logo

LastPass Confirms Data Breach in Klue Supply Chain Attack

ID: 71410b5e-040e-5466-aeab-1e76ef6be5dd

STIX ID: report--71410b5e-040e-5466-aeab-1e76ef6be5dd

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

## Executive summary LastPass and Klue confirmed a supply‑chain breach by the extortion group Icarus, which used a compromised legacy Klue credential to deploy malicious code that harvested OAuth tokens and mass-extracted Salesforce CRM data from hundreds of customers; exposed data included contact details, sales notes, and support case information. Affected organizations were notified, integrations and tokens were revoked, and recommended actions include rotating OAuth/API credentials, auditing Salesforce API access between June 11–17, 2026, and briefing staff on heightened phishing/extortion risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.