1. Executive summary
On 12 June 2026, LastPass was notified that market-intelligence platform Klue had suffered a security incident in which an attacker obtained OAuth tokens that Klue held for its customers' connected integrations (notably Salesforce and Gong). The attacker used those tokens to access LastPass's Salesforce environment and exfiltrate CRM-resident customer data. LastPass confirms that its products, services, and infrastructure were not affected, and customer password vaults remained secure. Exposed data is limited to CRM/business records: customer names, phone numbers, email addresses, physical addresses, support-case information, and sales/CRM data. No Gong (call/email) data was accessed. The "Icarus" extortion group has claimed the attack; this attribution is unconfirmed — the tradecraft is consistent with the ShinyHunters cluster (Salesforce, Salesloft Drift, Gainsight), and Icarus may be a persona or offshoot rather than a distinct actor. For EMEA financial-services firms, the bottom-line risk is targeted phishing/social-engineering of named contacts and CRM data leakage, not credential or vault compromise.
2. Regulatory framing
| Article | Trigger (fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28 (ICT third-party risk — general principles) | Klue is an ICT third-party provider integrated with LastPass's Salesforce and Gong environments; the breach originated in Klue's infrastructure. | Firms using Klue, or any vendor that holds OAuth tokens for Salesforce/Gong integrations, must reassess third-party risk for that vendor and document compensating controls. |
| DORA Art. 29 (preliminary assessment of ICT concentration risk) | Klue integrations (Salesforce, Hubspot, Zoom, Google Drive) represent a concentration point: a single vendor compromise yields broad CRM access across many customers. | Identify and document concentration risk where the same vendor holds tokens for multiple critical SaaS integrations; consider multi-vendor or token-isolation strategies. |
| DORA Art. 30 (key contractual provisions with ICT third-party providers) | Klue held OAuth tokens for LastPass's Salesforce/Gong; LastPass had to rotate tokens and disable access post-incident. | Review vendor contracts for token-rotation obligations, breach-notification SLAs, and audit/right-to-inspect clauses covering OAuth and integration credentials. |
| NIS2 Art. 21(2)(d) (supply chain security measures) | Attack vector was a compromised legacy credential at a supply-chain vendor (Klue integration service). | Supply-chain security assessments must cover legacy/integration-service credentials, not only primary application access. |
| DORA Art. 17 / Art. 18 / Art. 19 (ICT-related incident management; classification; reporting) | A major ICT-related incident at a third-party ICT service provider (Klue) with downstream impact on a financial entity's CRM data may meet classification thresholds. | Run incident-management process; classify per Art. 18 criteria; report major incidents to competent authorities per Art. 19 timelines. |
| UK NIS 2018 (OES/RDSP duties) | OES/RDSP entities using LastPass or Klue for CRM/Salesforce workflows may have incident-handling duties triggered by downstream CRM data exposure. | Assess whether the incident meets UK NIS reporting thresholds and notify the appropriate competent authority if so. |
3. Technical analysis & attack chain
- Initial access (Klue). Attacker obtained access to Klue's infrastructure via a compromised legacy credential associated with an integration service (per Klue's disclosure). No CVE or software vulnerability is implicated; the vector is credential-based.
- Token theft. From within Klue, the attacker stole OAuth tokens that Klue's customers had used to connect Klue to third-party services — primarily Salesforce, with Gong also integrated. Klue also holds integrations for Hubspot, Zoom, and Google Drive.
- Lateral pivot to customers. The attacker used the stolen tokens to authenticate to each victim's Salesforce environment as the Klue integration, bypassing normal user authentication and MFA.
- Data access and exfiltration. The attacker connected to LastPass's Salesforce environment and exfiltrated CRM data. Huntress and ReliaQuest detected anomalous Salesforce activity and notified Klue. LastPass's investigation found no evidence of access to Gong-resident data (calls/emails).
- Extortion phase. The "Icarus" group posted Klue on its dark-web leak site and is attempting to extort both Klue and downstream victims directly.
- Containment actions (LastPass). LastPass disabled employee access to Klue, rotated the exposed API/OAuth tokens, and notified law enforcement. Klue revoked credentials, tokens, and active integrations across its platform.
Technical specifics relevant to defenders
- Compromised component: Klue integration service (legacy credential). No CVE or CVSS score is associated with this incident; it is a credential/identity failure, not a software vulnerability.
- Affected integrations at Klue: Salesforce (primary target — where sensitive financial and PII data typically resides), Gong, Hubspot, Zoom, Google Drive.
- Data exposed (LastPass): customer names, phone numbers, email addresses, physical addresses, support-case information, sales/CRM-related data.
- Data NOT exposed: LastPass password vaults, product/infrastructure systems, Gong call/email data.
- Known downstream victims (per public reporting): LastPass, Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, Huntress, ReliaQuest, Klue itself. Victim list is expected to grow.
- Threat-actor sender domains flagged by LastPass as used in social-engineering lures:
baccarat.com[.]au,robinskitchen.com[.]au,house[.]com.au. - Attribution status: "Icarus" claim is unconfirmed. The tradecraft (legacy-credential pivot → OAuth token theft → Salesforce CRM exfiltration → extortion) matches the ShinyHunters cluster's prior campaigns against Salesforce, Salesloft Drift, and Gainsight. Icarus may be a persona, an offshoot, or a collaborator; treat attribution as unconfirmed.
4. Mitigation & containment
P1 — within 24 hours
- Revoke and rotate any OAuth tokens, API keys, or integration credentials issued to or via Klue for Salesforce, Gong, Hubspot, Zoom, Google Drive, or any other Klue-connected service.
- Audit Salesforce/Gong access logs for the period 12 June 2026 to date for activity originating from Klue integration IPs/service principals; identify and export any anomalous data exports, report runs, or bulk API calls.
- Block sender domains
baccarat.com[.]au,robinskitchen.com[.]au,house[.]com.auat the email gateway; brief front-line staff on the social-engineering risk. - Disable or restrict the Klue integration in Salesforce/Gong until vendor provides post-incident assurance.
P2 — within 72 hours
- Inventory all third-party integrations that hold OAuth tokens against Salesforce, Workday, NetSuite, or any CRM/ERP. Document token-issuance date, scope, and rotation cadence.
- Enforce IP-allowlisting / connected-app policies in Salesforce so that integration tokens cannot be replayed from arbitrary IPs.
- Review Salesforce Event Monitoring (or equivalent) for bulk read/export events; correlate against known Klue integration identifiers.
- Vendor risk review of Klue: require written post-incident report, root-cause for the legacy credential, evidence of credential rotation across all integration services, and updated breach-notification SLA.
P3 — within 7 days
- Contractual remediation (DORA Art. 30 alignment): ensure Klue (or equivalent vendor) contracts include token-rotation obligations, audit rights, and incident-notification SLAs consistent with DORA Art. 30.
- Concentration-risk assessment (DORA Art. 29): document whether Klue (or any single vendor) holds tokens for multiple critical SaaS integrations; consider diversification or token-isolation.
- User communications: notify affected customers of the CRM data exposure and the elevated phishing risk; reinforce that master passwords and vaults were not compromised.
- Threat-intel monitoring: subscribe to Klue's incident updates and monitor for Icarus extortion posts naming your organisation.
5. Indicators of compromise
| Type | Value | Confidence | Source |
|---|---|---|---|
| domain | baccarat.com[.]au |
High (named by LastPass as attacker sender domain) | LastPass advisory via BleepingComputer |
| domain | robinskitchen.com[.]au |
High (named by LastPass as attacker sender domain) | LastPass advisory via BleepingComputer |
| domain | house[.]com.au |
High (named by LastPass as attacker sender domain) | LastPass advisory via BleepingComputer |
domain baccarat.com.au
domain robinskitchen.com.au
domain house.com.au
6. Detection
Insufficient indicators to author a YARA rule (no malware artefacts, file paths, registry keys, or distinctive strings are present in the source material).
A Sigma rule is provided for the social-engineering/phishing vector based on the sender domains flagged by LastPass.
title: Suspicious Sender Domain Associated With Klue Supply Chain Attack (Icarus)
id: ad8f3c10-4b21-4f9e-9c2a-7d1f6b5e4a01
status: experimental
description: |
Detects inbound email from sender domains flagged by LastPass as used by
threat actors in the Klue supply chain attack (June 2026). These domains
have been observed in social-engineering lures targeting exposed CRM
contacts.
author: Adverse Trace
date: 2026-06-23
references:
- https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/
logsource:
product: email
category: email
detection:
selection_domains:
FromDomain|endswith:
- "baccarat.com.au"
- "robinskitchen.com.au"
- "house.com.au"
condition: selection_domains
falsepositives:
- Legitimate business correspondence from the listed domains (unlikely; treat any as suspicious and triage)
level: high
tags:
- attack.initial_access
- attack.t1566
- cve.na
7. Sources
- BleepingComputer — LastPass confirms data breach in Klue supply chain attack — https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/ — 2026-06-23
- BleepingComputer — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ — 2026-06-21
- SecurityWeek — Cybersecurity Firms Impacted by Klue Supply Chain Attack — https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ — 2026-06
- Risky Business News — Risky Bulletin: Klue breach impacts security firms — https://news.risky.biz/risky-bulletin-klue-breach-impacts-security-firms/ — 2026-06
- DataBreaches.net — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://databreaches.net/2026/06/21/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ — 2026-06-21
- Snyk Vulnerability Blog — When a vendor's breach becomes yours: lessons from the Klue incident — https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/ — 2026-06
8. Adverse Trace position
Severity: Moderate. This is a third-party/supply-chain incident with CRM-data exfiltration and an active extortion campaign, but no compromise of LastPass products, infrastructure, or password vaults. The primary residual risk to EMEA financial-services clients is targeted phishing and social-engineering against named contacts whose CRM data (name, email, phone, address, support history) is now in attacker hands; the flagged sender domains (baccarat.com[.]au, robinskitchen.com[.]au, house[.]com.au) confirm active lure activity. Attribution to "Icarus" is unconfirmed and the tradecraft aligns with the ShinyHunters cluster — treat as a single threat-actor family until evidence diverges. Client impact: firms using LastPass, Klue, or any vendor holding Salesforce/Gong OAuth tokens should rotate tokens, audit Salesforce access logs back to 12 June, and review vendor contracts and concentration risk under DORA Arts. 28–30 and NIS2 Art. 21(2)(d). Next steps: Adverse Trace will (1) monitor for additional victim disclosures and Icarus extortion posts, (2) update this advisory if Klue publishes a post-incident report or if new IOCs emerge, and (3) assist clients with Salesforce Event Monitoring review and DORA Art. 29 concentration-risk documentation on request.
Published via PulseTrace — Adverse Trace threat intelligence.