Klue: 2022 legacy credential led to customer data exfiltration

Colleagues, please note: a cybersecurity incident at Klue. A legacy credential led to a customer data breach.
Klue acknowledged that a 'legacy' credential, issued to a third party in 2022 for a pilot, was compromised. Attackers discovered on 12 June leveraged access to OAuth tokens, downloaded customer data — including LastPass items — and extorted affected parties.
The company is investigating and reviewing its access-management practices but has not explained why the credential wasn't revoked after the pilot or where it was stolen.
Why it matters: stale vendor access is a critical risk that demands formal review and strict revocation timelines.
How do you manage vendor access and stale credentials?
#cybersecurity #databreach #accessmanagement #informationsecurity

