# LastPass data breach exposes customer contact info, no passwords

**Published:** 2026-06-24T14:31:29.973Z  
**Topic:** Google  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/e276a5be-b1b6-45f6-bf26-26222ab2bd7d

LastPass breach via third‑party Klue leaked names, emails and phone numbers but not master passwords. Learn what was exposed and the next steps for users.

LastPass disclosed that a supply‑chain attack on its third‑party market‑research vendor Klue resulted in the theft of customer names, phone numbers, email and postal addresses, while master passwords and vault contents remained intact [3]. The breach raises immediate phishing risks for millions of users and forces the password‑manager to tighten its integrations.

| At a glance | |
|---|---|
| Company | LastPass |
| Breach source | Third‑party vendor Klue |
| Data exposed | Names, phone numbers, email & postal addresses, support case details |
| Passwords compromised | None (master passwords not exposed) |

## How the breach unfolded  
The incident began when attackers obtained OAuth tokens that Klue used to connect its platform to LastPass’s Salesforce and Gong systems. With those tokens, the threat actors accessed the Salesforce environment and exfiltrated the contact‑level CRM data listed above [3]. LastPass cut employee access to Klue, refreshed the compromised tokens, and launched a joint investigation with Klue, Salesforce and law‑enforcement [1]. The ransomware group Icarus claimed responsibility and warned of further data publication if a ransom was not paid [1].

## Impact on users and the market  
Although the breach did not expose any password vaults, the stolen personal details can be leveraged for targeted phishing or social‑engineering attacks, prompting LastPass to urge customers to stay vigilant for suspicious communications [1][3]. The episode adds to a series of security setbacks for the company, including 2022 incidents that compromised vault data and led to an $8.2 million settlement [2]. Competitors such as 1Password, NordPass and Bitwarden, which have not reported similar supply‑chain breaches, may benefit from heightened user concerns about LastPass’s security track record [1].

## What to watch
- **Klue remediation timeline** – monitoring when LastPass fully restores secure token handling and re‑enables the vendor.  
- **Legal and regulatory follow‑up** – any new class‑action filings or settlement updates stemming from the exposed contact data.  
- **Competitor response** – announcements from rival password managers highlighting their own supply‑chain security measures.

The breach underscores that even without direct access to password vaults, compromised ancillary data can erode trust in a core security product, leaving the market to watch how LastPass rebuilds its supply‑chain defenses and whether users migrate to alternatives.

## Sources
1. Zdnet — [LastPass hit by new data breach - 4 steps you should take now](https://www.zdnet.com/article/lastpass-new-data-breach-2026-steps-to-take-now/)
2. Lifehacker — [The LastPass Data Breach Settlement Could Net You a Big Payout](https://lifehacker.com/tech/the-lastpass-data-breach-settlement-payouts)
3. Techradar — [LastPass confirms data breach after hacker compromises supply ...](https://www.techradar.com/pro/security/lastpass-confirms-data-breach-after-hacker-compromises-supply-chain-heres-what-we-know)

---
Cite as: TrendWatcher, "LastPass data breach exposes customer contact info, no passwords", https://www.trendwatcher.in/article/e276a5be-b1b6-45f6-bf26-26222ab2bd7d
