Hackers stole OAuth tokens from Klue, a third-party platform, to access LastPass customer data in its Salesforce environment. LastPass products, services, and customer vaults were not affected. Exposed data may be used in phishing attacks. The Icarus extortion group claimed responsibility.
Tap to vote and see what everyone thinks.
Summary by ByteBrief
Klue OAuth breach expands as Icarus group claims attack