Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

LastPass Hit by Third-Party Data Breach: What You Need to Know About the Klue Incident

Posted on June 25, 2026June 25, 2026 by Martin Brinkmann

Anyone still using LastPass? If so, you need to be aware about a new security incident that has been confirmed by the company this week.

In the modern SaaS ecosystem, a digital fortress is only as secure as the side door left open for third-party vendors. Password management firm LastPass has disclosed a new data breach that involved the intelligence platform Klue.

According to an official incident report published on the LastPass blog, threat actors recently compromised Klue’s systems to steal OAuth tokens, granting them unauthorized access to LastPass’s Salesforce environment.

What the Attackers Obtained

The threat actors compromised Klue’s systems to steal OAuth tokens, which they then used to access LastPass’s Salesforce environment. The exposed data was limited to standard CRM and business contact information:

  • Customer names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Support case data
  • Sales-related data

What They Did NOT Obtain

The core architecture of LastPass remained unbreached. The attackers did not gain access to:

  • Customer Vaults: All stored passwords, secure notes, and saved data remained encrypted and secure
  • Master Passwords: Because of LastPass’s zero-knowledge architecture, master passwords are never known or stored by the company, and they were not exposed here.
  • Core Systems: LastPass products, services, and primary infrastructure were entirely unaffected

LastPass reveals that the information can be used for phishing attacks and other social engineering attempts. It recommends that “customers remain vigilant” and “exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information.”.

For LastPass users suffering from breach fatigue, this latest headline likely induces a familiar sense of dread. However, when put into perspective, the Klue incident is a far cry from the devastating, back-to-back breaches of 2022, where threat actors successfully made off with encrypted customer vault backups and proprietary source code.

Still, while this is fundamentally a story about a third-party CRM leak rather than a critical product failure, the stolen contact information arms hackers with exactly what they need to launch highly convincing phishing campaigns.

Tags:
Category: Security & Privacy

Post navigation

← System Restore Evolved: Windows 11 Point-in-Time Restore Hits General Availability

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • June 25, 2026 by Martin Brinkmann LastPass Hit by Third-Party Data Breach: What You Need to Know About the Klue Incident
  • June 24, 2026 by Martin Brinkmann System Restore Evolved: Windows 11 Point-in-Time Restore Hits General Availability
  • June 22, 2026 by Martin Brinkmann Microsoft is migrating OneDrive and Sharepoint to cloud.microsoft
  • June 20, 2026 by Martin Brinkmann Microsoft confirms Windows 11 version 26H2 officially
  • June 18, 2026 by Martin Brinkmann The Gog Summer Sale is here making it a great time to catch-up on classic games

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews