Key developments
Klue token theft exposes LastPass customer data
TechRadar reported that LastPass confirmed a third-party supply-chain incident after attackers obtained OAuth tokens held by Klue, a market intelligence platform integrated with LastPass Salesforce and Gong systems. The tokens were used to access LastPass customer data in Salesforce; LastPass said vaults and master passwords were most likely not exposed, but warned customers about phishing. BetaKit reported Klue tied the intrusion to a compromised legacy credential associated with a 2022 integration pilot and said contact, sales, and support information at customers including LastPass, OneTrust, and Sprout Social was accessed; Icarus reportedly claimed responsibility.
Why it matters
The incident shows how stale integration credentials and OAuth tokens can turn a vendor compromise into customer-data exposure across multiple enterprises.
Sources & driving stories
Xsolis phishing breach affects nearly 1.4 million people
Help Net Security's Sinisa Markovic reported that Xsolis, a healthcare technology company serving more than 600 hospitals and health insurers, confirmed unauthorized access after a targeted phishing attack on January 20, 2026. Xsolis detected unauthorized activity on January 22 and determined attackers acquired files that may include names, addresses, dates of birth, health insurance information, Social Security numbers, and medical treatment information. Data submitted to the U.S. Department of Health and Human Services says 1,396,519 individuals were impacted.
Why it matters
The breach involves protected health and identity data at healthcare scale, increasing fraud, identity-theft, and medical-privacy risk for affected patients.
Sources & driving stories
HELP NET SECURITY · Sinisa Markovic
Help Net Security coverageSCHUBERT JONCKHEER & KOLBE · Celina Reynes
Schubert Jonckheer & Kolbe coverageLondon police expand drones and facial recognition
Plataforma Media's Martim Silva reported that Metropolitan Police chief Mark Rowley announced expanded use of drones, fixed-camera facial recognition, and AI video analysis in London. A drone pilot launched in October has grown from two drones to nine, now monitoring about 200 incidents per week, and the Met plans a city-wide drone network. Police also plan more real-time facial recognition in areas such as the West End, citing more than 2,000 serious-crime arrests since early 2024, while Big Brother Watch warned of surveillance-state growth, misidentification, and discrimination risks.
Why it matters
The announcement moves biometric and AI-enabled surveillance closer to routine policing in one of the world's most camera-dense cities.
Sources & driving stories
PLATAFORMA MEDIA · Martim Silva
Plataforma Media coverageWorth noting
WORTH NOTING
Texas license vendor breach reported
Kaseya's June 24 breach roundup reported that Texas Parks and Wildlife Department disclosed a Texas Cyber Command-detected incident involving a hunting and fishing license system vendor, with potential access to driver's license, residential contact, and identification data for more than 3 million license holders.
WORTH NOTING
One Medical patient-data breach investigated
Schubert Jonckheer & Kolbe's Celina Reynes reported that Amazon-owned One Medical identified unauthorized access on June 13 to a third-party file storage system containing archived One Medical Seniors/Iora Health demographics and clinical records; ShinyHunters claimed 8.8 TB was exfiltrated, but the affected count has not been disclosed.
WORTH NOTING
Tracking litigation doctrine keeps shifting
MoFo reported that a Northern District of Illinois court allowed DOJ Bulk Sensitive Data Regulations allegations to support an ECPA crime-tort exception theory in Baker v. Index Exchange, while Law.com's Kat Black reported that a Northern District of California judge denied class certification against Capital One over individualized data-transmission, consent, and standing issues.
Still unclear
OPEN QUESTION
How far did Klue's integrations propagate exposure?
Affected customers and data categories vary across reports, and the incident turns on OAuth tokens and third-party platform access rather than data stored only inside Klue.
OPEN QUESTION
Can expanded surveillance meet privacy safeguards?
The Met is scaling drones, facial recognition, and AI analysis while civil-liberties groups warn about misidentification and discrimination, making governance details central.
