Back
LastPass Notifies Users of Another Breach — This Time Through a Vendor
SiTech AI Team2 წთ. საკითხავი

LastPass Notifies Users of Another Breach — This Time Through a Vendor

LastPass is emailing customers affected by a breach at market-research vendor Klue that exposed names, phone numbers, email addresses and support case data. The company says password vaults were not affected.

A supply-chain breach at a vendor

LastPass is emailing users affected by a security breach at Klue, a market-research firm that is one of the password manager's outside partners. The incident allowed hackers to reach customer information and support case data, according to reports and to LastPass's own account of the event.

Klue's platform integrates with Salesforce and Gong systems, which widened the range of data the attackers could reach. LastPass says its own password vaults were not affected.

What was exposed

In a blog post, LastPass said the information accessed was limited to standard business contact information and related customer relationship management data — customer names, phone numbers, email addresses and physical addresses — as well as support case data and sales-related data.

The response

LastPass says that as soon as it learned of the incident it revoked employee access to Klue, rotated the exposed API tokens, notified law enforcement and opened a detailed investigation into the scope of the event, working with contacts at both Klue and Salesforce.

The company is advising customers to remain vigilant about phishing attacks and social engineering that could use the compromised details. It also published the IP addresses and email sender domains associated with the attackers — 138.226.246[.]94, 94.154.32[.]160, 159.183.215[.]61 and 159.183.181[.]239, plus the domains baccarat.com[.]au, robinskitchen.com[.]au and house.com[.]au — so that other organisations can search their own systems for related activity.

Not the first incident

The breach is the latest in a series of security incidents at LastPass. In 2015, hackers obtained account email addresses, password reminders, authentication hashes and cryptographic salts, although the company said encrypted vault data was not accessed. In 2022, an attacker compromised a developer account and stole source code and technical information, then used it to reach cloud backups containing customer records and encrypted password vaults, along with unencrypted names, billing addresses, email addresses and phone numbers.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.