# LastPass Breached via Klue Supply Chain Attack: OAuth Tokens Exploited to Access Customer Data
Password manager LastPass confirmed a significant data breach this month stemming from a compromised third-party integration. Attackers leveraged stolen OAuth credentials from Klue, a B2B intelligence platform, to gain unauthorized access to LastPass's Salesforce environment and extract customer data. The incident underscores how even security-focused companies remain vulnerable through the growing attack surface of cloud integrations and third-party dependencies.
## The Threat: How OAuth Tokens Became Entry Points
LastPass disclosed that threat actors accessed its Salesforce infrastructure after obtaining OAuth tokens belonging to Klue, a SaaS competitor analysis tool integrated with multiple enterprise systems. The attackers exploited these stolen credentials to authenticate as legitimate users and move laterally into sensitive LastPass systems.
What was compromised:
The breach did not expose encrypted vault data or master passwords, according to LastPass. However, the access to customer records represents a significant exposure for a company entrusted with protecting sensitive credentials across millions of users.
## Background and Context: The Klue Supply Chain Attack
The Klue incident, which occurred in early June 2026, marked the beginning of this chain of compromises. Klue, which aggregates competitive intelligence for B2B sales and marketing teams, had its systems compromised by sophisticated threat actors. The attackers succeeded in extracting OAuth tokens and session credentials that numerous downstream customers—including LastPass—had integrated for data synchronization and automation.
The supply chain angle:
This reflects a broader pattern in 2026: attackers are increasingly targeting integration platforms and credential stores rather than attacking applications directly. Services like Klue, Zapier, and other iPaaS solutions have become prime targets because a single compromise can expose OAuth tokens to hundreds of downstream systems.
## Technical Details: Token Theft and Lateral Movement
How the attack unfolded:
1. Initial compromise of Klue: Attackers gained access to Klue's systems through methods not fully disclosed (likely phishing, credential stuffing, or an unpatched vulnerability).
2. Token extraction: Once inside Klue, attackers accessed the OAuth token storage and extracted credentials that Klue had obtained from integrations with customer systems—including LastPass.
3. Lateral movement: Using the stolen OAuth tokens, attackers authenticated to LastPass's Salesforce instance without triggering traditional login alerts (since the tokens were valid).
4. Data exfiltration: Within Salesforce, attackers queried customer account data, subscription records, and organizational metadata.
Why OAuth tokens were effective:
LastPass stated it detected the unauthorized access during routine security monitoring and immediately revoked affected OAuth sessions and reset credentials.
## Implications for Organizations and Users
### For LastPass Customers
### Broader Industry Ramifications
| Risk Factor | Impact |
|---|---|
| OAuth ecosystem fragility | Thousands of organizations rely on OAuth integrations with minimal visibility into token permissions |
| Supply chain visibility gap | Companies often don't know which integrations hold privileged access to their systems |
| Token management weakness | Most organizations lack comprehensive token inventory and rotation strategies |
| Third-party risk compounding | A breach in one vendor (Klue) cascades to dozens of downstream customers |
The incident demonstrates that OAuth tokens now function as a new form of currency in the attacker economy. Just as attackers trade stolen credentials on dark markets, compromised OAuth tokens provide immediate access to enterprise systems.
## HackWire Analysis
This breach reveals a critical blind spot in how enterprises approach cloud security. Most organizations treat OAuth integrations as "trusted connections" once authenticated, rarely auditing what permissions they've granted or how long tokens remain valid. The Klue incident proves this assumption is dangerous.
The timing matters: We're seeing a marked shift in Q2-Q3 2026 toward OAuth token harvesting. The SolarWinds precedent taught attackers that software update mechanisms are monitored heavily; today's attackers are going after integration platforms where security oversight tends to be lighter. Klue, Zapier, Make.com—these are the new supply chain chokepoints.
What's missing from most reporting: The real risk isn't just "LastPass got breached." It's that organizations have no way to know which of their own OAuth tokens might be floating in attacker hands right now. Did you integrate Klue? Chances are your Salesforce token is compromised too. Did you connect Klue to your data warehouse? Your analytics environment may be accessible. The breach surface extends far beyond LastPass.
For defenders: Immediately audit your OAuth token grants across all SaaS applications. Query your cloud access logs for Klue-issued tokens. Enable token rotation on any integration that accesses production systems. This incident should trigger an enterprise-wide review of third-party integrations with elevated privileges—something most security teams have deprioritized in favor of traditional patch management.
— HackWire Editorial
## Recommendations: Steps for Immediate Action
### For LastPass Users
### For Security Teams
### For Cloud Service Providers
## What Comes Next
LastPass stated it is cooperating with law enforcement and notifying affected customers directly. The company has committed to conducting a full forensic investigation and implementing additional security controls around third-party integrations.
The incident serves as a forcing function for the enterprise security community: OAuth token management can no longer be an afterthought. As the attack surface expands across integrations, visibility and control over these tokens will determine whether organizations can prevent the next supply chain cascade.
---