# LastPass Breached via Klue Supply Chain Attack: OAuth Tokens Exploited to Access Customer Data


Password manager LastPass confirmed a significant data breach this month stemming from a compromised third-party integration. Attackers leveraged stolen OAuth credentials from Klue, a B2B intelligence platform, to gain unauthorized access to LastPass's Salesforce environment and extract customer data. The incident underscores how even security-focused companies remain vulnerable through the growing attack surface of cloud integrations and third-party dependencies.


## The Threat: How OAuth Tokens Became Entry Points


LastPass disclosed that threat actors accessed its Salesforce infrastructure after obtaining OAuth tokens belonging to Klue, a SaaS competitor analysis tool integrated with multiple enterprise systems. The attackers exploited these stolen credentials to authenticate as legitimate users and move laterally into sensitive LastPass systems.


What was compromised:

  • Customer account metadata and user information from the Salesforce database
  • Organizational account details tied to enterprise customers
  • Potentially contact information and subscription-related data
  • Third-party integration configurations

  • The breach did not expose encrypted vault data or master passwords, according to LastPass. However, the access to customer records represents a significant exposure for a company entrusted with protecting sensitive credentials across millions of users.


    ## Background and Context: The Klue Supply Chain Attack


    The Klue incident, which occurred in early June 2026, marked the beginning of this chain of compromises. Klue, which aggregates competitive intelligence for B2B sales and marketing teams, had its systems compromised by sophisticated threat actors. The attackers succeeded in extracting OAuth tokens and session credentials that numerous downstream customers—including LastPass—had integrated for data synchronization and automation.


    The supply chain angle:

  • Klue serves as a hub connecting multiple enterprise software platforms
  • Compromising one integration provider created cascading vulnerabilities across dozens of customer environments
  • OAuth tokens, while more secure than passwords, still represent dangerous attack vectors when compromised
  • Many organizations rely on Klue without fully understanding the privilege level of their integrations

  • This reflects a broader pattern in 2026: attackers are increasingly targeting integration platforms and credential stores rather than attacking applications directly. Services like Klue, Zapier, and other iPaaS solutions have become prime targets because a single compromise can expose OAuth tokens to hundreds of downstream systems.


    ## Technical Details: Token Theft and Lateral Movement


    How the attack unfolded:


    1. Initial compromise of Klue: Attackers gained access to Klue's systems through methods not fully disclosed (likely phishing, credential stuffing, or an unpatched vulnerability).


    2. Token extraction: Once inside Klue, attackers accessed the OAuth token storage and extracted credentials that Klue had obtained from integrations with customer systems—including LastPass.


    3. Lateral movement: Using the stolen OAuth tokens, attackers authenticated to LastPass's Salesforce instance without triggering traditional login alerts (since the tokens were valid).


    4. Data exfiltration: Within Salesforce, attackers queried customer account data, subscription records, and organizational metadata.


    Why OAuth tokens were effective:

  • OAuth tokens bypass the need for passwords and multi-factor authentication
  • Applications often grant broad permissions to integrated services
  • Token expiration policies may not be aggressive enough to detect abuse quickly
  • Salesforce logs may not distinguish between legitimate and stolen token usage

  • LastPass stated it detected the unauthorized access during routine security monitoring and immediately revoked affected OAuth sessions and reset credentials.


    ## Implications for Organizations and Users


    ### For LastPass Customers


  • Limited immediate exposure: Since vault contents remain encrypted, users' passwords and stored secrets should remain secure
  • Identity risk: Exposed account metadata could enable targeted phishing or account takeover attempts against enterprise customers
  • Trust considerations: A password manager suffering a data breach—even one not affecting encrypted credentials—raises questions about infrastructure security posture

  • ### Broader Industry Ramifications


    | Risk Factor | Impact |

    |---|---|

    | OAuth ecosystem fragility | Thousands of organizations rely on OAuth integrations with minimal visibility into token permissions |

    | Supply chain visibility gap | Companies often don't know which integrations hold privileged access to their systems |

    | Token management weakness | Most organizations lack comprehensive token inventory and rotation strategies |

    | Third-party risk compounding | A breach in one vendor (Klue) cascades to dozens of downstream customers |


    The incident demonstrates that OAuth tokens now function as a new form of currency in the attacker economy. Just as attackers trade stolen credentials on dark markets, compromised OAuth tokens provide immediate access to enterprise systems.


    ## HackWire Analysis


    This breach reveals a critical blind spot in how enterprises approach cloud security. Most organizations treat OAuth integrations as "trusted connections" once authenticated, rarely auditing what permissions they've granted or how long tokens remain valid. The Klue incident proves this assumption is dangerous.


    The timing matters: We're seeing a marked shift in Q2-Q3 2026 toward OAuth token harvesting. The SolarWinds precedent taught attackers that software update mechanisms are monitored heavily; today's attackers are going after integration platforms where security oversight tends to be lighter. Klue, Zapier, Make.com—these are the new supply chain chokepoints.


    What's missing from most reporting: The real risk isn't just "LastPass got breached." It's that organizations have no way to know which of their own OAuth tokens might be floating in attacker hands right now. Did you integrate Klue? Chances are your Salesforce token is compromised too. Did you connect Klue to your data warehouse? Your analytics environment may be accessible. The breach surface extends far beyond LastPass.


    For defenders: Immediately audit your OAuth token grants across all SaaS applications. Query your cloud access logs for Klue-issued tokens. Enable token rotation on any integration that accesses production systems. This incident should trigger an enterprise-wide review of third-party integrations with elevated privileges—something most security teams have deprioritized in favor of traditional patch management.


    — HackWire Editorial


    ## Recommendations: Steps for Immediate Action


    ### For LastPass Users

  • Monitor your email and phone for phishing attempts targeting account compromises
  • If your organization uses LastPass, confirm that IT has rotated any stored API keys or service accounts
  • Enable passwordless sign-in (passkeys/biometric) where available to reduce password exposure
  • Review LastPass's detailed breach notification for specifics about which customer data may have been exposed

  • ### For Security Teams

  • Inventory all OAuth integrations connected to production systems (Salesforce, cloud data stores, communication platforms)
  • Review token permissions: Use cloud provider tools to audit what scopes OAuth apps currently hold
  • Implement token rotation: Set automatic expiration policies for OAuth tokens (30-90 days depending on sensitivity)
  • Monitor for Klue compromise: Check access logs for unusual Salesforce/database queries between June 1-15, 2026
  • Disable unused integrations: Remove any Klue connections that aren't actively used

  • ### For Cloud Service Providers

  • Provide token provenance tracking (show end-users which third party a token originated from)
  • Implement behavioral anomaly detection specific to token-based access patterns
  • Require multi-factor authentication even for valid OAuth token access when accessing sensitive data
  • Offer granular token revocation at the integration level

  • ## What Comes Next


    LastPass stated it is cooperating with law enforcement and notifying affected customers directly. The company has committed to conducting a full forensic investigation and implementing additional security controls around third-party integrations.


    The incident serves as a forcing function for the enterprise security community: OAuth token management can no longer be an afterthought. As the attack surface expands across integrations, visibility and control over these tokens will determine whether organizations can prevent the next supply chain cascade.


    ---


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)