:

KLUE BREACH EXPOSES DATA AT LASTPASS, JAMF, HACKERONE

SECURITY DESK2 MIN READ
TUE, JUN 23, 2026

■ AI-SUMMARIZED FROM 5 SOURCES ▸ TIMELINE

Canadian market intelligence firm Klue confirmed a data breach claimed by cybercrime group Icarus, compromising customer information at multiple downstream companies including password manager LastPass.

Klue, a market research platform, fell victim to a supply chain attack that gave hackers access to sensitive data across several high-profile clients. The Icarus cybercrime group claimed responsibility for the breach. LastPass disclosed that attackers stole personal information and customer support case records from its Salesforce environment during the Klue incident. The password manager said hackers obtained OAuth tokens from Klue's systems, enabling unauthorized access to customer data stored in LastPass's CRM platform. Other affected companies include endpoint management firm Jamf and bug bounty platform HackerOne, both of which confirmed exposure during the same attack. This marks the second significant data breach to impact LastPass customers in recent years, following a previous incident involving a technology partner. The company has notified affected users and recommended security reviews. Supply chain attacks like the Klue breach highlight how hackers target service providers to access larger customer bases. By compromising a single vendor, attackers can gain entry to dozens of downstream organizations without directly targeting them. No information on the scope of exposed data or potential remediation measures has been detailed by all affected parties. Customers of impacted companies are advised to monitor accounts for suspicious activity and consider changing passwords stored in password managers as a precaution. The incident underscores ongoing security challenges in cloud-based services and third-party integrations, areas that have become increasingly targeted by sophisticated threat actors.

■ MORE FROM THE SECURITY DESK

A threat actor compromised BdThemes' infrastructure and modified a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack leveraged the company's premium web-design plugin distribution system.

5H AGOAI Desk

HackerOne, the bug bounty platform, has come under criticism following recent policy shifts and operational decisions that have impacted its security researcher community.

6H AGOSecurity Desk

Simply deleting files from old USB drives before disposal provides minimal data protection. Experts warn that deleted data can be recovered with basic tools, making proper wiping essential.

8H AGOIndustry Desk

CISA has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices, including a critical server-side request forgery flaw.

10H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.