LastPass confirmed on June 23 that hackers accessed customer-support and CRM records inside its Salesforce environment after OAuth tokens were stolen in the Klue supply-chain attack, while its password vaults remained untouched. BleepingComputer's reporting traced the full access path. [1]
The sequence is worth stating plainly because each hop matters. Klue, a market-intelligence platform used by LastPass's go-to-market teams, integrates with Salesforce. Attackers — later identified as the Icarus extortion crew, which launched in April — reached Klue's backend using a dormant but still-active credential created for a prototype integration, then pushed a malicious code update that harvested the OAuth tokens Klue held for its customers' Salesforce instances. Those tokens were then used to query connected CRMs directly. LastPass learned of its exposure on June 12. [1][2]
The comforting part is also the trap. "Customer vaults remained secure" is true and will headline every summary. It is not the same as nothing happened. What left the building includes customer names, phone numbers, email addresses, physical addresses, support-case content, and sales data — exactly the raw material a phishing operation needs to impersonate a vendor convincingly. LastPass itself warned customers to distrust messages from look-alike sender domains and to remember that no legitimate agent will ever ask for a master password. [1]
MSM and the security trade can frame this precisely: tokens, endpoints, telemetry. X will hear one word — LastPass — and relitigate the vault breaches of years past, concluding that password managers failed again. They did not fail here; they were not the target. The paper's divergence claim is about surface area. The vault was never the surface. The integration was.
ReliaQuest's telemetry, cited by BleepingComputer, shows what that means operationally: attackers ran automated Python scripts against Salesforce's REST API for nearly twenty-four hours, first mapping objects slowly through reconnaissance queries, then exfiltrating hard — nearly a thousand queries in fifteen minutes in one environment, a six-hour pull in another. Salesforce responded by disabling the Klue Battlecards connection platform-wide. Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, and Huntress were among the organizations swept into the same campaign, each notified with extortion emails signed by an alias called "mr bean." [2]
Modern business risk increasingly lives between products rather than inside them. Klue, Salesforce, Gong, and LastPass are separate nouns on an org chart; to an attacker holding valid tokens they are one continuous path. Defenses calibrated against passwords and malware miss this class entirely because every step of it looks authorized. The credentials were real. The scripts merely read what the tokens could read.
The receipts to watch from here are procedural and checkable. Token rotation: LastPass says it rotated exposed API and OAuth credentials and cut employee access to Klue. Notification: affected customers need timely, specific disclosure, not boilerplate. Replication: whether more SaaS vendors connected to Klue disclose similar exposure, and whether Salesforce permanently re-certifies marketplace integrations that hold standing API grants. Each is public or eventually will be.
A breach that misses the crown jewels can still map the kingdom. Support tickets know which customers are large, who signs contracts, and who answers the phone. That is not vault theft. It is reconnaissance sold back to criminals — and it should reset how companies price every third-party integration they approve.