LastPass Confirms Vendor Breach Exposing Customer Data And Raising Phishing Risk

corporate lawyer attorney US legal bankruptcy contract case

LastPass has confirmed a security incident involving a third-party vendor, putting customer contact information at risk and prompting urgent warnings about targeted phishing attacks.

The breach originated at a third-party market intelligence platform that integrates with LastPass systems, specifically its Salesforce and Gong environments, according to the company.

A threat actor used compromised credentials to access LastPass customer data held within its Salesforce environment, the company has acknowledged.

The exposed information is broad in scope, covering business contact details and customer relationship management data gathered through the company’s sales and support operations.

LastPass confirmed that the compromised data includes “business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.”

With that volume of personal and business contact information now in the hands of a threat actor, the risk of highly targeted phishing campaigns is considered significant.

LastPass is urging customers to “remain vigilant of potential phishing attacks or social engineering attempts, which could leverage exposed contact details.”

The company has also advised users to “always exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information.”

In a pointed reminder to its user base, LastPass stressed that “no one at LastPass will ever ask for your master password.”

The company also clarified that “all official communication from LastPass comes through our trusted support channels,” warning customers to treat any unexpected contact with suspicion.

Password managers hold a unique position in the digital security ecosystem, meaning any breach affecting customer data carries heightened implications for both personal and corporate security.

The incident serves as a broader reminder that third-party vendor relationships represent one of the most persistent and difficult-to-manage risks in enterprise cybersecurity today.

Organisations and individuals using LastPass are advised to stay alert, avoid clicking on unsolicited links, and verify any communication claiming to come from the company before taking action.