LastPass customer data exposed through Klue supply chain attack
ID: cbc82368-ce7b-5b26-b9fe-088119340a9d
STIX ID: report--cbc82368-ce7b-5b26-b9fe-088119340a9d
Feed Name: Help Net Security
Threat Score
LastPass disclosed that compromised OAuth tokens from a third-party market intelligence platform, Klue, were used to access customer CRM data in its Salesforce environment; exposed information included business contact details and sales/support records. Multiple security vendors were affected, an extortion group (Icarus) claimed responsibility, and LastPass revoked access, rotated tokens, and published indicators of compromise while investigating with Klue and law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
