LastPass via Klue - supply chain
A theft of OAuth tokens at Klue (a sales intelligence tool integrated with Salesforce) gave access to the contact data of LastPass customers. The encrypted vaults were not exposed. The real risk is targeted phishing based on a contact list stolen at a peripheral subprocessor, not the compromise of the cryptographic core.
Takeaway : zero-knowledge protects the vaults, not the metadata held by third parties.