Security · 6h ago
LastPass Breach Exposes Customer Support Data via Stolen OAuth Tokens
Attackers used stolen Klue OAuth tokens to access LastPass's Salesforce environment, exposing customer contact and support data. The breach did not compromise encrypted vaults or master passwords. LastPass confirmed the incident in a public statement.
Meridian48 take
This is another reminder that even if vaults remain secure, third-party integrations can create dangerous attack surfaces for password managers.
Read the full reporting
LastPass Confirms Vendor Breach Exposed Customer Contact, Support Data →
TechRepublic
lastpass-breachoauth-token-theft