LastPass Breach Linked to Third-Party Intelligence Tool Klue

Hackers have breached LastPass by exploiting a legacy credential held by market intelligence firm Klue, allowing unauthorized access to customer data stored within Salesforce. The incident, part of a broader campaign by a group calling itself Icarus, exposed contact information but left core password vaults untouched.

Today, 10:45
1,161 0
LastPass Breach Linked to Third-Party Intelligence Tool Klue

The attackers utilized stolen OAuth tokens to query the Salesforce API, extracting names, email addresses, phone numbers, and physical addresses of LastPass customers. This operation was not isolated; the extortion group Icarus targeted multiple organizations simultaneously, with Recorded Future, Jamf, and Sprout Social among those affected. Cybersecurity firms Huntress and ReliaQuest identified that the perpetrators relied on Python scripts to automate the large-scale theft across the compromised platforms.

In response to the intrusion, LastPass has revoked Klue’s access and initiated coordination with law enforcement agencies. While the company maintains that its encrypted password vaults remain secure, it has warned users to exercise heightened caution regarding phishing attempts. The extortionists are currently pressuring victims to establish contact via the Session messaging platform, threatening to leak the stolen datasets if their demands are ignored.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!