Skip to main content
  1. Home
  2. Computing
  3. News

LastPass suffers another data breach, but this time your password vault is safe

The company says hackers accessed customer names, contact details, and support records through a third-party vendor, not LastPass' own systems.

Add as a preferred source on Google
LastPass website on a laptop.
Digital Trends

If you’ve ever submitted a support ticket to LastPass, that exchange may now be in the hands of hackers. According to TechCrunch, the password manager has confirmed that customer names, contact details, and support case records were exposed in a recent breach at one of its third-party vendors.

What the hackers got, and what they didn’t

LastPass said its own systems were not compromised and that users’ password vaults remain secure. The exposed data was instead accessed through Klue, a market research company LastPass works with.

While no passwords were stolen, the hackers used their access to Klue’s network to pull customer records, including phone numbers, email addresses, physical addresses, and contents of support tickets.

Recommended Videos

In a blog post about the incident, the company stressed that the breach did not affect encrypted password vaults, master passwords, or any credentials stored within LastPass itself. Even so, the exposed information could still prove useful to attackers, who could leverage it for phishing or social engineering campaigns.

A years-old credential opened the door

The LastPass exposure stems from a wider security breach at Klue, which revealed that attackers gained access using a credential linked to a pilot project dating back to 2022. TechCrunch reports that the credential remained active and provided a way into the company’s systems.

Klue said the attackers were able to access customer data connected to its services, affecting multiple organizations that relied on the platform. Along with LastPass, Gong, Jamf, HackerOne, Insurity, OneTrust, Recorded Future, Snyk, Huntress, Sprout Social, and Tanium were affected.

For LastPass, this marks the second time its users have had data caught up in a breach. A 2022 breach exposed encrypted password vaults that were later linked to cryptocurrency theft. This latest exposure did not involve vault data or passwords, but it highlights how a security lapse at a third-party vendor can still affect customers who never interacted with the vendor directly.

Pranob Mehrotra
Pranob is a seasoned tech journalist with over eight years of experience covering consumer technology. His work has been…
What makes a laptop effective for remote work?
Dell 14 Plus

This post is brought to you in paid partnership with Dell

Remote and hybrid work have changed what people expect from a laptop. Most professionals are no longer working from a single desk all day. A typical workflow now involves morning Zoom or Microsoft Teams calls, browser tabs running alongside Slack and email, and moving between home, the office, cafés, and even airports without disrupting productivity.

Read more
Deepfake scams are getting uglier, and Bitdefender now has an app for the panic
RealCheck gives Android and iOS users a paid way to test suspicious videos before money or personal data is at risk.
how-to-remove-nudes-deepfake-non-consensual-images

Bitdefender has launched RealCheck, a deepfake detector built for the moment when fake video scams show up as ordinary clips. The standalone app is available now for Android and iOS, and it can analyze uploaded files or links from digital platforms.

RealCheck checks a video’s authenticity and screens for scam intent in the same report. That includes signals tied to financial fraud, credential theft, impersonation, and reputational attacks.

Read more
I’d grab this 8BitDo Prime Day keyboard deal before buying another boring gaming keyboard
8BitDo’s Xbox-inspired mechanical keyboard gets a Prime Day price that makes the nostalgia easier to justify.
Computer, Computer Hardware, Computer Keyboard

Prime Day is packed with gaming keyboards that blur together under the same rainbow lighting. The 8BitDo Retro 87-Key Wireless RGB Mechanical Gaming Keyboard has a cleaner hook: original Xbox-style nostalgia, modern wireless options, and a sale price that makes the whole retro bit easier to defend.

8BitDo Retro 87-Key Wireless RGB Mechanical Gaming Keyboard: Xbox nostalgia without collector pricing

Read more