LastPass Confirms Customer Data Breach After Klue OAuth Token Theft

https://hackread.com/wp-content/uploads/2026/06/klue-lastpass-data-breach-1024x576.jpg

LastPass has confirmed it was affected by the Klue supply chain incident, saying an unauthorised actor used stolen OAuth tokens from the third-party market intelligence platform to access customer data stored in its Salesforce environment.

The company said it learned of the Klue incident on June 12, 2026, after Klue, a market intelligence platform used by LastPass go-to-market teams, notified customers about unauthorised activity. Klue integrates with business tools, including Salesforce and Gong, which made the stolen tokens valuable because they could be used to reach connected customer systems without needing normal login credentials.

According to LastPass, the exposed data was limited to customer relationship management information inside Salesforce. This included customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related records. The company said LastPass products, services, infrastructure, and customer vaults were not affected.

The incident follows earlier reportingthat Salesforce disabled Klue Battlecards’ integration...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more