LastPass sells one thing: a locked box. The box is the product. The box is the brand. When the box leaks, the company does not have a messaging problem — it has an engineering problem.
On June 23, LastPass confirmed that hackers stole customer support case data during a breach at Klue, one of its technology partners. The data did not come from Klue's own operations. It came from LastPass's. Klue was the door. The files inside were LastPass's.
This is the second incident to hit LastPass customers in recent years. The first was worse by most measures, reaching encrypted password vaults. This one appears limited to support case metadata — the records generated when a customer contacts the help desk. LastPass has not said how many cases were exposed, what fields were included, or whether contact information, account identifiers, or reported vulnerabilities appear in the stolen set.
That silence is itself a data point.
The tradeoff embedded in every SaaS security product is the one nobody puts on the slide: your security is now only as tight as your vendor's vendor's vendor. LastPass's 2022 breach ran through a compromised developer endpoint. This one ran through a support tooling partner. Different door, same result — data that customers trusted to a security product is now somewhere else.
The machine LastPass sells is trust operationalized as software. Every breach is a benchmark run on that machine. This is the second benchmark in recent memory. The number is not good.