Password manager provider LastPass has begun notifying customers that their personal information and support ticket records were stolen during a recent cyberattack at its market research partner, Klue.
In an email correspondence sent to affected users, LastPass clarified that the security breach occurred on the systems of the third-party marketing firm, rather than its own infrastructure. Despite this, the unauthorized actors managed to exploit their access to harvest a significant volume of sensitive customer data.
What information was compromised in the Klue hack?
In an official blog post detailing the security incident, LastPass disclosed that the compromised data includes customer names, telephone numbers, email addresses, physical addresses, sales-related details, and support case history.
LastPass stated that its proprietary systems remain entirely unaffected, and customer password vaults were not accessed or compromised during the incident.
The risks associated with exposed support tickets
While the precise contents of the stolen customer support tickets have not been fully disclosed, such records frequently contain sensitive information. Users typically contact customer support to resolve billing discrepancies or seek assistance with account recovery. In similar historical breaches involving support databases, exposed files have occasionally contained user credentials and government-issued identity documents.
The wider impact of the supply chain compromise
LastPass is the latest in a growing list of prominent cybersecurity organisations to report data theft linked to the Klue breach, which was publicly disclosed last week. Other affected firms include HackerOne, Recorded Future, and Tanium.
Spokespeople for LastPass did not immediately respond to requests for comment regarding the total number of users affected by the incident. According to its corporate website, LastPass currently serves more than 33 million users and approximately 1.6 million paying customers globally.
A history of security challenges
This incident follows a major security breach in 2022, during which hackers managed to steal LastPass’s entire archive of customer password vaults. Although these vaults were encrypted with master passwords known only to the customers, the theft allowed bad actors to attempt offline brute-force attacks to crack weaker master passwords.
Several high-value cryptocurrency thefts were subsequently linked to the 2022 LastPass breach, after investigators suspected that hackers successfully cracked the stolen vaults to access victims’ private wallet keys.
Who is behind the Klue cyberattack?
Klue Chief Executive Jason Smith confirmed in a company update that unauthorized activity was detected on the firm’s systems on 12 June. An extortion and hacking collective operating under the moniker “Icarus” has claimed responsibility for the intrusion, threatening to leak the stolen data unless a ransom is paid.
Smith has not yet responded to inquiries regarding the exact number of clients affected or whether the company has engaged in negotiations with the extortion group.
