LastPass confirmed that the Klue supply chain attack exposed customer data held within its Salesforce environment after threat actors obtained OAuth tokens from the market intelligence platform. The Icarus extortion group compromised Klue's infrastructure using legacy credentials for an integration service, gaining access to OAuth tokens that connected multiple vendors' CRM systems. LastPass's core products and customer vaults remained unaffected, but the breach exposed customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data stored in Salesforce. The company has disabled Klue access, rotated exposed tokens, and warned users to disregard communications from spoofed domains. This incident underscores a critical vulnerability in the CX technology stack: the assumption that third-party integrations inherit the same security posture as the primary vendor.
For CX teams, the implications are twofold. First, this breach demonstrates that your customer data exposure extends far beyond your primary platform—Salesforce, Zendesk, or Freshdesk instances are only as secure as the weakest integration connected to them. Support teams should immediately audit which third-party tools have OAuth access to their CRM environments and what data those integrations can reach. Second, the targeting of go-to-market teams suggests attackers are deliberately hunting for customer intelligence data to fuel phishing and social engineering campaigns. Given that CX professionals routinely handle sensitive customer contact information and support case histories, teams should expect heightened targeting and should implement stricter verification protocols for any outbound communications claiming to be from vendors or support channels. The question for larger organisations is whether your current vendor risk management programme actually maps OAuth token permissions across your entire integration ecosystem, or whether you're relying on vendors to self-report breaches after the fact.
The broader pattern here—Klue OAuth breach victim list grows as Icarus hackers claim attack—reveals that supply chain attacks targeting CRM integrations are now a systematic threat vector rather than isolated incidents. CX leaders should treat OAuth token rotation and integration audits as operational security requirements equivalent to password management, not as optional hardening measures. The fact that Gong data was not accessed despite Klue's integration suggests that some platforms may have implemented stricter token scoping, which raises the question: are your integrations requesting overly broad permissions, and do you know which vendors have actually implemented least-privilege access controls?
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month. [...]