Cyber Incident Victim: LastPass
Timeline
Summary
LastPass disclosed that a breach at its technology partner Klue resulted in attackers accessing customer support case records and personal information such as names, phone numbers, email addresses, and physical addresses. The company stated that its own infrastructure, including password vaults, remained uncompromised and that no passwords or payment card data were accessed in the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
OnJune 12, 2026, Klue’s chief executive reported that the company had identified unauthorized access to its systems. The hacking and extortion group Icarus subsequently claimed responsibility for the breach and warned that it would release stolen data unless a ransom was paid. On June 23, 2026, LastPass published a blog post and sent an email to affected customers stating that the breach originated at Klue and not within LastPass’s own environment. LastPass explained that threat actors had gained access to customer data stored in its Salesforce instance through the compromised Klue integration.

According to LastPass’s disclosure, the attackers obtained customers’ names, phone numbers, email addresses, and physical addresses, as well as customer support case records and sales‑related data. LastPass emphasized that its products, services, and underlying infrastructure remained unaffected and that customer password vaults stayed secure. The company also noted that no passwords, payment card information, telemetry, or infrastructure data were accessed during the incident. Other cybersecurity firms that reported similar data thefts from the Klue breach include HackerOne, Recorded Future, and Tanium.
LastPass reported having more than 33 million total users and approximately 1.6 million paying customers as of 2024. The company had previously suffered a breach in 2022 in which attackers copied the entire repository of encrypted customer vaults, an event that later contributed to several cryptocurrency thefts after weak master passwords were cracked. Klue’s investigation indicated that the initial intrusion was detected on June 12, and Icarus has continued to threaten public release of the stolen material unless its demands are met.
