LastPass Says Klue Supply Chain Attack Let Hackers Access Salesforce Customer CRM Data
Image: TechCrunch

LastPass Says Klue Supply Chain Attack Let Hackers Access Salesforce Customer CRM Data

23 June, 2026.Technology and Science.10 sources

The story in 15 seconds

  • OAuth tokens stolen from Klue allowed unauthorized access to LastPass Salesforce
  • Customer contact details and CRM data exposed in LastPass Salesforce environment
  • Core vaults and passwords remained secure; only CRM data was exposed

The divide · 1 of 3

What Klue breach entry mechanism was reported

Both emphasize legacy-credential access; differences would matter if entry vector differed.

Who skipped what

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
10 sources
Other
6
Western Alternative
1
Asian
1
Local Western
1
Western Mainstream
1

Western Alternative

AppleInsider
AppleInsider

LastPass user data stolen by hackers again

23 June, 2026

Other

BleepingComputer
BleepingComputer

LastPass confirms data breach in Klue supply chain attack

23 June, 2026

Cyber Press
Cyber Press

LastPass Confirms Customer CRM Data Accessed in Klue Supply Chain Incident

23 June, 2026

Cybersecurity Dive
Cybersecurity Dive

Klue investigating supply chain attack that targeted Salesforce integrations

23 June, 2026

CyberSecurityNews
CyberSecurityNews

LastPass Customer Data Exposed in Klue Supply Chain Attack

23 June, 2026

Hackread
Hackread

LastPass Confirms Customer Data Breach After Klue OAuth Token Theft

23 June, 2026

SQ Magazine
SQ Magazine

LastPass Warns of Data Exposure in Klue Supply Chain Hack

23 June, 2026

Asian

Firstpost
Firstpost

LastPass discloses theft of customer support records following partner breach

23 June, 2026

Local Western

mezha.net
mezha.net

LastPass confirms data theft after Klue security breach

23 June, 2026

Western Mainstream

TechCrunch
TechCrunch

Password manager maker LastPass says hackers stole customer support case data during Klue breach

23 June, 2026

Full story

Klue OAuth Breach

LastPass confirmed that a supply chain attack involving its third-party vendor Klue led an unauthorized actor to use stolen OAuth tokens to access customer data stored in its Salesforce environment.

LastPass has confirmed it was affected by theKlue supply chain incident

HackreadHackread

LastPass said it learned of the Klue incident on June 12, 2026, after Klue notified customers about unauthorized activity, and it said the exposed data was limited to customer relationship management information inside Salesforce.

Image from AppleInsider
AppleInsiderAppleInsider

The company said the exposed information included customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related records, while LastPass products, services, infrastructure, and customer vaults were not affected.

In a statement quoted by BleepingComputer, LastPass said, "On June 12th, LastPass was made aware of an incident that occurred at Klue (klue.com)," and it added that the threat actor then used the credentials to access LastPass customer data within its Salesforce environment.

Icarus Extortion

Multiple outlets tied the Klue breach to a threat actor named Icarus, with TechCrunch reporting that Icarus took credit and threatened to release stolen data if a ransom wasn’t paid.

TechCrunch also reported that LastPass said the breach occurred at market research firm Klue, and not its own systems, while hackers abused their access to obtain reams of data about LastPass customers.

Image from BleepingComputer
BleepingComputerBleepingComputer

LastPass said it launched an investigation and learned that an unauthorized actor was able to obtain OAuth tokens Klue held for many of its customers, including LastPass, and BleepingComputer quoted LastPass describing how the threat actor then used these credentials to access LastPass customer data within its Salesforce environment.

The incident was described as affecting systems integrated with Klue, and Hackread said Salesforce disabled Klue Battlecards’ integration infrastructure on June 17, 2026, after detecting unusual activity involving the app’s connection to Salesforce.

What’s at Risk Next

LastPass warned that exposed contact details and CRM records could be used in phishing and social engineering attacks, and it advised customers to remain cautious of unsolicited communications.

LastPass advised caution around phishing andsocial engineering attempts

HackreadHackread

Hackread said LastPass reminded users that LastPass staff will never ask for a master password and that official support communication should come through trusted LastPass channels.

BleepingComputer similarly said attackers may leverage the exposed data in phishing and social engineering attacks, and it reiterated that the master password should not be shared with anyone.

Beyond LastPass, Cybersecurity Dive reported that the Klue attack led to mass exfiltration of Salesforce customer relationship management data belonging to hundreds of customers, including several prominent cybersecurity firms, and it said Salesforce disabled connections through the Klue Battlecards app until further notice.

NewsCord Digest

Get every Technology and Science story like this one, in one email

Daily or weekly, only the topics you follow, each with the difference our analysis found across the outlets covering it.

Set up your digest

More on Technology and Science