MLXIO
red padlock on black computer keyboard
CybersecurityJune 23, 2026· 5 min read· By MLXIO Insights Team

Vaults Dodge Hit as LastPass Breach Exposes User Data

Share

MLXIO Intelligence

Analysis Snapshot

68
High
Confidence: LowTrend: 10Freshness: 96Source Trust: 100Factual Grounding: 91Signal Cluster: 20

High MLXIO Impact based on trend velocity, freshness, source trust, and factual grounding.

Thesis

High Confidence

LastPass says a breach at outside partner Klue exposed business contact, CRM, support, and sales-related customer data, while customer vaults were not affected.

Evidence

  • LastPass is emailing affected users after hackers accessed data through Klue, a market research partner tied to its go-to-market systems.
  • The exposed information included customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related data.
  • LastPass said vault contents were not affected and revoked employee access to Klue after learning of the incident.
  • BleepingComputer reported attackers obtained OAuth tokens held by Klue and used them to access LastPass customer data in Salesforce.

Uncertainty

  • LastPass has not publicly provided a count of affected users in the available reporting.
  • The final scope of the incident remains under investigation with Klue and Salesforce.
  • LastPass found no evidence of access to Gong-related data, but the article frames the disclosed scope as still having gaps.

What To Watch

  • Whether LastPass discloses the number of affected customers.
  • Updates on the investigation into Klue, Salesforce access, and exposed OAuth tokens.
  • Customer phishing or social engineering attempts using the stolen contact and support data.

Verified Claims

LastPass warned users that personal data was accessed after hackers breached Klue, an outside market research partner.
📎 LastPass is warning users that personal data was accessed after hackers hit Klue, an outside market research partner connected to its sales and customer systems.High
LastPass said customer password vaults were not affected by the Klue-related incident.
📎 The password manager says customer vaults were not affected.High
The exposed information included business contact details, CRM data, support case data, and sales-related data.
📎 The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.High
LastPass responded by revoking employee access to Klue, rotating exposed API tokens, notifying law enforcement, and investigating with Klue and Salesforce contacts.
📎 The company said it revoked employee access to Klue after learning of the incident. It also rotated exposed API tokens, notified law enforcement, and opened 'a detailed investigation into the scope of the event, working with our contacts at both Klue and Salesforce.'High
LastPass warned customers to remain vigilant for phishing or social engineering attempts using the stolen data.
📎 LastPass is explicitly warning customers to 'remain vigilant of potential phishing attacks or social engineering attempts' using the stolen data.High

Frequently Asked

Were LastPass password vaults affected by the Klue breach?

No. LastPass said customer vaults were not affected and that the exposed data was limited to business contact, CRM, support, and sales-related information.

What LastPass user data was exposed in the Klue incident?

The exposed data included customer names, phone numbers, email addresses, physical addresses, CRM data, support case data, and sales-related data.

How did attackers access LastPass customer data in this incident?

According to the article, hackers accessed data through Klue, an outside market research partner connected to LastPass sales and customer systems. BleepingComputer reported that OAuth tokens held by Klue were used to access LastPass customer data in Salesforce.

What did LastPass do after learning about the Klue breach?

LastPass said it revoked employee access to Klue, rotated exposed API tokens, notified law enforcement, and began investigating the incident with Klue and Salesforce contacts.

What is the main risk to users from the LastPass Klue breach?

The article frames the main risk as phishing and social engineering, because contact details and support or sales records could help attackers create credible, targeted messages.

Updated on June 23, 2026

LastPass is warning users that personal data was accessed after hackers hit Klue, an outside market research partner connected to its sales and customer systems.

The password manager says customer vaults were not affected, but the incident exposed business contact, CRM, support, and sales-related data, according to 9to5Mac . For a company built on trust around credentials, even a partner-linked breach lands hard.

LastPass alerts users after Klue breach exposes contact and support data

LastPass is emailing affected users after a breach at Klue, a market research firm used by the company’s go-to-market teams. The attack allowed hackers to access customer information and support case data tied to LastPass.

LastPass said the exposed data was limited to standard business and CRM information, not password vault contents.

“The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.”

That distinction matters. Vault data is the crown jewel for a password manager. CRM and support data, while less sensitive than stored credentials, can still give attackers enough detail to craft credible phishing emails, impersonate support staff, or target users with account-specific lures.

The company said it revoked employee access to Klue after learning of the incident. It also rotated exposed API tokens, notified law enforcement, and opened “a detailed investigation into the scope of the event, working with our contacts at both Klue and Salesforce.”

BleepingComputer reported that LastPass was made aware of the Klue incident on June 12th, and that attackers obtained OAuth tokens Klue held for customers including LastPass. Those tokens were then used to access LastPass customer data in its Salesforce environment.

Klue’s platform integrates with Salesforce and Gong systems, according to LastPass. BleepingComputer reported that LastPass found no evidence of access to Gong-related data, which can include customer calls and emails.

The disclosed scope still has gaps. LastPass has not provided, in the available reporting, a public count of affected users.


Partner-linked incident adds pressure after LastPass’s previous security failures

This is not a repeat of LastPass’s worst prior breach pattern, but it hits the same nerve: users trusted a password manager, and attackers still reached data connected to that relationship.

The latest incident stems from a third-party partner rather than a reported direct compromise of LastPass’s own products or vault infrastructure. That does not make it harmless. It shifts the weak point from the password vault to the vendor chain around customer management and support.

MLXIO analysis: The practical risk is not mass vault cracking based on what LastPass has disclosed. The risk is precision fraud. Names, phone numbers, email addresses, physical addresses, support cases, and sales records can help an attacker sound legitimate when contacting a user.

LastPass is explicitly warning customers to “remain vigilant of potential phishing attacks or social engineering attempts” using the stolen data. That is the right risk frame: attackers do not need a vault if they can trick a user or employee into handing over access.

The incident also sharpens the reputational problem because LastPass has been here before in different forms.

Year Reported incident Vault impact reported
2015 Hackers obtained account email addresses, password reminders, authentication hashes, and cryptographic salts LastPass said encrypted vault data was not accessed
2022 An attacker compromised a developer account, stole source code and technical information, then accessed cloud backups containing customer records and encrypted password vaults Encrypted password vaults were accessed, along with unencrypted names, billing addresses, email addresses, and phone numbers
2026 Hackers accessed LastPass customer data through Klue-linked access to CRM/support systems LastPass says password vaults were not affected

For readers tracking how hidden supplier dependencies keep surfacing in tech risk, MLXIO’s Future Trends Everyone Keeps Misreading — Here's Why and Key Trends Reveal the Next Tech and Finance Shake-Up offer broader context on why indirect exposure can matter as much as the headline product.

LastPass also published technical indicators tied to the attackers. Security teams can search for related activity using these details:

  • IP addresses: 138.226.246[.]94, 94.154.32[.]160, 159.183.215[.]61, 159.183.181[.]239
  • Email sender domains: baccarat.com[.]au, robinskitchen.com[.]au, house.com[.]au

That list is useful for enterprise defenders. For individual users, the more likely exposure is a convincing email, text, or phone call that references real support or account details.


LastPass users should verify alerts and tighten account security now

Users who receive a breach notice should verify it through official LastPass channels before clicking links or opening attachments. Unexpected emails claiming to be about this incident deserve extra scrutiny, especially if they push urgency around account resets, vault access, or software updates.

LastPass users should not share their master password with anyone. If LastPass directly advises a master password change for a specific account, users should follow that guidance through the official site or app rather than through an emailed link.

Practical steps now:

  • Verify: Check notices by going directly to LastPass’s official website or app, not through unsolicited links.
  • Review MFA: Confirm multi-factor authentication is enabled and tied to trusted devices or apps.
  • Watch accounts: Monitor accounts tied to exposed contact details, especially if a support case included sensitive context.
  • Scrutinize support claims: Treat calls or emails referencing LastPass support history as potentially hostile unless independently verified.
  • Preserve evidence: Save suspicious messages, headers, sender domains, and timestamps for security teams or LastPass support.

The next disclosures matter. Watch whether LastPass provides a count of affected users, expands the data categories, releases more indicators, or says whether regulators have contacted the company or Klue.

The immediate scenario is clear: vaults are not reported compromised, but attackers may now have enough customer context to make scams look personal. That makes user verification, not panic, the first line of defense.

Impact Analysis

  • LastPass says password vaults were not affected, but exposed CRM and support data can still enable targeted phishing.
  • The breach came through Klue, showing how third-party vendors can create security risk for trusted services.
  • LastPass revoked Klue access, rotated exposed API tokens, notified law enforcement, and began investigating the incident.

Data Impact From the Klue Breach

Data categoryStatusReader risk
Customer vaultsNot affectedStored passwords were not exposed according to LastPass
Business contact and CRM dataAccessedNames, phone numbers, emails, physical addresses, and customer relationship data could aid phishing
Support and sales-related dataAccessedAttackers may use account-specific details to impersonate support or craft targeted lures
MLXIO

Written by

MLXIO Insights Team

Algorithmic Research & Human Oversight

Powered by advanced algorithmic research and perfected by human oversight. The Insights Team delivers highly structured, cross-verified analysis on emerging tech trends and digital shifts, filtering out the fluff to give you high-fidelity value.

Related Articles

person typing on silver MacBook
CybersecurityJul 26, 2026

Phishing Fails Can Cost Binance Workers Their Jobs

Binance treats repeated phishing failures as a job risk, not a training nuisance, with $137.7B in assets on the line.

9 min read

person using laptop computer holding card
CybersecurityJun 23, 2026

6,843 Fake Domains Turn Amazon Prime Day Into a Trap

Prime Day’s biggest deal may be bait: 6,843 fake domains were ready before shoppers arrived.

7 min read

a man wearing a mask
CybersecurityMay 24, 2026

Scammers Abuse Real Microsoft Address to Push Phishing

Scammers used a real Microsoft alert address to send phishing links for months, turning trusted security emails into a risk.

6 min read

a hand holding a black device
CybersecurityMay 26, 2026

185,000 People Get SSNs Spilled in 7-Eleven Data Breach

A 7-Eleven breach exposed SSNs, licenses and personal data for 185,000+ people, raising long-term identity-theft risks.

6 min read

red padlock on black computer keyboard
CybersecurityMay 13, 2026

77% Hit by Data Breaches — Top Privacy Tools to Shield You in 2026

With 77% of security pros hit by breaches, these top privacy tools in 2026 help you block trackers and secure your online identity.

10 min read

two black fish finders on a fishing boat
TechnologyAug 5, 2026

Apple CarPlay Grabs the Helm on 2027 Pontoon Boats

Apple CarPlay and Android Auto are coming standard to select 2027 Crest and Balise pontoons with Savvy Navvy navigation.

7 min read

a person holding a smart phone in their hand
TechnologyAug 4, 2026

18-Hour Motorola Razr Fold Leaves Samsung Chasing Hard

Motorola’s Razr Fold hit 18h22m browsing, beating Samsung’s Galaxy Z Fold7 by about four hours.

7 min read

person clicking Apple Watch smartwatch
TechnologyAug 4, 2026

51 New Workout Modes Fix Amazfit Helio Strap's Big Gap

Amazfit Helio Strap firmware 3.22.0.1 adds 51 workout modes, VO2 Max tweaks and phased global rollout via Zepp.

5 min read

Nightstand with a lamp, clock, and chargers.
TechnologyAug 4, 2026

ChargeUltra G4 Bets $40 Can Kill Nightstand Clutter

ChargeUltra G4 packs a charger, clock, alarms, and light into a $40 Kickstarter—but delivery is not due until October 2026.

7 min read

icon
TechnologyAug 4, 2026

WhatsApp Group Chats Grab an @all Panic Button Today

WhatsApp is adding @all alerts, tighter poll controls and easy spin-off groups to stop decisions from getting buried in busy chats.

6 min read

Stay ahead of the curve

Get a weekly digest of the most important tech, AI, and finance news — curated by AI, reviewed by humans.

No spam. Unsubscribe anytime.