{"id":370855,"date":"2026-06-24T06:04:00","date_gmt":"2026-06-24T13:04:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=370855"},"modified":"2026-06-24T06:04:20","modified_gmt":"2026-06-24T13:04:20","slug":"lastpass-confirms-2026-customer-data-breach-klue-hack-exposed-salesforce-data","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/lastpass-confirms-2026-customer-data-breach-klue-hack-exposed-salesforce-data\/","title":{"rendered":"LastPass confirms 2026 customer data breach: Klue hack exposed Salesforce data"},"content":{"rendered":"<p class=\"wp-block-paragraph\"><a href=\"https:\/\/lastpass-free-password-manager-chrome.en.softonic.com\/\" rel=\"noopener\">LastPass<\/a> said in a <strong>June 2026<\/strong> notice that it was affected by a security breach tied to <a href=\"https:\/\/klue.en.softonic.com\/\" rel=\"noopener\">Klue<\/a>. According to the company, the incident exposed OAuth tokens, gave attackers access to LastPass data stored in Salesforce, and may also have exposed customer contact records and support data. LastPass also says password vaults and master passwords were not affected.<\/p>\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" alt=\"Bitwarden\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/ccc9bd58-7ab2-4d67-ad2c-4dc5c6f2091e\/2905767400\/bitwarden-logo\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Bitwarden<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/bitwarden.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">Download<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/bitwarden.en.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">In LastPass\u2019s account of what happened, the attackers breached Klue first, then used stolen customer tokens to get into Salesforce, along with systems connected to Salesforce and <a href=\"https:\/\/gong.en.softonic.com\/\" rel=\"noopener\">Gong<\/a>. The company says it has since <strong>revoked that access<\/strong>, blocked employees from using Klue, and started an investigation.<\/p>\n\n<p class=\"wp-block-paragraph\">LastPass says your password vault and master password weren\u2019t affected. Still, <strong>customer contact records<\/strong> may have been exposed. So if you get an unexpected message that appears to be from LastPass, be extra careful, especially if it asks for credentials, payment, or urgent action on your account.<\/p>\n\n<p class=\"wp-block-paragraph\">If you use LastPass regularly, take this seriously. Attackers don\u2019t need access to your vault to do damage; stolen CRM data can be enough to fuel convincing phishing emails and fake support scams. And this comes after LastPass\u2019s much more serious <strong>2022<\/strong> breach, later reports in 2023 and 2024 about offline cracking, reports of crypto theft tied to seed phrases, a \u00a31.23 million fine from the UK Information Commissioner\u2019s Office in 2025, a $24.5 million class-action settlement, and reports linking this Klue attack to Icarus and other affected companies, including Recorded Future, Tanium, Jamf, <a href=\"https:\/\/sprout-social.en.softonic.com\/\" rel=\"noopener\">Sprout Social<\/a>, Gong, and Insurity.<\/p>\n\n<p class=\"wp-block-paragraph\">You can read LastPass\u2019s <strong>June 2026<\/strong> notice on LastPass\u2019s official site.<\/p>","protected":false},"excerpt":{"rendered":"<p>LastPass said in a June 2026 notice that it was affected by a security breach tied to Klue. According to the company, the incident exposed OAuth tokens, gave attackers access to LastPass data stored in Salesforce, and may also have exposed customer contact records and support data. LastPass also says password vaults and master passwords &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/lastpass-confirms-2026-customer-data-breach-klue-hack-exposed-salesforce-data\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;LastPass confirms 2026 customer data breach: Klue hack exposed Salesforce data&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9325,"featured_media":370854,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-370855","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9325"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=370855"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370855\/revisions"}],"predecessor-version":[{"id":370856,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/370855\/revisions\/370856"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/370854"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=370855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=370855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=370855"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=370855"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=370855"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=370855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}