LastPass recently confirmed that customer data was exposed as part of the growing Klue supply chain attack. Attackers compromised OAuth tokens maintained by a third-party platform and used them to gain unauthorized access to customer data stored in Salesforce environments. While LastPass reports that password vaults, products and infrastructure were not affected, customer contact information, support cases and CRM-related data may have been exposed.

This incident highlights a growing cybersecurity reality:

  • Your vendors are now part of your attack surface
  • SaaS integrations can create hidden pathways into critical business systems
  • OAuth tokens and API connections often receive less scrutiny than traditional credentials
  • A security program that focuses only on your internal environment is no longer enough

How can organizations protect themselves?

  • Inventory all third-party SaaS integrations and understand what data they can access
  • Regularly review and remove unused OAth tokens, API keys and Application Permissions
  • Implement least-privilege access for integration and service accounts
  • Continuously monitor Salesforce, Microsoft 365, Google Workspace, and other SaaS platforms for unusual activity
  • Conduct vendor risk assessments that evaluate not only the vendor’s controls, but also the integrations they maintain
  • Develop an incident response plan that specifically addresses third-party and supply chain compromises

The most concerning aspect of this breach isn’t that LastPass was targeted. It’s that attackers never needed to compromise LastPass directly. They compromised a trusted vendor and leveraged that trust to access customer environments.

Supply chain attacks continue to prove that cybersecurity is no longer just about protecting your network-it’s about managing trust across your entire digital ecosystem.