Password manager maker LastPass has notified customers that a recent hack at one of its technology partners resulted in the theft of personal information and customer support case records. This marks the company's latest data breach in recent years.
In an email shared with TechCrunch by an affected customer, LastPass said the breach occurred at its market research company Klue, not its own systems. However, hackers exploited their access to obtain large amounts of data about LastPass customers.
LastPass is the latest in a growing list of cybersecurity companies to report data theft as a result of the Klue breach it disclosed last week. Other companies affected include HackerOne, Recorded Future, and Tanium.
LastPass said in a blog post sharing information about the incident that the hackers stole customer names, phone numbers, email addresses, and addresses, as well as customer support case data and sales-related data.
LastPass said its own infrastructure, including customers' password vaults, was not affected.
The content of the customer support ticket is not yet known, but it likely contains pieces of personal or confidential information. Customers typically contact customer service when they have billing issues or need assistance accessing their account. Past incidents involving customer support tickets have involved credentials and government-issued identification.
A LastPass spokesperson did not immediately respond to TechCrunch's request for comment or questions about the incident, including the number of customers affected.
LastPass has more than 33 million users and approximately 1.6 million paying customers as of 2024, according to its website.
LastPass previously experienced a data breach in 2022. In that case, hackers stole the company's entire customer password vault. The vault was used to store passwords, tokens, and other sensitive credentials such as personal and credit card numbers.
Although the vault was encrypted with a master password known only to the customer, the breach allowed hackers to brute force and crack the vault offline using the weakest master password, and then gain access to the secrets inside. Several cryptocurrency thefts were later linked to the LastPass breach after hackers were suspected of cracking password vaults and stealing victims' wallet keys.
Klue CEO Jason Smith said in a blog post that the company identified the hacker within its systems on June 12. A hacking and extortion group called Icarus took credit for the breach and publicly threatened to release the stolen data unless a ransom was paid.
Smith did not respond to TechCrunch's email regarding the incident, including how many customers were affected and whether the company had contact with the hackers.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

