LastPass alerts users to data theft following Klue partner breach
The breach at market research firm Klue, attributed to the extortion group Icarus, has compromised names, contact details, and sales data for several technology companies, including LastPass.

Password manager LastPass has notified customers that their personal information and customer support case records were stolen during a cyberattack on its technology partner, Klue. The incident marks the second data breach to affect the company in recent years, though LastPass confirmed that its own infrastructure and encrypted password vaults remain secure and unaffected.
The breach occurred at Klue, a market research firm, rather than within LastPass’s direct systems. However, hackers exploited their access to Klue to obtain significant volumes of data regarding LastPass customers. In a blog post detailing the incident, LastPass stated that the stolen information included names, phone numbers, email addresses, physical addresses, customer support case data, and sales-related data.
The cyberattack on Klue was identified on June 12, according to Klue CEO Jason Smith. The hacking and extortion group Icarus has taken credit for the incident and has publicly threatened to release the stolen data if a ransom is not paid. Smith has not yet responded to requests for comment regarding the number of affected customers or whether Klue has been in contact with the hackers.
LastPass is among a growing list of cybersecurity companies affected by the Klue breach, which was disclosed last week. Other impacted firms include HackerOne, Recorded Future, and Tanium. While the exact contents of the stolen customer support tickets remain unknown, they are likely to contain fragments of potentially private or sensitive information, as past support interactions have included credentials and government-issued identity documents.
This event follows a significant breach in 2022 where LastPass’s own systems were compromised. During that incident, hackers stole the company’s entire store of customer password vaults. Although the vaults were encrypted with master passwords known only to the customers, the attackers were able to brute-force and crack the vaults offline using the weakest passwords. Several crypto thefts were later linked to that breach, with hackers suspected of stealing wallet keys by cracking the password vaults.
As of 2024, LastPass serves more than 33 million users, including approximately 1.6 million paying customers. Spokespeople for LastPass did not immediately respond to requests for comment regarding the current incident or the specific number of customers affected by the Klue breach.
