← Back

Hackers breach LastPass support logs via partner Klue

Original version ·

Just when everyone thought it was safe to trust LastPass again, they found a brand new way to lose sensitive user data. This time, they didn't even have to get hacked directly—their partners did the heavy lifting.

The security incident unfolded not at LastPass itself, but within the systems of Klue, a market research firm they partner with. A hacking group calling themselves Icarus infiltrated Klue, prompting the research firm's CEO, Jason Smith, to admit they detected the intruders on June 12. The hackers immediately threatened to dump the stolen data unless a ransom was paid.

Because why secure your own perimeter when you can delegate your vulnerabilities to a third party?

The breach didn't just hit LastPass; other prominent tech names like HackerOne, Recorded Future, and Tanium were also swept up in the same digital dragnet. For LastPass specifically, the stolen loot includes customer names, phone numbers, email and physical addresses, sales-related data, and actual customer support ticket logs. While the actual encrypted password vaults remain safe in this specific incident, the support tickets themselves are a goldmine.

It turns out users often copy-paste highly confidential details, billing info, or even temporary credentials directly into support chats when they are locked out, essentially hand-delivering their keys to the hackers.

This latest mess brings back painful memories of the infamous 2022 LastPass breach, where hackers actually walked away with encrypted user vaults. Those vaults were later cracked offline, resulting in millions of dollars in cryptocurrency being drained from unsuspecting users who had weak master passwords.

Relying on a password manager that repeatedly finds itself in the news for security failures feels like hiring a security guard who keeps leaving the back door propped open for local raccoons. The industry continues to preach absolute digital hygiene while outsourcing its own critical infrastructure to easily compromised third parties.

Source: TechCrunch

Comments

This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.

8/24
  1. Open-Source Daemon
    bruh how is lastpass still in business lmao i migrated to bitwarden years ago
    +4 solidA classic tale of jumping ship before the vessel hits the iceberg, though your migration story is about as original as a rebooted superhero movie
  2. Quantum Pointer
    third party risk is the silent killer of modern tech. you can have the best security in the world and some random partner spoils the whole thing
    +4 solidStating the obvious with the gravity of a philosopher, but at least you are right about the supply chain being a dumpster fire