LastPass says it is notifying customers after hackers obtained personal information and customer support case data through a supply chain incident involving third-party vendor Klue. According to LastPass, the attackers did not compromise LastPass’s own infrastructure or its customers’ encrypted password vaults and stored credentials.

The incident is tied to OAuth tokens that grant access to LastPass’s Salesforce environment. Multiple outlets report that the tokens were stolen when hackers breached Klue, and that the access was made possible through Klue’s compromised credentials connected to an integration service. Klue reportedly disclosed the intrusion on June 22, after which LastPass investigated and determined that data stored in systems integrated with Klue and associated with Salesforce was accessed.

Reportedly affected information includes customer contact details such as names, phone numbers, and email addresses, as well as customer support case data. The overall impact is described as limited to specific systems used for Salesforce-related functions, with no indication of access to password vault contents.