LastPass Confirms Data Breach in Klue Supply Chain Attack
ID: 71410b5e-040e-5466-aeab-1e76ef6be5dd
STIX ID: report--71410b5e-040e-5466-aeab-1e76ef6be5dd
Feed Name: CosmicBytez Labs
## Executive summary LastPass and Klue confirmed a supply‑chain breach by the extortion group Icarus, which used a compromised legacy Klue credential to deploy malicious code that harvested OAuth tokens and mass-extracted Salesforce CRM data from hundreds of customers; exposed data included contact details, sales notes, and support case information. Affected organizations were notified, integrations and tokens were revoked, and recommended actions include rotating OAuth/API credentials, auditing Salesforce API access between June 11–17, 2026, and briefing staff on heightened phishing/extortion risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
