LastPass confirmed this week that hackers stole customer contact data and support records from its Salesforce environment, the latest victim in a supply chain attack on market intelligence platform Klue that swept hundreds of enterprise organizations.
The breach originated on June 12. An unauthorized actor obtained OAuth tokens, authorization credentials that grant third-party platforms access to connected services, that Klue held on behalf of its customers.
Exposed data includes customer names, phone numbers, email addresses, physical addresses, and support case records. LastPass said its own infrastructure was unaffected and that customer password vaults remain secure.
The attacker, an extortion group calling itself Icarus, entered Klue through a compromised legacy credential, then generated OAuth tokens for connected platforms and deployed automated scripts to extract Salesforce data in bulk.
The operation gave Icarus access to Salesforce environments across hundreds of organizations through a single compromised vendor integration, without requiring any direct breach of those companies’ own infrastructure. Salesforce and Gong both disabled the Klue Battlecards integration in response.
Confirmed victims include HackerOne, Recorded Future, Tanium, Jamf, Sprout Social, BeyondTrust, and Huntress, which said “hundreds of Klue customers” were affected. A second unverified party subsequently said it obtained access to the same stolen data and threatened to publish names of nearly 200 victim companies daily, Huntress reported on June 24. Those statements have not been independently verified.
LastPass has revoked Klue’s access, notified law enforcement, and urged customers to remain alert to phishing attempts, stating that no one at LastPass will ever request a master password.
The incident is the company’s second major breach since hackers stole encrypted customer password vaults in 2022. A $24.5 million class action settlement tied to that incident received preliminary court approval in February 2026, with a claims deadline of July 2, 2026 for eligible users.







