READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

LastPass Customer Contact Data Stolen in Breach of Third-Party Vendor Klue

LastPass Customer Contact Data Stolen in Breach of Third-Party Vendor Klue
Ransomware group Icarus breached Klue, a market research platform, and stole OAuth tokens that unlocked customer data stored in Salesforce. LastPass users had names, phone numbers, email addresses, and physical addresses exposed. No master passwords or password vaults were taken.

What Got Stolen

LastPass disclosed in a blog post this week that a breach at third-party vendor Klue exposed contact and CRM data belonging to LastPass customers. The stolen information includes names, phone numbers, email addresses, physical addresses, and support and sales-related records, according to ZDNet's reporting on the disclosure.

The attackers did NOT get master passwords or password vaults. LastPass has been clear about this distinction.

How It Happened

Klue is a market research platform LastPass used to connect its Salesforce and Gong systems. The attackers obtained the OAuth security tokens Klue used to authenticate across those platforms. With those tokens in hand, they pulled LastPass customer data directly out of Salesforce.

Klue said it discovered the breach on June 12, according to ZDNet. Since then, Klue has been working with cybersecurity experts to assess the damage and restore compromised connections.

LastPass's response included cutting off all employee access to Klue, refreshing the exposed tokens, launching an investigation with Klue and Salesforce, and notifying law enforcement.

LastPass Was Not Alone

This was not a targeted LastPass attack. Klue is a shared vendor, and the breach hit a wide range of companies. According to TechCrunch's reporting cited by ZDNet, other victims include Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Sprout Social, and Tanium.

Ransomware group Icarus has claimed responsibility and threatened to publish the stolen data if Klue does not pay a ransom. No source in this reporting confirms whether Klue has paid or refused.

LastPass's History With Security

LastPass has had a rough few years on security. The company suffered a significant breach in 2022 in which encrypted password vault data was taken, a far more serious incident than this one. That history is why any new LastPass breach headline gets outsized attention, and fairly so.

The data exposed this time is contact information, not credentials. Someone with your name, email, and phone number cannot log into your accounts. The vault encryption that protects your actual passwords was not touched.

The Legitimate Concern

Contact data in the hands of a ransomware group is not harmless. Stolen names, phone numbers, and email addresses are exactly what sophisticated phishing and social engineering attacks are built on. An attacker who knows you are a LastPass customer, has your phone number, and knows you have an open support case has a credible pretext to call you, impersonate LastPass support, and talk you into handing over your master password directly. That threat does not require cracking any encryption.

This is a documented tactic, and the exposed data is purpose-built for it.

What LastPass Users Should Do

According to ZDNet, LastPass has been sending breach notification emails to affected customers. If you use LastPass and have not received one, check your spam folder.

Be skeptical of any inbound contact, by phone, email, or text, that references your LastPass account, a support ticket, or account security. LastPass will not call you unsolicited and ask for your master password. No legitimate company will.

ZDNet also recommends considering a master password change as a precaution, even though the vaults were not compromised. That is a reasonable step.

Unanswered Questions

The story leaves open how many LastPass customers were actually affected and whether Icarus follows through on publishing the data. Klue has not disclosed the scope of the breach in terms of total records. As of June 24, 2026, no source confirms whether a ransom was paid or whether stolen data has been released. If Icarus publishes, the phishing risk goes from theoretical to immediate.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ZDNETLastPass hit by new data breach - 4 steps you should take now