Tech

Password manager maker LastPass says hackers stole customer support case data during Klue breach

Noozly Editorial Desk ·
Password manager maker LastPass says hackers stole customer support case data during Klue breach

LastPass, the widely used password management service, has begun alerting customers that a cyberattack on one of its technology vendors exposed their personal details along with records tied to past support interactions. The company confirmed the incident in outreach to affected users, marking yet another security lapse tied to the firm within the past several years.

According to a notification obtained by TechCrunch from a customer who received it, LastPass clarified that the intrusion did not originate within its own network. Instead, the point of entry was a partner firm's infrastructure, though the consequences reached directly into LastPass's customer records.

The compromised vendor has been identified as Klue, a company that specializes in market and competitive intelligence research. Investigators say intruders leveraged whatever access they gained through Klue to pull large volumes of information tied specifically to LastPass account holders, rather than targeting Klue's own client base alone.

LastPass is not the only firm ensnared by this incident. A string of cybersecurity-focused companies have come forward in recent days to acknowledge that their own customer data was similarly exposed after intruders breached Klue's systems, a compromise the vendor publicly acknowledged roughly a week earlier. Among the other companies reporting fallout are HackerOne, Recorded Future, and Tanium, underscoring how a single vendor compromise can ripple outward across an entire industry of security-conscious clients.

For LastPass specifically, this marks the second time in a relatively short span that its customers have been caught up in a data security incident, following an earlier episode connected to a different technology partner. The recurrence is likely to renew scrutiny of how password managers — tools entrusted with some of users' most sensitive credentials — vet and monitor the third-party vendors that touch customer data, even when that data consists of support tickets rather than vault contents.

Security researchers have long warned that supply-chain style breaches, where attackers compromise a shared vendor rather than the end target directly, can be especially damaging because a single point of failure exposes customers of multiple otherwise-unrelated companies at once. The pattern seen with Klue's client roster, spanning several major names in the cybersecurity sector, illustrates how deeply interconnected corporate back-office tools like customer support and research platforms have become, and how attractive they are as a single point of leverage for intruders.

LastPass has not detailed the precise volume of records taken or specified which categories of personal information beyond support case data were included in the exposure. It also remains unclear what remediation steps, such as credential resets or enhanced monitoring, the company is offering to affected customers, or whether regulators will examine the incident given the sensitivity of the service LastPass provides. Customers who use LastPass are advised to watch for official communications from the company and to be alert to phishing attempts that could exploit the leaked support case details.

Source: TechCrunch

technologyinnovationdigitalpasswordmanagermaker
Original source
TechCrunch →

Related articles

Fidji Simo steps down from OpenAI’s no. 2 role
Tech

Fidji Simo steps down from OpenAI’s no. 2 role

OpenAI's No. 2 executive, Fidji Simo, is stepping down from her full-time role after her medical leave proved longer than expected — a leadership vacuum that comes at a tricky time as the company eyes a possible IPO and races to catch Anthropic in the enterprise market.