National Law Review
6/28/2026

LastPass vendor breach exposes customer data, raises phishing concerns
Original: Privacy Tip #497 – LastPass Security Incident Raises Concern for Targeted Phishing Attacks
Short summary
LastPass disclosed a vendor breach exposing customer contact information and CRM data through compromised Salesforce credentials. The platform recommends heightened phishing vigilance and reiterates that legitimate staff never request master passwords via unsolicited contact.
- •Vendor breach compromised LastPass customer contact details and CRM data via Salesforce access
- •Threat actor used stolen credentials to access customer information in LastPass environment
- •LastPass advises customers to watch for targeted phishing attempts using exposed contact information
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



