In 2022, LastPass’ breach coughed up encrypted customer passwords spurring some crypto heists later. Now it says a breach at Klue gave attackers access to its Salesforce data, along with that of other companies who, according to reports, are being extorted by “Icarus.” For LastPass, the stolen data includes customers’ names, phone numbers, and other data, but not the actual password vaults this time. [Link: Klue Supply Chain Incident & LastPass Response | https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response | LastPass]

More cybersecurity firms have disclosed the impact of the Klue supply chain attack as hackers threaten to release stolen data.

Huntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.

As yet another extortion crew Icarus exploits Salesforce-linked integrations

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month.

LastPass notified customers that personal data and support cases were stolen after hackers breached Klue and used stolen OAuth tokens to access Salesforce.

It's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.

More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.

LastPass users are once again being warned about stolen personal data, though this time the breach happened through one of the company’s outside partners.

In 2022, LastPass’ breach coughed up encrypted customer passwords spurring some crypto heists later. Now it says a breach at Klue gave attackers access to its Salesforce data,…

LastPass conferma un data breach causato dall'attacco a Klue: esposti dati CRM e ticket di supporto clienti.

Hackertámadás érte a LastPass egyik partnerét, érzékeny felhasználói adatok is illetéktelen kezekbe kerültek.

LastPass ha informato i propri utenti di un'ulteriore compromissione dei dati personali, questa volta avvenuta attraverso un partner esterno. I vault delle password non sarebbero…

Nearly a dozen cybersecurity firms have confirmed having business data stolen from their Salesforce instances during the Klue hack.

The good news for anyone still using LastPass after its previous security disasters is that this was not a compromise of the company's password manager infrastructure. LastPass...

A third-party supplier breach has exposed LastPass customer names, phone numbers, and other data. Here's how to protect yourself.

Hackers used a backdoor through a little-known third-party app to steal LastPass customer data.