Editor's note: Sources report dates in 2026, presenting an unexplained temporal anomaly; DeafNews reports them as they appear in the original sources.
LastPass publicly disclosed an indirect data breach on June 24, 2026. The intrusion did not hit the company's systems directly, but those of Klue, an external vendor specializing in market research and customer relationship management. The Icarus criminal group claimed responsibility for the operation, which exposed personal data but not password vaults.
- The breach is indirect: the attack targeted Klue, a LastPass vendor, not the password manager's internal systems.
- Exposed data includes names, email addresses, phone numbers, physical addresses, support tickets, and business data; password vaults were not compromised.
- The technical vector is the compromise of OAuth tokens on Salesforce, obtained via Klue's legacy credentials.
- Beyond LastPass, the Klue breach affected HackerOne, Recorded Future, Tanium, Gong, Jamf, Insurity, OneTrust, Snyk, and Sprout Social.
The June 12 Attack and LastPass Notification
Klue identified unauthorized activity in its systems on June 12, 2026. CEO Jason Smith disclosed in an official statement that attackers used compromised legacy credentials to obtain OAuth tokens. These tokens allowed access to the Salesforce infrastructure integrated with Klue.
LastPass notified the breach on June 24, twelve days after Klue's identification. In the interim, the company revoked employee access to the Klue platform and rotated API tokens. It also launched an investigation and notified relevant authorities.
LastPass publicly shared indicators of compromise. According to HWUpgrade, these include four IP addresses and three Australian domains: baccarat.com.au, robinskitchen.com.au, and house.com.au.
"The core of the service — passwords and site credentials — remained safe" — HDblog.it, citing LastPass
The distinction between CRM data and encrypted vaults is central to understanding the incident's scope. LastPass explicitly ruled out that user-stored credentials were touched. However, the exposure of names, emails, phones, and physical addresses — combined with support tickets and business data — creates a surface for targeted phishing campaigns.
The Technical Vector: OAuth and Salesforce
The compromise of OAuth tokens represents a recurring pattern in attacks on interconnected SaaS ecosystems. OAuth tokens function as delegated access keys between platforms: when compromised, they enable lateral movement without the need to steal primary passwords.
In the Klue case, attackers exploited legacy credentials to obtain valid tokens on Salesforce. This opened access to CRM data shared between Klue and its customers, including LastPass. The pivot from obsolete credentials to an integrated CRM platform is a documented vector in similar incidents.
Klue was working with CrowdStrike on the forensic investigation at the time of the first public reconstructions, according to ZDNet. The dossier does not specify the actual duration of unauthorized access before June 12.
Icarus and the Klue Victim List
The Icarus group, specializing in hacking and extortion, claimed the attack. Cybersecitalia reports that the group threatened to release the data. The dossier does not independently confirm whether an explicit ransom was demanded, nor does it document or rule out ransom payment by Klue or LastPass.
The scope of the Klue breach extends beyond the LastPass case. Converging sources report a victim list that includes recognized security firms such as HackerOne, Recorded Future, and Tanium. Added to these are Gong, Jamf, Insurity, OneTrust, Snyk, and Sprout Social.
The dossier does not document specific motives or infrastructure overlaps linking Icarus to other known groups. The concentration of victims in the technology and security sectors suggests targeting may have been influenced by the visibility of CRM data accessible via the Klue-Salesforce infrastructure.
Third-Party Dependency and the Limits of Control
The incident highlights a structural tension in the digital services supply chain. LastPass promises to isolate user credentials with zero-knowledge encryption, but its operational security depends on third-party ecosystems like Klue for CRM and support functions.
This dependency creates an attack surface that escapes the company's direct control. The exposed data — names, emails, phones, addresses, support tickets — resided on vendor-managed platforms, not in LastPass's encrypted systems.
LastPass reports 33 million total users and 1.6 million paying customers as of 2024, according to Cybersecitalia citing TechCrunch as the original source. The exact number of users involved in this specific incident has not been made public. The dossier also does not clarify whether the exposed data concerns only business users or consumers as well.
What to Do Now
LastPass users should assume their contact data is circulating in criminal environments. This awareness is the first step to recognizing targeted phishing attempts that exploit specific information such as name, address, or support ticket history.
LastPass has published IoC indicators that can be used to monitor contact with the attackers' known infrastructure. The reported IP addresses are 138.226.246[.]94, 94.154.32[.]160, 159.183.215[.]61, and 159.183.181[.]239.
The dossier does not document specific remedial measures taken by Klue beyond the investigation with CrowdStrike. It provides no indications from LastPass on potential compensation or identity monitoring services for potentially affected users.
Eroding Trust
LastPass finds itself managing another reputational crisis after the 2022 breach. The distinction between secure vaults and exposed CRM data is technically correct, but the boundary perceived by users is more blurred. A password manager that loses personal data — even indirectly — weakens the narrative of total control over one's digital security.
The competitive context includes 1Password and Bitwarden as alternatives in the password manager market. These entities are not involved in the incident and add no elements to the specific case.
This reconstruction relies primarily on HDblog.it and converging editorial sources. A structured advisory from LastPass or Klue with a CVE identifier is absent. Information has been verified against cited sources and updated as of publication time.
Information has been verified against cited sources and updated as of publication time.
Sources
- https://www.hdblog.it/android/articoli/n662385/lastpass-data-breach-klue-dati-rubati-cosa-fare/
- https://www.cybersecitalia.it/lastpass-nuovo-data-breach-esposti-nomi-email-numeri-di-telefono-e-indirizzi-fisici/66499/
- https://www.hwupgrade.it/news/web/nuovo-incidente-su-lastpass-esposti-ancora-una-volta-i-dati-personali-degli-utenti_155255.html
- https://klue.com/blog/an-update-on-recent-klue-security-incident
- https://www.zdnet.com/article/lastpass-new-data-breach-2026-steps-to-take-now/
- https://www.techbuzz.ai/articles/lastpass-suffers-fresh-data-breach-via-third-party-supplier
- https://1password.com/
- https://bitwarden.com/