Affected Systems

LastPass customers. Attack vector: compromised Klue third-party service leading to OAuth token theft and unauthorized access to LastPass Salesforce environment containing customer data.

Exploitation Status

Active exploitation confirmed. Attackers successfully stole OAuth tokens via compromised Klue supply chain and accessed LastPass Salesforce customer data. This is a confirmed breach, not theoretical.

Business Impact

Customer data exposure at LastPass via third-party compromise. Organizations using LastPass should assume potential exposure of data stored in LastPass Salesforce CRM (likely support tickets, account details, contact information). Supply chain risk demonstrates OAuth token theft as viable attack path. LastPass users face potential targeted phishing or credential stuffing based on leaked data. No CVE assigned as this is supply chain compromise, not software vulnerability.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Audit all third-party integrations with OAuth access to critical systems (Salesforce, CRM, support platforms) and revoke unnecessary tokens immediately
  • If using LastPass: monitor for phishing attempts targeting your organization; review LastPass account activity logs for anomalies; consider password rotation for sensitive accounts
  • Review Salesforce OAuth token grants and implement token expiration policies; enable Salesforce Event Monitoring to detect abnormal API access patterns
  • Assess vendor risk for all SaaS tools with access to customer data; prioritize vendors with broad OAuth scopes or CRM integration
  • Implement conditional access policies and IP allowlisting for Salesforce and other critical SaaS platforms to limit lateral movement from compromised tokens