← Retour au blog
tech 25 June 2026

LastPass: Yet Another Data Breach

LastPass has notified its users of a new data breach involving an external partner. Although password vaults remain unaffected, personal information has been compromised.

Article inspired by the original source
LastPass notifies users of yet another data breach ↗ 9to5mac.com

# LastPass: Yet Another Data Breach

LastPass, the popular password manager, has once again faced a data breach. This time, the incident occurred through an external partner, the market research firm Klue. This news comes after several security incidents that have already shaken user trust.

Details of the Breach

According to a report by TechCrunch, LastPass has emailed users affected by this breach, which allowed hackers to access customer information and support case data. The compromised information includes customer names, phone numbers, email addresses, physical addresses, as well as sales and support data. Fortunately, the password vaults, which are the core of LastPass's offering, have not been affected.

Measures Taken by LastPass

Following the incident, LastPass revoked employee access to Klue, rotated the exposed API tokens, and notified law enforcement. A detailed investigation was launched to fully understand the scope of the event. LastPass is working closely with Klue and Salesforce, as Klue's platform integrates with Salesforce and Gong systems.

Impact on Users

LastPass users are encouraged to remain vigilant against potential phishing attacks or social engineering attempts that could leverage the compromised information. The company also shared IP addresses and email sender domains associated with the attackers to help detect suspicious activity.

History of Security Incidents at LastPass

This latest breach is part of a series of security incidents affecting LastPass. In 2015, hackers obtained account email addresses, password reminders, authentication hashes, and cryptographic salts. In 2022, a developer account was compromised, allowing an attacker to steal source code and technical information, and later access cloud backups containing customer records.

Recommendations for Users

Although LastPass's password vaults have not been directly compromised, it is crucial for users to take steps to protect their accounts. This includes enabling two-factor authentication, regularly reviewing third-party app access, and being aware of phishing attempts.

Conclusion

This latest incident underscores the importance of choosing trustworthy partners and maintaining constant vigilance in data security. With the increase in technological integrations, companies must double down on efforts to secure their ecosystems.

Let's discuss your project in 15 minutes.

LastPass data breach security phishing cybersecurity
Deepthix newsletter · 100% AI · every Monday 8am

An AI agent reads tech for you.

Our AI agent scans ~200 sources per week and ships the best articles to your inbox Monday 8am. Free. One click to unsubscribe.

Visit the newsletter page →

Want to automate your operations?

Let's talk about your project in 15 minutes.

Book a call