LastPass Confirms Customer CRM and Support Data Stolen in Klue Data Breach — What We Know

LastPass Confirms Customer CRM and Support Data Stolen in Klue Data Breach — What We Know

You are currently viewing LastPass Confirms Customer CRM and Support Data Stolen in Klue Data Breach — What We Know
LastPass says customer contact details and support case records were stolen after hackers breached its technology partner, Klue. The company's password vaults were not affected.

A Klue security incident let hackers access LastPass customer data stored in Salesforce. Here’s what was taken, why phishing risks may follow, and how you can protect yourself now online.

What Happened?

According to LastPass, the password manager company learned about the Klue security incident on June 12.

Klue is a third-party market intelligence platform used by LastPass sales and marketing teams.

The platform connects with Salesforce and Gong, two business tools used to manage customer and sales information.

LastPass said hackers used credentials taken in the Klue incident to access LastPass customer data stored in Salesforce.

The company began investigating after learning about the incident.

Who Was Affected and What Data Was Accessed?

LastPass did not say how many customers were affected.

The accessed information included customer names, phone numbers, email addresses, physical addresses, support case data, and sales-related data.

LastPass said customer vaults (secure digital storage for passwords and other login information) remained secure. Its products, services, and infrastructure were not affected.

The company also found no evidence that hackers accessed data connected to Gong.

Details such as your name, email, phone number, and address can help criminals make phishing messages sound more believable.

Many people also do not know their information was exposed in earlier data breaches or data leaks until suspicious messages or activity appear.

If you are unsure whether your information was leaked elsewhere, automatic monitoring can help you spot problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

How Hackers Used Klue Access Tokens to Reach LastPass Data

Klue held OAuth tokens for LastPass and other customers. OAuth tokens are digital keys that let apps connect without sharing a password.

Hackers obtained these tokens and used the LastPass connection to access customer data inside Salesforce.

LastPass then stopped employee access to Klue and replaced the affected digital access keys.

The company also worked with Klue and Salesforce, notified law enforcement, and added more safeguards.

Check if your email was found in a leak

Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.

Run a free check

Why a Company You Never Used Can Still Put Your Data at Risk

You may never have heard of Klue, yet its security incident still affected data connected to LastPass. That is because companies often use outside services for sales, support, analytics, and other work.

Each connection can create another path to stored information. 

According to Verizon’s 2025 Data Breach Investigations Report, third-party services were involved in 30% of data breaches, twice the previous share.

That means a security problem at one company can put another company’s customer data at risk. 

Even when your passwords remain safe, contact details can help criminals make a message feel personal.

A fake support request may include your name, phone number, or details from an earlier case.

That is why unexpected messages deserve a second check, especially when they ask for passwords or urgent action.

Person checking a message on a smartphone after the LastPass data breach, with guidance on spotting phishing attempts.
After the LastPass breach, customers should be cautious of messages that use personal details or ask for passwords, payments, or immediate action.

3 Simple Ways to Lower Your Phishing Risk

These simple habits can help you respond more safely after a data breach:

1. Question messages that ask for your master password

Watch for emails, calls, or messages claiming to be from LastPass and asking for your master password (the main password that unlocks all passwords stored in LastPass).

LastPass says its staff will never ask for that password, so such a request is a strong warning sign.

Do not reply or use links in the message. Open LastPass through your saved bookmark or official support site instead.

2. Protect your main email account

Be alert if you reuse an email password or have no two-step verification. Your email can reset many other accounts, so a takeover can spread quickly.

Open your email account’s Security settings, choose Two-Step Verification, and follow the prompts to add an authenticator app.

If you need help, the Futureproof Email Protection tool guides you through the process step by step.

Email Protection helps you create strong passwords and set up two-step verification to secure your account.

3. Verify messages that use your personal details

Be careful with messages that mention your name, address, phone number, or a recent support issue.

Criminals can use real details to make phishing messages feel trustworthy.

Contact the company through its official website or saved phone number before sharing information or taking action.

Your Data Can Be Reached Through Companies You Never See

The LastPass incident shows how one outside service can create risk for another company’s customers.

Your best defense is to slow down when messages use personal details, protect your email, and verify unusual requests.

Tools like Futureproof can also help you spot leaked information earlier and take clear steps before problems grow.

Those habits give you more control and peace of mind, even when a trusted company uses other services.