1. Executive summary
LastPass has disclosed that attackers exfiltrated customer personal information and customer support case records from its Salesforce environment after OAuth tokens were compromised in a supply-chain attack on Klue (klue.com), a third-party market intelligence platform. The incident, which LastPass was made aware of on June 12, 2026, affected Klue's integrations with LastPass's Salesforce and Gong systems. Over a dozen Klue customers — including BeyondTrust, HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium — have confirmed similar Salesforce data theft, making this a multi-organisation cascading supply-chain event. EMEA financial services using LastPass for credential management should assess exposure of support case data, which may contain sensitive operational context, credential references, or identity verification material.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28: ICT third-party risk — general principles | LastPass customer data was compromised via Klue, a third-party ICT provider integrating with Salesforce and Gong. | Financial institutions using LastPass must assess third-party risk exposure from the Klue supply-chain breach under their ICT third-party risk framework. |
| DORA Art. 17: ICT-related incident management process | LastPass was notified of the Klue incident on June 12 and launched an incident response process. | Institutions must ensure their own incident management process accounts for cascading third-party breach notification and containment. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | Customer personal information and support case records were stolen — a data exfiltration incident with potential classification as a major ICT-related incident depending on data sensitivity. | Institutions must classify this incident per their DORA classification criteria; if support case data contains sensitive financial or identity data, it may meet major-incident thresholds. |
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | If the exfiltrated data meets major-incident criteria, reporting to competent authorities is required. | Assess whether exposed support case data triggers major-incident reporting obligations; document the assessment rationale. |
| NIS2 Art. 21(2)(d): supply chain security measures | The breach originated in Klue, a third-party supplier, and cascaded to Klue customers' Salesforce environments via compromised OAuth tokens. | NIS2-regulated entities must evaluate supply-chain security measures covering SaaS integrations and OAuth token management. |
3. Technical analysis & attack chain
Attack chain (confirmed steps)
- Initial compromise of Klue. Attackers gained access to Klue (klue.com), a market intelligence platform. The specific initial access vector at Klue has not been disclosed in the available sources. Snyk's analysis characterises the root cause as "a forgotten credential at vendor Klue" that let attackers reach customers' Salesforce data — single-sourced; verify before enforcement.
- OAuth token theft. Attackers obtained OAuth tokens from Klue that were used to authenticate integrations with customer Salesforce environments. The mechanism by which these tokens were compromised (e.g., credential exposure in Klue's infrastructure, token storage compromise) is not detailed in the available sources.
- Salesforce access via stolen OAuth tokens. Using the compromised OAuth tokens, attackers authenticated to LastPass's Salesforce environment. Klue integrates with Salesforce and Gong systems across its customer base; the OAuth integration provided a trusted authentication path into customer CRM data.
- Data exfiltration. Attackers accessed and stole customer personal information and customer support case records from the Salesforce environment. The specific data fields, volume, and scope of exfiltrated records have not been disclosed in the available sources.
- Multi-organisation impact. The same compromised Klue integration was used to access Salesforce instances at over a dozen Klue customers. SecurityWeek reports confirmed impact at BeyondTrust, HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, and Tanium, in addition to LastPass.
Technical specifics
- Affected platform: Klue (klue.com) — market intelligence platform integrating with CRM and sales tools.
- Affected LastPass systems: Salesforce environment and Gong integration.
- Authentication mechanism exploited: OAuth tokens (integration tokens between Klue and Salesforce).
- Data accessed: Customer personal information and customer support case records.
- Notification date: June 12, 2026 — LastPass was made aware of the Klue incident.
- No CVE, malware family, C2 infrastructure, persistence mechanism, or privilege escalation technique is identified in the available sources. This is a credential-theft-driven SaaS supply-chain compromise, not a traditional endpoint exploitation chain.
Caveats
- The characterisation of the root cause as "a forgotten credential" is single-sourced (Snyk blog); verify before enforcement.
- No MITRE ATT&CK technique IDs, no named threat actor, and no CISA-KEV entries are associated with this item. Attribution is unconfirmed — no actor has been named in any source.
- The specific LastPass customer data fields exposed have not been enumerated in the sources. The term "personal information" is used by LastPass but not defined.
4. Mitigation & containment
P1 — Within 24 hours
- Identify LastPass usage. Determine whether your organisation uses LastPass as a password manager or has open support cases containing sensitive operational data, credentials, or identity verification material.
- Audit support case history. Review all LastPass support cases submitted by your organisation. Flag any cases containing: production credentials, infrastructure details, identity documents, financial data references, or PII. Assume this data is compromised.
- Revoke and rotate credentials. If any support case or personal information shared with LastPass contains credentials or secrets, revoke and rotate them immediately. Priorise: shared passwords, API keys, service-account credentials, and any secrets referenced in support correspondence.
- Notify affected individuals. If employee personal information was shared in support cases (e.g., for identity verification), notify affected individuals per your breach-notification process.
P2 — Within 72 hours
- Audit OAuth integrations. Inventory all third-party SaaS platforms that hold OAuth tokens for your Salesforce, Gong, or other CRM environments. Identify any integrations with Klue or similar market-intelligence platforms. Review token scopes and permissions.
- Revoke unnecessary OAuth tokens. Revoke OAuth tokens for third-party integrations that are non-essential or have excessive scopes. Re-enforce least-privilege token scopes for remaining integrations.
- Review Salesforce audit logs. Pull Salesforce login history and data-export logs for the period from early June 2026 onward. Look for: anomalous IP access, data-export or report-export events, API access from unfamiliar locations, and bulk-data-access patterns. Salesforce audit trails are accessible via Setup > Environments > Monitoring > View Audit Trail.
- Assess DORA incident classification. Per DORA Art. 18, classify this incident. If support case data contained sensitive financial operational data, assess whether it meets the threshold for a major ICT-related incident requiring reporting under DORA Art. 19.
P3 — Within 7 days
- SaaS integration governance. Establish or update policy governing third-party OAuth integrations to production CRM and collaboration platforms. Require: token scope review, periodic token rotation, integration inventory, and vendor security assessment before granting OAuth access.
- Supply-chain risk assessment. Per DORA Art. 28 and NIS2 Art. 21(2)(d), update your ICT third-party risk register to include SaaS integration platforms (like Klue) that hold authentication tokens to your environment. Assess concentration risk per DORA Art. 29 if multiple critical SaaS integrations share a common platform.
- Contractual provisions. Per DORA Art. 30, ensure contracts with SaaS integration providers include breach-notification SLAs, security audit rights, and incident-information obligations.
- DORA resilience testing. Per DORA Art. 24, consider incorporating third-party SaaS integration compromise scenarios into operational resilience testing.
5. Indicators of compromise
No indicators of compromise available in the source material. No file hashes, IP addresses, domains, mutex names, or specific artefact identifiers were disclosed in the available sources.
6. Detection
The sources contain one usable artefact for detection purposes: the domain klue.com, which is the legitimate Klue platform domain. However, since Klue is a legitimate service and blocking it would disrupt business operations, and no malicious infrastructure indicators (attacker IPs, domains, or C2 endpoints) are provided, there are no actionable detection rules to author.
Insufficient indicators to author detection rules.
Behavioural detection recommendation (manual, not a rule): In Salesforce, query login history and data-access events for OAuth-authenticated sessions originating from Klue integration tokens during June 2026. Look for data-export, report-export, or bulk-data-access events associated with these sessions. This requires Salesforce admin access and is not automatable from the current source material.
7. Sources
- DataBreaches.net — "LastPass says hackers stole customer support case data during Klue breach" — https://databreaches.net/2026/06/24/lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/?pk_campaign=feed&pk_kwd=lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach — 2026-06-24
- BleepingComputer — "LastPass confirms data breach in Klue supply chain attack" — https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/ — 2026-06-24
- Help Net Security — "LastPass customer data exposed through Klue supply chain attack" — https://www.helpnetsecurity.com/2026/06/24/lastpass-klue-data-breach-salesforce-environment/ — 2026-06-24
- SecurityWeek — "BeyondTrust, LastPass Impacted by Klue-Salesforce Incident" — https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/ — 2026-06-24
- Snyk Vulnerability Blog — "When a vendor's breach becomes yours: lessons from the Klue incident" — https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/ — 2026-06-24
- SecurityWeek — "More Cybersecurity Firms Disclose Impact From Klue Hack" — https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ — 2026-06-24
8. Adverse Trace position
Severity assessment: is appropriate. This is a confirmed supply-chain data breach affecting a password-manager vendor widely used in financial services. No CVE, no CISA-KEV entry, no named threat actor, and no malware indicators are associated with this item — the risk is data-exfiltration via compromised SaaS OAuth integration, not endpoint exploitation. The "forgotten credential" root-cause characterisation is single-sourced (Snyk); attribution is unconfirmed. Client-impact assessment: EMEA financial services clients using LastPass should immediately audit support case history for sensitive data exposure and rotate any credentials shared in support correspondence. The cascading nature of this incident — over a dozen Klue customers confirmed affected, including multiple cybersecurity vendors — elevates the risk that adversary reconnaissance of stolen support case data could inform targeted attacks against affected organisations. Clients should also audit their own third-party OAuth integrations to Salesforce and CRM platforms, as the Klue compromise demonstrates the systemic risk of SaaS integration tokens as an attack vector. Next steps: Adverse Trace will monitor for: disclosure of specific data fields exposed, IOCs from the Klue-side investigation, any named threat actor, and impact on additional financial-services organisations. We will issue an update if material new information emerges.
Published via PulseTrace — Adverse Trace threat intelligence.