LastPass notifies users of yet another data breach

Hacker News Top News

Summary

LastPass is notifying users of a data breach caused by a compromise at its third-party vendor Klue, exposing customer names, email addresses, and support case data, but not password vaults.

No content available
Original Article
View Cached Full Text

Cached at: 06/25/26, 02:11 PM

# LastPass notifies users of yet another data breach - 9to5Mac Source: [https://9to5mac.com/2026/06/23/lastpass-notifies-users-of-yet-another-data-breach/](https://9to5mac.com/2026/06/23/lastpass-notifies-users-of-yet-another-data-breach/) ![LastPass system outage - down for users](https://9to5mac.com/wp-content/uploads/sites/6/2024/03/lastpass-outage.jpg?quality=82&strip=all&w=1600)LastPass users are once again being warned about stolen personal data, though this time the breach happened through one of the company’s outside partners\. Here are the details\. ## LastPass says password vaults not affected As reported by[*TechCrunch*](https://techcrunch.com/2026/06/23/password-manager-maker-lastpass-says-hackers-stole-customer-support-case-data-during-klue-breach/), LastPass is emailing users affected by a[breach at market research firm Klue](https://klue.com/blog/an-update-on-recent-klue-security-incident), which allowed hackers to access customer information and support case data\. The news came as LastPass shared more information on a[blog post](https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response), where it explained: > The information accessed was limited to standard business contact information and related customer relationship management \(CRM\) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales\-related data\. LastPass said that upon learning about the incident, the company revoked employee access to Klue, rotated the exposed API tokens, notified law enforcement, and launched “a detailed investigation into the scope of the event, working with our contacts at both Klue and Salesforce\.” The company explains that Klue’s platform integrates with Salesforce and Gong systems\. As a result, LastPass is recommending that customers “remain vigilant of potential phishing attacks or social engineering attempts” leveraging the compromised information\. LastPass also shared the following IP addresses and email sender domains associated with the attackers, which companies can use to search for related activity in their systems: > IP Addresses: - 138\.226\.246\[\.\]94 - 94\.154\.32\[\.\]160 - 159\.183\.215\[\.\]61 - 159\.183\.181\[\.\]239 Email Sender Domains: - baccarat\.com\[\.\]au - robinskitchen\.com\[\.\]au - house\.com\[\.\]au This is the latest in a series of security incidents affecting LastPass\. In[2015](https://blog.lastpass.com/posts/lastpass-security-notice?utm_source=chatgpt.com), hackers obtained account email addresses, password reminders, authentication hashes, and cryptographic salts, although LastPass said encrypted vault data was not accessed\. In[2022](https://blog.lastpass.com/posts/notice-of-recent-security-incident?utm_source=chatgpt.com), an attacker compromised a developer account and stole source code and technical information\. The attacker later used that information to access cloud backups containing customer records and encrypted password vaults, along with unencrypted details such as names, billing addresses, email addresses, and phone numbers⁠\. To learn more about the Klue breach and LastPass’s response,[follow this link](https://blog.lastpass.com/posts/klue-supply-chain-incident-and-lastpass-response)\. #### Worth checking out on Amazon - [Geoffrey Cain – ‘Steve Jobs in Exile’](https://amzn.to/4v3CS5Q) - [David Pogue – ’Apple: The First 50 Years’](https://amzn.to/46Y3nQj) - [MacBook Neo](https://amzn.to/47vJmkn) - [Logitech MX Master 4](https://amzn.to/3KmIQN7) - **[AirPods Pro 3](https://www.amazon.com/Apple-Cancellation-Translation-Headphones-High-Fidelity/dp/B0FQFB8FMG?tag=marcmendes-20)** - [AirTag \(2nd Generation\) – 4 Pack](https://amzn.to/4sewc3a) - [Apple Watch Series 11](https://amzn.to/46VomDB) - [Wireless CarPlay adapter](https://www.amazon.com/gp/product/B0F6T6N2B1?tag=marcmendes-20) [![Add 9to5Mac as a preferred source on Google](https://9to5mac.com/wp-content/themes/ninetofive/dist/images/google-preferred-source-badge-dark.png)![Add 9to5Mac as a preferred source on Google](https://9to5mac.com/wp-content/themes/ninetofive/dist/images/google-preferred-source-badge-light.png)](https://google.com/preferences/source?q=https://9to5mac.com) *FTC: We use income earning auto affiliate links\.*[More\.](https://9to5mac.com/about/#affiliate) [![](https://9to5mac.com/wp-content/uploads/sites/6/2026/06/750-x-150-all-deals-1.png)](https://amzn.to/3QOoNKR)

Similar Articles

Security News This Week: LastPass Users Had Their Data Stolen—Again

Wired

This security news roundup covers the latest LastPass data breach via a partner, predictive policing in Bristol, Dialog group data exposure, Anthropic's AI model negotiations with the White House, OpenAI's new GPT-5.5-Cyber and open-source patching initiative, and other security stories.

One million passports leaked online

Hacker News Top

Nearly a million passports and photo IDs from multiple European countries were exposed on public URLs with no authentication, accessible to anyone for months. The breach, discovered by security researcher Sammy Azdoufal, occurred due to poor security practices by companies managing age verification for cannabis clubs.

New Pass-ta-key attack reveals all the things we didn't know about passkeys

Ars Technica

A new attack called Pass-ta-key shows that passkeys stored in Google Password Manager on Windows can be extracted by malware, revealing that passkeys are generally stored locally rather than in TPM hardware. The article clarifies that this is not a novel attack and that the Windows platform is the main exception.