π€ The Open-Palm Breach Report
LastPass has confirmed β and yes, we know you’re tired of sentences that begin this way β that customer data was exposed after the Icarus extortion group compromised Klue, an AI-powered market intelligence platform, stole its OAuth tokens, and used them to waltz into LastPass’s Salesforce environment like they had a meeting booked.
The data stolen includes:
- Customer names, phone numbers, email addresses, and physical addresses
- Support case information and CRM records
- Sales-related data from the Salesforce environment
LastPass has emphasized that its products, services, and infrastructure were not affected, and customer password vaults remain secure. Which is reassuring in the way that a restaurant telling you “the kitchen is fine, we only lost the guest list and everyone’s home address” is reassuring.
The company became aware of the incident on June 12th. It has since disabled employee access to Klue, rotated the exposed API and OAuth tokens, and notified law enforcement.
π The Two-Handed Supply Chain Dissection
Let us trace the chain, because it is exquisite.
Klue is an AI-powered competitive intelligence platform β the kind of tool your marketing team uses to track what your competitors are saying. It integrates with Salesforce and Gong to pull in CRM and sales call data. LastPass’s go-to-market teams used it. So did Recorded Future. And Tanium. And Jamf. And Sprout Social. And Gong itself. And Insurity.
The Icarus group compromised Klue’s infrastructure using legacy credentials for an integration service β because of course they did. In the great taxonomy of breach root causes, “legacy credentials that nobody remembered existed” sits right between “default password” and “the intern’s API key” in the Hall of Preventable Sadness.
Once inside Klue, the attackers harvested OAuth tokens β the authentication credentials that allow third-party applications to access data in connected systems. Think of OAuth tokens as digital valet keys: they don’t unlock the whole car, but they absolutely let you drive it wherever you want. In this case, the destination was LastPass’s Salesforce instance, which contained enough customer PII to fuel a phishing campaign that could run for years.
The Icarus group then launched an extortion campaign using spoofed sender domains including baccarat.com.au, robinskitchen.com.au, and house.com.au β Australian retail domains that suggest the threat actors either compromised additional infrastructure or have a very specific taste in kitchenware and gambling.
πΏ The Gentle Awakening
Here is the part where we pause and contemplate the architecture of modern enterprise trust.
LastPass did not get breached. LastPass’s vendor got breached. The vendor’s integration service credentials got breached. Those credentials granted access to OAuth tokens, which granted access to Salesforce, which contained customer data. That is four degrees of separation between the original vulnerability and the data that walked out the door.
This is not a failure of LastPass’s security. This is a failure of the concept of having vendors. Every SaaS tool your company connects to Salesforce is a potential supply chain attack. Every OAuth token is a promise that someone else’s security is as good as yours. And every “AI-powered market intelligence platform” that your marketing team adopted during a quarterly planning session is now a threat vector with a landing page and a free trial.
For LastPass specifically, this is the company’s latest in a series of security incidents, following the significant breaches in 2022 that exposed encrypted customer vault data. The password manager has become the industry’s most reliable recurring character in breach notification emails β a status that no amount of OAuth token rotation can fully remediate.
π The Gold-Leaf Reckoning
The Klue breach is a case study in what happens when the software supply chain becomes so long that nobody can see both ends at the same time. Seven companies confirmed affected. Legacy credentials that nobody rotated. OAuth tokens that connected platforms like a daisy chain of implicit trust. An extortion group that named itself after the mythological figure who flew too close to the sun, which is either very on-the-nose or the most self-aware threat actor branding in history.
The lesson, as always, is not new: your security posture is only as strong as your least-audited vendor’s oldest integration credential. But knowing the lesson and learning it are, in enterprise security, two entirely different budget line items.
LastPass customers should watch for phishing attempts using their exposed contact information. The threat actors now have names, emails, phone numbers, and addresses β which is everything you need to craft a convincing social engineering attack and nothing you need to access a password vault. Small comfort, but comfort nonetheless. Your passwords are safe. Your inbox is not.
“The AI-powered market intelligence platform was compromised via legacy credentials that nobody remembered existed, which granted access to OAuth tokens that nobody audited, which connected to Salesforce instances that nobody monitored. Other than that, the security architecture was flawless.” β The Slap of Wisdom Incident Response Team, currently auditing its own vendor list and finding three integrations it didn’t know it had