LastPass 通知用户再次发生数据泄露事件
LastPass notifies users of yet another data breach

原始链接: https://9to5mac.com/2026/06/23/lastpass-notifies-users-of-yet-another-data-breach/

LastPass 已通知用户其第三方合作伙伴、市场研究公司 Klue 发生数据泄露事件。此次事件泄露了标准的业务联系方式及客户关系管理(CRM)信息,包括姓名、电话号码、电子邮箱地址、物理地址,以及与客户支持和销售相关的详细信息。 为此,LastPass 已撤销员工对 Klue 的访问权限,更新了受影响的 API 令牌,并与 Klue 和 Salesforce 联合展开调查。公司提醒用户,务必警惕可能利用这些被盗数据进行的网络钓鱼和社交工程攻击。 为了帮助企业识别相关活动,LastPass 公布了一份与此次泄露事件相关的可疑 IP 地址和电子邮件域名列表。继 2015 年和 2022 年发生重大安全事件后,此次事件是该公司面临的又一安全挑战。尽管此次泄露仅涉及业务联系数据,不涉及加密的保险库信息,但仍建议用户对潜在诈骗保持警惕。

LastPass 近期披露了另一起数据泄露事件,源于其第三方供应商 Klue 的安全事故。尽管最初关于密码安全性的担忧在 Hacker News 上引发了争议,但澄清显示,此次事件仅涉及联系方式,并未导致用户密码库被非法访问。 此次讨论凸显了人们对集中式密码管理工具日益增长的怀疑。批评者认为,这些服务因数据过于集中而造成了“系统性风险”,使其成为攻击者眼中的高价值目标。评论者指出,密码管理工具的规模已使其成为主要攻击目标,即便不涉及密码库本身的泄露,也会严重损害用户信任。其他人则指出,这已不是该公司首次发生安全事件,并将其反复发生的泄露归咎于公司未能优先考虑核心产品的完整性,反而过度关注第三方集成与业务增长。 归根结底,这场讨论反映了网络安全领域中更深层的矛盾:即集中式凭证管理所带来的便利性,与单一供应商遭受攻击时可能引发的灾难性后果之间,始终存在着权衡。
相关文章

原文

LastPass users are once again being warned about stolen personal data, though this time the breach happened through one of the company’s outside partners. Here are the details.

As reported by TechCrunch, LastPass is emailing users affected by a breach at market research firm Klue, which allowed hackers to access customer information and support case data.

The news came as LastPass shared more information on a blog post, where it explained:

The information accessed was limited to standard business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.

LastPass said that upon learning about the incident, the company revoked employee access to Klue, rotated the exposed API tokens, notified law enforcement, and launched “a detailed investigation into the scope of the event, working with our contacts at both Klue and Salesforce.”

The company explains that Klue’s platform integrates with Salesforce and Gong systems.

As a result, LastPass is recommending that customers “remain vigilant of potential phishing attacks or social engineering attempts” leveraging the compromised information. LastPass also shared the following IP addresses and email sender domains associated with the attackers, which companies can use to search for related activity in their systems:

IP Addresses: 

  • 138.226.246[.]94 
  • 94.154.32[.]160 
  • 159.183.215[.]61 
  • 159.183.181[.]239

Email Sender Domains: 

  • baccarat.com[.]au 
  • robinskitchen.com[.]au 
  • house.com[.]au

This is the latest in a series of security incidents affecting LastPass. In 2015, hackers obtained account email addresses, password reminders, authentication hashes, and cryptographic salts, although LastPass said encrypted vault data was not accessed.

In 2022, an attacker compromised a developer account and stole source code and technical information. The attacker later used that information to access cloud backups containing customer records and encrypted password vaults, along with unencrypted details such as names, billing addresses, email addresses, and phone numbers⁠.

To learn more about the Klue breach and LastPass’s response, follow this link.

Worth checking out on Amazon

FTC: We use income earning auto affiliate links. More.

联系我们 contact @ memedata.com