LastPass, the company behind the widely used password manager, is notifying customers that some of their personal information and customer support case records were stolen by hackers.

According to TechCrunch, the data was taken not through LastPass itself, but during a breach at Klue, a Canadian market research company that works with LastPass. Reporter Zack Whittaker writes that the stolen information includes customers' personal details and the records of support cases they had filed.

TechCrunch notes this is the second data breach to affect LastPass customers in recent years, with this latest incident again originating from one of the company's outside partners rather than its core systems.

The details matter because password managers are designed to be a security backstop — a single, heavily guarded vault holding the keys to a person's online life. When the company that runs one is connected to a breach, even indirectly, it raises pointed questions about how customer data is shared with and protected by third-party vendors.

The incident is also a reminder of how supply-chain exposure works in practice: a customer may never interact with Klue, yet their information can still be swept up when a contractor is compromised. Support case records, in particular, can contain details about a person's account and the problems they reported — useful raw material for follow-on phishing attempts.

LastPass has not, in these source items, disclosed how many customers were affected or the full scope of what was taken.

Why it matters: when a company built on trust to safeguard your passwords is tied to yet another breach, it underscores how a vendor's weak link can put millions of users' data at risk.