Skip to content

LastPass

Disclosed Jun 23, 20263 months agoConfirmed

Official notice

LastPass support case data stolen via Klue OAuth tokens

LastPass said attackers used OAuth tokens stolen in the Klue breach to access its Salesforce environment and take customer contact details and support case data. Vaults and core products were not affected.

What is known

People affectedNot stated in the sources we have
DisclosedJun 23, 2026
AttackSupply chain
Data exposedNames, Phone numbers, Emails, Addresses, Messages
SectorTech · US
StatusConfirmed
Part ofKlue (2026)

Sources

Source
Klue supply chain incident and LastPass responseblog.lastpass.com · Official notice
LastPass confirms data breach in Klue supply chain attackbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalJun 23

Same campaign

OrganizationAffected
8x88x8 says Klue integration abused to exfiltrate Salesforce customer dataJun 233 months agoSupply chainUnknown
KlueKlue legacy credential breach leads to OAuth token theft and Salesforce raidsJun 193 months agoSupply chainUnknown

Other breaches at LastPass

BreachAffected
Attacker steals LastPass customer vault backups after earlier dev breachNov 30, 20223 years agoHacking1.6M
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about LastPass

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.