LastPass says hackers accessed customer information through a supply chain incident involving Klue, a market intelligence platform used by LastPass’s go-to-market teams. LastPass reports that it learned of the incident on June 12, after attackers compromised Klue and stole OAuth tokens. Those tokens provided unauthorized access to LastPass’s Salesforce environment. Multiple outlets report that the affected data includes customer contact details such as names, phone numbers, and email addresses, as well as customer support case records.

LastPass also states that its own infrastructure was not compromised, and that its customers’ encrypted password vaults and stored credentials were not affected. The outlets describe the incident as limited to systems integrated with Klue and the Salesforce setup that those integrations used.

Klue disclosed that the intrusion stemmed from access obtained through a compromised legacy credential tied to an integration service, which then led to theft of the OAuth tokens used for connections to third-party platforms such as Salesforce. LastPass is notifying customers and addressing the issue based on the information shared in its disclosure.