[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGZSLPM12hkEQqRyvS8XcqXW_oF_VtzAjxvmCTQlGBhg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"46b4299f-7199-4eae-af8b-b127e7df5786","third-party-oauth-token-theft-exposes-lastpass-customer-crm-data","7daa97cb-5ef7-42a1-8c60-bb9d95a35699","Third-Party OAuth Token Theft Exposes LastPass Customer CRM Data","The root cause of this breach was LastPass's inherited trust in a compromised third-party vendor, Klue, whose stolen OAuth tokens were leveraged to access LastPass's Salesforce CRM environment. This illustrates how supply chain vulnerabilities can bypass an organization's own security controls entirely — an attacker never needed to compromise LastPass directly. OAuth tokens, when stolen, act as silent keys that grant persistent access without triggering password-based alerts, making detection difficult without robust token monitoring. The incident underscores that third-party integrations must be treated as potential attack surfaces, not trusted extensions of internal systems. Even when core products (like password vaults) remain secure, exposure of CRM data can still damage customer trust and carry regulatory implications.","**Immediate actions:**\n- Audit and revoke all active third-party OAuth tokens, re-issuing only those verified as uncompromised.\n- Implement token anomaly detection in Salesforce and other CRM platforms to flag unusual access patterns originating from third-party integrations.\n- Notify affected customers promptly and assess whether exposed data triggers GDPR, CCPA, or other breach notification obligations.\n\n**Long-term improvements:**\n- Adopt a zero-trust model for all third-party integrations, enforcing least-privilege scopes on every OAuth token and API credential.\n- Establish a formal vendor risk management program that requires security attestations and continuous monitoring of third-party platforms before granting CRM or data access.\n- Segment CRM and customer data environments so that a single compromised integration cannot access the full dataset.\n\n**Detection measures:**\n- Deploy a CASB (Cloud Access Security Broker) solution to monitor and log all third-party access to SaaS platforms like Salesforce in real time.\n- Set automated alerts for OAuth token usage outside of expected hours, geolocations, or data volumes to enable rapid response to token theft.\n- Conduct quarterly access reviews of all third-party OAuth integrations, removing unused or excessive permissions immediately.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 5 – Account Management","CIS Control 15 – Service Provider Management","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 AC-6 – Least Privilege","NIST SP 800-53 SI-7 – Software, Firmware, and Information Integrity","NIST SP 800-53 CA-3 – System Interconnections","NIST CSF ID.SC-4 – Supply Chain Risk Management","GDPR Article 33 – Notification of a Personal Data Breach","GDPR Article 28 – Processor Obligations","ISO 27001 A.15.1 – Information Security in Supplier Relationships","ITIL – Third-Party and Supplier Management Practice","published","2026-06-23T20:21:48.804979+00:00","2026-06-23T20:21:48.54+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fhackread.com\u002Flastpass-customer-data-breach-klue-oauth-token\u002F","lastpass-confirms-customer-data-breach-after-klue-oauth-token-theft-6d2d83","LastPass Confirms Customer Data Breach After Klue OAuth Token Theft",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]