Briefing

LastPass Warns Users of Data Breach via Partner Klue

security
by mooreds ·

Patch exposed API tokens and revoke partner access immediately.

What to do now

Patch exposed API tokens and revoke partner access immediately.

Summary

LastPass has notified users of a data breach that occurred through its partner, market‑research firm Klue, which allowed hackers to access customer information and support case data.

The breached data included standard business contact information and CRM data such as customer names, phone numbers, email addresses, physical addresses, support case data, and sales‑related data.

Upon discovering the incident, LastPass revoked employee access to Klue, rotated exposed API tokens, notified law enforcement, and launched a detailed investigation in collaboration with Klue and Salesforce.

LastPass recommends that customers remain vigilant for potential phishing attacks or social engineering attempts that could leverage the compromised information.

The breach also revealed a list of IP addresses (138.226.246.94, 94.154.32.160, 159.183.215.61, 159.183.181.239) and email sender domains (baccarat.com.au, robinskitchen.com.au, house.com.au) that could be used to search for related activity.

This incident follows previous security events: a 2015 breach that exposed account emails, password reminders, authentication hashes, and cryptographic salts, and a 2022 breach that compromised a developer account, source code, and cloud backups containing customer records.

LastPass emphasizes that encrypted vault data was not accessed during the 2015 breach and that the 2022 breach involved unencrypted details such as names, billing addresses, email addresses, and phone numbers.

The company is conducting a thorough investigation and will provide updates as more information becomes available.

Key changes

  • Breach occurred through partner Klue, exposing CRM data
  • LastPass revoked employee access to Klue and rotated API tokens
  • Company notified law enforcement and launched investigation
  • IP addresses and email sender domains were disclosed
  • Previous 2015 breach exposed authentication hashes and salts
  • 2022 breach compromised developer account and cloud backups

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting