LastPass warned its users due to the data breach at its business partner Klue. It was stated that the password safes were safe.
LastPass users faced a new security warning regarding the theft of their personal information. This time, the information breach occurred through Klue, one of the company’s external business partners.
LastPass is contacting affected users via email and informing them about the situation. The company particularly emphasizes that password safes are not affected by this incident.
Scope and details of the data breach
The breach at market research firm Klue allowed attackers to access customer information and reinforcement request data. According to the statement made by LastPass, the captured information was limited to standard business contact information and customer interest management information.
This information includes customer names, telephone numbers, e-mail addresses and physical addresses, as well as records regarding the basis request and sales. The company stated that it revoked employee access to Klue and renewed the exposed API keys as soon as it learned of the incident.
LastPass announced that it notified law enforcement and launched a detailed investigation in coordination with both Klue and Salesforce. It is said that the Klue platform works integrated with Salesforce and Gong systems.
The company advises its customers to be careful against possible phishing attacks or social engineering attempts that may arise from this leak. LastPass also suggested scanning systems by sharing IP addresses and e-mail sending domain names that were determined to be in contact with attackers.
Past security incidents
This is not the first security problem that LastPass has experienced, and the company has come to the fore with similar incidents in the past. In 2015, attackers obtained account email addresses, reminder passwords, and authentication summaries.
More recently, in 2022, an attacker took over the developer account and gained access to the source code and technical information. As a result of this attack, in addition to encrypted password vaults, unencrypted data such as names, billing addresses and phone numbers were also compromised.
Do you use LastPass and will you continue to use the platform following the latest leak?