Observed Signal · Jun 24, 2026 · Security Incident / Data Breach · Source: t3n · Impact: 4/5 · Sentiment: Negative

LastPass Customer Data Stolen via Klue Breach

Executive Signal Summary

Password manager LastPass is handling a data breach after attackers accessed customer information by compromising a third‑party market intelligence platform, Klue. Klue detected unauthorized activity on 2026-06-12 and says attackers likely used old, compromised credentials for an integration service. Through that access, attackers viewed LastPass support tickets containing customer names, phone numbers, email addresses, home addresses, support-case details and sales-relevant information; payment data included in support tickets may also have been exposed. LastPass says its internal systems and user vaults were not compromised, and it is notifying affected users by email. Actions taken include suspending Klue employees’ access to LastPass data, rotating API access tokens, and planning additional protections. Users are advised to monitor payment activity and consider changing associated email addresses to reduce phishing risk.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A major consumer password manager had customer data exposed via a third‑party vendor breach; this raises significant supply‑chain security and trust concerns for many businesses and consumers that rely on LastPass.

SIGNAL RADAR

Track Klue Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • LastPass reports that attackers accessed customer data by exploiting a breach at third‑party platform Klue.
  • Klue detected unauthorized activity on 2026-06-12 and attributes access to old, compromised credentials for an integration service.
  • Compromised data includes customer names, phone numbers, email addresses, home addresses, support‑case data and sales‑relevant information; payment details submitted in support tickets may also be affected.
  • LastPass states its internal systems and password vaults were not compromised and has suspended Klue access and rotated API access tokens.
  • LastPass has over 33 million registered users, including about 1.6 million paying customers; affected users are being informed by email.

Connected Companies & Entities

2 Entities mapped

“The attackers targeted the market intelligence/platform Klue; Klue's CEO Jason Smith said unauthorized activity was detected on 2026-06-12 a...”

“TechCrunch reported that LastPass is currently informing users by email about the incident....”

Ontology Mapping & Concepts

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Jun 24, 2026
Original Coverage Title: “Passwortmanager Lastpass: Hacker erbeuten Kundendaten – was Nutzer jetzt wissen müssen”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Market Research & Consumer PanelJun 23, 2026

Klue: 2022 Credential Used in Customer Data Breaches

Market research firm Klue confirmed that a credential issued in 2022 for a limited pilot was used by hackers in June 2026 to steal data from multiple corporate customers, including LastPass and several cybersecurity companies. Klue detected the intrusion on June 12, 2026, and disclosed the incident on June 23, 2026. Attackers leveraged access to Klue’s systems — which store OAuth tokens used to access customer data in other clouds and databases — to download data and extort impacted companies. Klue says the credential was originally provided to a third party for a pilot in 2022 but has not explained why it wasn’t revoked or what type of credential it was. A group calling itself Icarus claimed responsibility and threatened to publish the stolen data. Klue says it is conducting a comprehensive review of credential management, vendor access controls, monitoring and deployment security.

Read assessment
Data BreachJun 25, 2026

Klue Hack: Stolen Customer Data Being Deleted, New Threats

Market research provider Klue confirmed a June 12, 2026 breach in which attackers stole customer data and authentication keys. Klue says it is communicating with the threat actor known as “Icarus,” which told the company it is taking steps to delete stolen customer data and that the Icarus site is down. Klue also warned customers that a second, unnamed gang is attempting to extort Klue’s customers directly after claiming to obtain samples of data from Icarus; that group published a list and demanded ransom, claiming 195 affected customers. Klue reported attackers used a 2022 third-party credential (from a limited pilot) to access systems and exfiltrate OAuth tokens that allowed login to customer clouds and databases.

Read assessment
Market Research & Consumer Panel (data breach at market intelligence provider)Jun 22, 2026

Klue hack exposes customer data across cybersecurity firms

Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.