Confirmed: Klue’s integration with Salesforce exposed LastPass customer data (and there are lessons for us all to learn)

AI-powered market research platform Klue describes its dynamic battlecards for sales teams as โ€œan essential weapon for reps facing tough competition and savvy buyersโ€. Sadly, it has discovered that hackers also like the weapon analogy, with several of its customers falling victim to an attack through its integrated systems.

Although the actual extent of the attacks is yet to be determined, we know cybersecurity vendors are among them. One of the most notable is password manager LastPass, which has confirmed that the attackers were able to โ€œaccess LastPass customer data within our Salesforce environmentโ€. Data that may have included โ€œcustomer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related dataโ€.

The newly discovered Icarus ransomware and extortion group, first observed in the wild earlier this month, has claimed responsibility for the attack. โ€œWe advice (sic) Klue to contact us for a swift resolution, in order not to affect the companies you work with,โ€ the group demanded, adding that if Klue didnโ€™t โ€œaccommodate this request, we advice (sic) the companies who want to protect their data to contact usโ€.

Example of a Klue Battlecard
Example of a Klue Battlecard (image: Klue)

Response from Klue, LastPass and Salesforce

Klue CEO Jason Smith has since released a statement to update customers on the incident, first identified on 12 June, when unauthorised activity was found in โ€œa portion of Klueโ€™s integration infrastructureโ€.

The attackers gained access โ€œthrough a compromised legacy credential associated with an integration service,โ€ Smith said, which I understand to be the Battlecards app, that then enabled attackers to โ€œobtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environmentsโ€.

Salesforce, for its part, has said it has โ€œdisabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident.โ€

โ€œThere is no evidence that customer content stored within the Klue platform was impacted,โ€ Smith said, adding that โ€œspecific remediation guidance has been shared directly with affected customersโ€.

LastPass has also contacted affected customers while confirming that โ€œLastPass products, services, and infrastructure were not impacted in any way and customer vaults remain secureโ€.

How to fight Klue attacks… and similar

Josh Picolet, VP of Detection & Analysis at Team Cymru, told me that the most important lesson from the Klue incident is that attackers are increasingly targeting the connective tissue between organisations rather than the organisations themselves.

โ€œThird-party platforms often sit at the centre of large networks of trust,โ€ Picolet said, โ€œmaking them attractive targets because a single compromise can create downstream access to dozens or hundreds of victims.โ€

โ€œYour security is now only as strong as the third-party apps you have granted standing access to your CRM,โ€ Sunil Gottumukkala, CEO, at Averlo warned, โ€œand most teams donโ€™t actively track those integrations.โ€

I will leave the last words to Denis Calderone, CTO, Suzu Labs, who pointed out that there have now been three Salesforce OAuth supply chain attacks in under a year, from two different threat actors, using the same playbook.

โ€œAt this point, we have to accept that this particular attack pattern has been successfully commoditised,โ€ he said.

In terms of mitigation? โ€œIf you’re a Klue customer, rotate every OAuth token tied to that integration, and don’t limit yourself to Salesforce. If Klue had an OAuth connection into your Slack, your Google Drive, or anything else, treat those tokens as compromised and rotate them now.โ€

The real takeaway here, though, is that every organisation must audit all connected apps for any dormant integration credentials, paying particular attention to automating alerts for abnormal API query volumes from third-party services.

โ€œIf a connected app that normally syncs a few hundred records starts pulling thousands of queries in minutes,โ€ Calderone concluded, โ€œthat’s your early warning.โ€

More by Davey Winder

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.