmed that a supply chain attack involving its third-party vendor Klue led an unauthorized actor to use stolen OAuth tokens to access customer data stored in its Salesforce environment. LastPass said it learned of the Klue incident on June 12, 2026, after Klue notified customers about unauthorized activity, and it said the exposed data was limited to customer relationship management information inside Salesforce.

The company said the exposed information included customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related records, while LastPass products, services, infrastructure, and customer vaults were not affected. In a statement quoted by BleepingComputer, LastPass said, "On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com)," and it added that the threat actor then used the credentials to access LastPass customer data within its Salesforce environment.B

Image from AppleInsider
AppleInsiderAppleInsider

Icarus Extortion

Multiple outlets tied the Klue breach to a threat actor named Icarus, with TechCrunch reporting that Icarus took credit and threatened to release stolen data if a ransom wasn’t paid. TechCrunch also reported that LastPass said the breach occurred at market research firm Klue, and not its own systems, while hackers abused their access to obtain reams of data about LastPass customers.

LastPass said it launched an investigation and learned that an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass, and BleepingComputer quoted LastPass describing how the threat actor then used these credentials to access LastPass customer data within its Salesforce environment. BThe incident was described as affecting systems integrated with Klue, and Hackread said Salesforce disabled Klue Battlecards’ integration infrastructure on June 17, 2026, after detecting unusual activity involving the app’s connection to Salesforce.

Image from BleepingComputer
BleepingComputerBleepingComputer

What’s at Risk Next

LastPass warned that exposed contact details and CRM records could be used in phishing and social engineering attacks, and it advised customers to remain cautious of unsolicited communications. Hackread said LastPass reminded users that LastPass staff will never ask for a master password and that official support communication should come through trusted LastPass channels.

BleepingComputer similarly said attackers may leverage the exposed data in phishing and social engineering attacks, and it reiterated that the master password should not be shared with anyone. BBeyond LastPass, Cybersecurity Dive reported that the Klue attack led to mass exfiltration of Salesforce customer relationship management data belonging to hundreds of customers, including several prominent cybersecurity firms, and it said Salesforce disabled connections through the Klue Battlecards app until further notice.