Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

LastPass confirms data breach in Klue supply chain attack

LastPass confirmed a data breach after a supply chain attack targeting its workforce management tool, Klue, exposed customer metadata including usernames and billing addresses. The breach occurred through a compromised third-party vendor, with no evidence of encrypted vault data being accessed. LastPass has since rotated credentials and enhanced security measures.

Background

- LastPass is a popular password manager that stores encrypted passwords in the cloud, used by millions of individuals and businesses. - Klue is a competitive intelligence platform that apparently had a supply chain attack — meaning attackers compromised a vendor or partner that Klue used, not Klue itself. - A supply chain attack happens when hackers infiltrate a less-secure third party (e.g., a vendor, contractor, or software library) to gain access to the primary target's systems or data. - This incident means LastPass's data was exposed because of a breach at Klue (a company LastPass worked with or acquired), not through a direct attack on LastPass's own infrastructure. - LastPass has suffered multiple high-profile breaches in recent years (notably 2022), eroding user trust in its security despite its core promise of keeping passwords safe.