Password manager maker LastPass says hackers stole customer support case data during Klue breach

LastPass has notified customers that personal information and support case data were stolen during a breach at third-party vendor Klue, affecting millions of users across the password manager's customer base; this incident highlights the critical supply chain security risks that persist even when an organization's own infrastructure remains secure. The breach follows LastPass's 2022 major data loss and represents an ongoing pattern of exposure for the company, underscoring the need for IT leaders to reassess their third-party vendor risk management and data classification practices. This incident demonstrates that even security-focused companies remain vulnerable to downstream compromises, and organizations must implement stricter vendor access controls and data minimization strategies.

Zack WhittakerTechCrunch2 min read
Read full article
Password manager maker LastPass says hackers stole customer support case data during Klue breach
This is the second data breach to affect LastPass customers in recent years, after one of the password manager's tech partners was recently breached.