LastPass Customer Data Exposed in Klue Supply Chain Attack
ID: 6b659e25-cb77-543d-8457-14f9c58a923b
STIX ID: report--6b659e25-cb77-543d-8457-14f9c58a923b
Feed Name: cybersecurityNews.com
LastPass disclosed a supply-chain security incident stemming from its third-party vendor Klue, where stolen OAuth tokens were used to access LastPass' Salesforce instance and exfiltrate customer CRM data (names, emails, phone numbers, addresses, support and sales records). The company states core products and password vaults were not affected, has revoked Klue access and rotated tokens, engaged Klue/Salesforce and law enforcement, and published IOCs (several IPs and suspicious sender domains) while warning customers to be wary of phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
