
LastPass, the well-known password management service, has informed its users about a security breach that compromised their personal information and customer support records. This incident occurred at Klue, a market research firm linked to LastPass, rather than within LastPass's own systems. According to an email from an affected customer shared with TechCrunch, hackers exploited their access to Klue’s database, resulting in the theft of sensitive data including customer names, phone numbers, email addresses, physical addresses, as well as details related to customer support cases. This breach highlights a troubling trend among cybersecurity firms, as several others, including HackerOne, Recorded Future, and Tanium, have also reported data thefts stemming from the Klue incident. In a blog post detailing the breach, LastPass reassured users that their own infrastructure, specifically the password vaults containing sensitive credentials, remains secure. However, the contents of customer support tickets—which may include sensitive information—are still under scrutiny. Typically, users reach out to customer service for billing issues or account access assistance, and past breaches have shown that such tickets can sometimes reveal critical information including passwords and government-issued identification. As of 2024, LastPass boasts over 33 million users, with approximately 1.6 million of them being paying customers. The company faced a significant data breach in 2022, where hackers compromised the entire store of customer password vaults, leading to concerns about the security of user credentials. The breach allowed for offline brute-force attacks on vaults with weaker master passwords, raising alarms about the potential for crypto theft linked to the stolen wallet keys. Klue’s CEO, Jason Smith, announced in a blog post that the intrusion was detected on June 12. The hacking group Icarus has claimed responsibility for the attack and has issued threats to release the stolen data unless a ransom is paid. As of now, there has been no response from Smith regarding the scale of the affected customer base or any communication with the hackers.
Warner Bros. Discovery has initiated legal proceedings against Amazon, accusing the tech giant of unlawful interference ...
TechCrunch | Jul 25, 2026, 21:25
Kalshi, the prediction market platform, has taken significant legal steps against Netflix, sending a cease-and-desist le...
TechCrunch | Jul 25, 2026, 17:10
Have you noticed an unusual trend where people are wrapping their wallets in aluminum foil? This peculiar practice has e...
Business Today | Jul 25, 2026, 02:45
In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...
TechCrunch | Jul 25, 2026, 21:00
As technology continues to evolve, a notable shift is occurring in the relationship between humans and artificial intell...
Business Insider | Jul 25, 2026, 09:50