In 2022, LastPass’ breach coughed up encrypted customer passwords spurring some crypto heists later. Now it says a breach at Klue gave attackers access to its Salesforce data, along with that of other companies who, according to reports, are being extorted by “Icarus.” For LastPass, the stolen data includes customers’ names, phone numbers, and other data, but not the actual password vaults this time. [Link: Klue Supply Chain Incident & LastPass Response | https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response | LastPass]

More cybersecurity firms have disclosed the impact of the Klue supply chain attack as hackers threaten to release stolen data.

Huntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.