Skip to main content

Company intelligence

Lastpass cybersecurity incidents and threat signals

lastpass.com

Lastpass logo

This company page brings together public reporting currently associated with Lastpass. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

1

Published signals

currently linked to this company

0

Last 28 days

recent published signals

1

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 1, 2026

Latest report

most recent published signal

Company signals

All published signals involving Lastpass

Lastpass logo
High

LastPass Discloses Supply Chain Security Incident via Third-Party Vendor Klue

LastPass reported a supply chain security incident on June 22, 2026, stemming from a breach at its third-party vendor, Klue. Attackers exploited compromised legacy credentials at Klue to obtain OAuth tokens, which were then used to access LastPass's Salesforce CRM environment. The compromised information includes customer names, email addresses, phone numbers, and physical addresses, as well as support case information. LastPass confirmed that its core infrastructure and password vaults were not affected, but the incident highlights risks associated with third-party integrations.

Lastpass

FAQ

Questions about Lastpass cybersecurity reporting

What does the Lastpass page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Lastpass.

Does every mention of Lastpass appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.