Klue security incident affects LastPass, customer phone numbers, addresses, and other CRM data leaked

robot
Abstract generation in progress
ME News Update, June 24 (UTC+8), Password management tool LastPass announced that its third-party market intelligence platform Klue experienced a security incident, with hackers stealing OAuth tokens held by multiple clients (including LastPass) and using these tokens to access LastPass's Salesforce CRM system, potentially exposing some customer names, phone numbers, email addresses, home addresses, support case details, and CRM data. The official reminder: LastPass's products, services, infrastructure, and customer vaults were not affected, and Gong system data was not accessed. LastPass has taken immediate measures, including suspending employee access to Klue, rotating exposed API tokens, conducting a detailed investigation, and collaborating with Klue, Salesforce, and law enforcement agencies. Additionally, threat intelligence has been shared with the security community via the TIME team, and future protections have been strengthened. Users should remain vigilant against phishing emails, calls, or social engineering attacks that may exploit leaked information, and remember that LastPass will never ask for the master password; all official communications are sent through trusted channels. (Source: ChainCatcher)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments