LastPass says hackers stole customer data in Klue supply chain breach

15 sources
  • LastPass said hackers accessed customer personal information and support case data via the Klue supply chain breach, though password vaults were not affected.
  • The attack, attributed to extortion group Icarus, exploited a legacy credential to harvest OAuth tokens from Klue's integration with Salesforce on June 11.
  • Firms including Huntress, Recorded Future, Tanium, Jamf, HackerOne, and Snyk have also disclosed CRM data theft from the same breach, according to The Register.
Sources (15)
  1. 1 Password manager maker LastPass says hackers stole customer support case data during Klue breach techcrunch.com
  2. 2 Klue Supply Chain Incident & LastPass Response blog.lastpass.com
  3. 3 Cybersecurity Firms Impacted by Klue Supply Chain Attack www.securityweek.com
  4. 4 Security shops among the 'hundreds' of Klue hack victims www.theregister.com
  5. 5 OAuth Hacks Return: Salesforce Disables Third-Party App ... www.salesforceben.com
  6. 6 Icarus Threat Actor Exploits Legacy Credentials and OAuth ... techjacksolutions.com
  7. 7 Klue Integration Abused in Salesforce Data Theft reliaquest.com
  8. 8 Klue: SaaS supply chain compromise through long-lived ... www.threatlocker.com
  9. 9 LastPass confirms data breach in Klue supply chain attack www.socdefenders.ai
  10. 10 Klue hack results in data breach at several cybersecurity ... techcrunch.com
  11. 11 Klue OAuth Integration Breach Exposes Salesforce ... www.rescana.com
  12. 12 LastPass Customer Data Accessed in Klue Supply Chain ... gbhackers.com
  13. 13 Klue OAuth Breach Fuels Icarus Salesforce Data Theft ... innovatecybersecurity.com
  14. 14 Klue Confirms Breach Exposed CRM Data Across Integrations www.crn.com
  15. 15 Klue OAuth breach linked to 'Icarus' Salesforce data theft ... www.bleepingcomputer.com

Leave a Reply