LastPass confirms data breach in Klue supply chain attack
LastPass confirmed a data breach after a supply chain attack targeting its workforce management tool, Klue, exposed customer metadata including usernames and billing addresses. The breach occurred through a compromised third-party vendor, with no evidence of encrypted vault data being accessed. LastPass has since rotated credentials and enhanced security measures.
Background
- LastPass is a popular password manager that stores encrypted passwords in the cloud, used by millions of individuals and businesses.
- Klue is a competitive intelligence platform that apparently had a supply chain attack — meaning attackers compromised a vendor or partner that Klue used, not Klue itself.
- A supply chain attack happens when hackers infiltrate a less-secure third party (e.g., a vendor, contractor, or software library) to gain access to the primary target's systems or data.
- This incident means LastPass's data was exposed because of a breach at Klue (a company LastPass worked with or acquired), not through a direct attack on LastPass's own infrastructure.
- LastPass has suffered multiple high-profile breaches in recent years (notably 2022), eroding user trust in its security despite its core promise of keeping passwords safe.