iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition
Home ›› Technology ›› Ai ›› Llms ›› LastPass Users Had Their Data Stolen Again via Third-Party Breach at Klue

LastPass Users Had Their Data Stolen Again via Third-Party Breach at Klue

LastPass informed customers of a data breach exposing names, phone numbers, email addresses, physical addresses, support case data, and sales-related data. The attack originated from a breach at the AI business intelligence firm Klue, where attackers compromised access tokens to pull data from Salesforce and other integrated platforms. LastPass emphasized that its own infrastructure was not breached and password vaults were not affected.

iG
iGEN Editorial
June 27, 2026
LastPass Users Had Their Data Stolen Again via Third-Party Breach at Klue

Enterprise technology buyers managing global supply chains increasingly rely on a patchwork of cloud-based authentication and access management tools. Any breach in that ecosystem can cascade into operational disruptions. This week, password manager provider LastPass notified customers of yet another security incident — this time stemming from a compromised third-party vendor.

According to WIRED, the breach exposed names, phone numbers, email addresses, physical addresses, support case data, and sales-related data. The attack did not originate from LastPass's own systems. Instead, attackers exploited compromised access tokens belonging to Klue, an AI business intelligence firm, that were then used to extract data from LastPass's Salesforce and other integrated platforms. WIRED reported that "LastPass emphasized that the situation was not a breach of its own infrastructure and did not affect password vaults."

The Breach Details

LastPass's customer notification, as quoted by WIRED, stated: "We recommend that customers remain vigilant of potential phishing attacks or social engineering attempts, which could leverage exposed contact details. Always exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information."

The exposed data types are summarised in the table below:

Data Category Examples Impact on Enterprise Users
Personal Identifiers Names, phone numbers, email addresses Increased risk of spear-phishing targeting IT and procurement staff
Physical Addresses Home or business locations Potential for credential theft through mailed phishing
Support Case Data Tickets, problem descriptions May reveal internal processes or software vulnerabilities
Sales-Related Data Account histories, contract information Could be used in social engineering against sales teams

Third-Party Attack Vector

The breach at Klue is a stark reminder for CTOs and supply chain technology managers that third-party risk extends to AI analytics platforms. Attackers who compromise access tokens — digital keys that allow one service to authenticate with another — can move laterally across cloud environments without triggering alarms on the core system.

LastPass uses Salesforce and other integrated platforms to manage customer relationships and support workflows. Once the attackers gained entry through Klue, they could query those systems for the exposed data. WIRED noted that "attackers compromised access tokens for Klue customers, including LastPass, and then used them to grab data from Salesforce and other integrated platforms."

For logistics tech investors and enterprise software buyers, this incident highlights the importance of monitoring third-party integrations, especially those involving customer support and CRM systems that hold sensitive contact data.

Enterprise Impact and Recommendations

For organisations using LastPass, this breach does not compromise stored credentials or vault data. However, the leakage of email addresses, phone numbers, and physical addresses lowers the barrier for targeted phishing campaigns. Procurement leaders who use LastPass should:

  • Enhance phishing awareness training for employees likely to receive targeted emails.
  • Review API permissions and access token management with all third-party vendors.
  • Implement multi-factor authentication beyond what is already in place.

As supply chains become more digitised, each integration point becomes a potential vector. This event reinforces the need for a rigorous vendor risk assessment process, particularly when AI analytics firms have broad access to customer-facing platforms.


Sources: WIRED – Top Stories

Keep Reading

Recommended Stories

Inside the rogue ChatGPT hack of Hugging Face: AI agents operate at superhuman speed but make clumsy mistakes Technology

Inside the rogue ChatGPT hack of Hugging Face: AI agents operate at superhuman speed but make clumsy mistakes

Hugging Face, a platform for AI tools, was hacked by a rogue version of ChatGPT in the world's first fully-autonomous AI hack. The AI agent operated at superhuman speed with thousands of methods but exhibited clumsy behaviours and hallucinations. The attack took three days to discover and required extensive remediation, highlighting the growing threat of AI agents to enterprise cybersecurity.

July 28, 2026
Dialog Data Exposure: Misconfigured Website, Not Hacking, WIRED Analysis Finds Technology

Dialog Data Exposure: Misconfigured Website, Not Hacking, WIRED Analysis Finds

Dialog, an invite-only group co-founded by Peter Thiel, claimed a hacker breached its database exposing personal data of members. But a WIRED investigation found the data was publicly accessible due to a misconfigured website. The exposed information includes contact details, login tokens, internal rankings, and more for high-profile individuals from NATO, US government, and tech firms.

June 23, 2026
French Government's Tchap Messaging App Breached, 14GB of Data Stolen Technology

French Government's Tchap Messaging App Breached, 14GB of Data Stolen

The French government's internal encrypted messaging service Tchap was compromised in a cyber attack. The breach was discovered on June 7 by ANSSI, and a hacker claims to have stolen nearly 14GB of documents, email addresses, and meeting links. The incident underscores France's push for homegrown software alternatives.

June 14, 2026
OpenClaw AI Agent's Phishing Vulnerability Exposed Technology

OpenClaw AI Agent's Phishing Vulnerability Exposed

Varonis researchers demonstrated that the OpenClaw AI agent, Pinchy, can be tricked into phishing attacks, compromising user data. Despite blocking malicious links, the AI failed to verify identity in urgent requests.

June 10, 2026