Skip to main content
Back to overview
High

LastPass Discloses Supply Chain Security Incident via Third-Party Vendor Klue

LastPass reported a supply chain security incident on June 22, 2026, stemming from a breach at its third-party vendor, Klue.

Key points

  • LastPass reported a supply chain security incident on June 22, 2026.
  • The breach originated from a third-party vendor, Klue.
  • Attackers used stolen OAuth tokens to access LastPass's Salesforce CRM data.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Partner actor · Confidentiality impact

Possible third-party involvement

03

Potential impact

Potential data exposure

Confidentiality

Published
Jun 22, 2026
Updated
Jul 1, 2026
Confidence
High
Evidence
22 sources

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible third-party involvement

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: supplier or third-party involvement

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

LastpassData DisclosureThird-Party Vendor Klue LastPassKlue. AttackersKlueOAuthLastPassSalesforce CRM

Quick context

Questions about this signal

What happened in this signal?

LastPass reported a supply chain security incident on June 22, 2026, stemming from a breach at its third-party vendor, Klue. Attackers exploited compromised legacy credentials at Klue to obtain OAuth tokens, which were then used to access LastPass's Salesforce CRM environment. The compromised information includes customer names, email addresses, phone numbers, and physical addresses, as well as support case information. LastPass confirmed that its core infrastructure and password vaults were not affected, but the incident highlights risks associated with third-party integrations.

When was this signal reported?

Shadow Tier lists Jun 22, 2026 as the signal date.

Which organization is connected to this signal?

Lastpass is the organization connected to this public signal.

Explore Lastpass