LastPass Breached Through Third-Party Connection Klue

What Happened

LastPass customers' data stolen. CRM records, emails, phone numbers, authentication details, all walked out the door. LastPass's own security stayed clean. The breach happened at a vendor connected to their Salesforce.

How They Got In

Klue, a market intelligence platform, was compromised via a legacy credential from 2022. A credential nobody revoked. Nobody monitored. Nobody even remembered existed. Attackers used Klue's OAuth tokens to walk straight into LastPass.

No exploit. No brute force. Just a trusted connection doing what it was built to do.

The Pattern

48% of breaches now involve a third party. Klue wasn't a vendor LastPass was worried about. It was already connected. Already trusted. Already forgotten.

What FrontierZero Catches

Legacy credentials sitting dormant for years. OAuth tokens with permissions way beyond their original scope. Vendor accounts that haven't been reviewed since they were first provisioned.

Most companies have zero visibility into this. No baseline. No pattern monitoring. No way to detect when a dormant connection suddenly gets active.

The Gap

You approved Klue in 2022. You moved on. If that credential got compromised in June 2026, you'd never know until customers reported it.

What You Need

Real-time visibility into every external connection, approved and forgotten. Monitor behavior patterns. Catch when old credentials suddenly wake up. Revoke what's no longer needed.

Get your External Connections Report. See every vendor token, OAuth grant, and integration currently connected to your environment. Then you can actually manage them.