LastPass Warns Customers After Hackers Steal Personal Data Through Klue Security Breach
Technology

LastPass Warns Customers After Hackers Steal Personal Data Through Klue Security Breach

LastPass is alerting millions of users after cybercriminals accessed personal data and customer support records via a breach at market research firm Klue.

By Jenna Patton4 min read

LastPass Customers Hit by Another Data Breach — This Time Through a Third-Party Vendor

LastPass, one of the world's most widely used password management platforms, is reaching out to affected customers following a cybersecurity incident that exposed personal information and customer support records. The breach did not originate within LastPass's own systems — instead, hackers infiltrated Klue, a market research firm that serves as a technology partner to LastPass and numerous other companies in the cybersecurity industry.

What Happened and Who Is Responsible?

According to an email obtained by TechCrunch from an impacted LastPass user, the company confirmed that cybercriminals exploited their unauthorized access to Klue's systems to harvest substantial amounts of data belonging to LastPass customers. Klue's CEO, Jason Smith, revealed in a public blog post that the intrusion was first detected on June 12. A hacking and extortion group known as Icarus has since claimed responsibility for the attack, publicly threatening to release the stolen data unless a ransom is paid.

LastPass is not alone in being caught in the fallout. Several other prominent cybersecurity organizations — including HackerOne, Recorded Future, and Tanium — have also reported data theft stemming from the same Klue breach.

What Data Was Stolen?

In a blog post addressing the incident, LastPass outlined the categories of customer information that were compromised. The stolen data includes:

  • Full names
  • Phone numbers
  • Email addresses
  • Physical mailing addresses
  • Customer support case records
  • Sales-related information

While the specific contents of individual customer support tickets remain unknown, such records commonly contain sensitive fragments of information. Customers typically engage with support teams over billing disputes, account recovery issues, or technical difficulties — interactions that may involve partial credentials or identity-related details.

Importantly, LastPass confirmed that its own core infrastructure remained secure and was not affected by the breach. Customer password vaults — the encrypted repositories used to store passwords, tokens, and other sensitive credentials — were not accessed or compromised.

A Company With a Troubled Security History

This incident marks yet another significant security setback for LastPass, a company that has faced growing scrutiny over its data protection practices in recent years.

In 2022, LastPass suffered a far more severe breach in which hackers successfully exfiltrated the company's entire collection of customer password vaults. Although those vaults were protected by individual master passwords known only to each user, the theft enabled attackers to conduct offline brute-force attacks — particularly effective against accounts secured by weaker master passwords. The consequences proved serious: multiple cryptocurrency thefts were subsequently linked to that breach, with investigators suspecting that hackers cracked vulnerable vaults and used the wallet keys stored inside to drain victims' digital assets.

Scale of Potential Impact

As of 2024, LastPass reports having more than 33 million registered users and approximately 1.6 million paying customers. The company has not yet disclosed how many individuals have been affected by the current breach, and representatives did not respond to requests for comment at the time of reporting.

What Customers Should Do Now

Although password vaults remain uncompromised in this latest incident, affected LastPass customers should still take precautionary steps:

Immediate Actions to Consider

  • Monitor your email for any phishing attempts that could exploit your exposed contact information
  • Be cautious of unsolicited phone calls claiming to be from LastPass or related services
  • Review your account activity for any unusual or unauthorized changes
  • Enable multi-factor authentication if you haven't done so already
  • Stay alert for targeted scams that may use your personal details to appear legitimate

The Bigger Picture: Third-Party Risk in Cybersecurity

This incident serves as a stark reminder of the vulnerabilities that arise from interconnected vendor ecosystems. Even companies with robust internal security practices can find their customers exposed through the weaknesses of third-party partners. As the Klue breach continues to ripple through the cybersecurity industry, organizations and individual users alike are being reminded that supply chain security is no longer optional — it is a fundamental component of any credible data protection strategy.