Apps & Consumer
LastPass customer data stolen in breach at partner firm Klue
LastPass is notifying customers that hackers stole personal information and support case records during a security breach at its technology partner, Klue.
LastPass is notifying customers that their personal information and customer support case data—which refers to records of interactions between customers and support teams—were stolen during a recent hack at one of its technology partners. The password manager company confirmed that the security breach occurred at market research firm Klue, and not on its own systems. However, during the incident, hackers abused their access to obtain reams of data about LastPass customers. The stolen files include customer names, phone numbers, email addresses, physical addresses, sales-related data, and customer support case records.
LastPass stated that the company’s own infrastructure was unaffected by the incident, meaning that customers’ password vaults—the encrypted storage for user credentials—remain secure. The company is not the only firm impacted by the security failure at its partner. LastPass is the latest in a growing list of cybersecurity companies that have reported data thefts as a result of the breach at Klue, which was disclosed last week. Other affected technology and security firms include HackerOne, Recorded Future, and Tanium.
It is not yet known what was in the contents of the stolen customer support tickets, although they likely contain fragments of potentially private or sensitive information. Customers typically contact support teams when they are experiencing billing issues or require assistance to gain access to their accounts. The exposure of this support data affects a platform that, according to its website, has more than 33 million users and around 1.6 million paying customers.
The timeline of the breach traces back to earlier in the month. Klue CEO Jason Smith stated in a blog post that the market research firm identified hackers in its systems on June 12. A hacking and extortion group called Icarus has since taken credit for the breach. The group has publicly threatened to release the stolen data if a ransom is not paid.
Why it matters
LastPass is the latest in a growing list of cybersecurity companies reporting data thefts stemming from the Klue breach, highlighting the risks of third-party vendor vulnerabilities.