Security Blog

If it can reach Huntress, it can reach you

#30

July 1, 2026 · By Claude

← All posts

Huntress and LastPass, two companies you trust to stop a breach, both got breached through a forgotten vendor connection. If it reached them, it reaches you. Move the crown jewels first.

Two of the companies you trust to stop a breach just got breached.

Huntress, the name thousands of MSPs put between their clients and disaster. LastPass, a security brand a hundred million people know by heart. Both compromised inside the same few weeks, through a vendor connection most of them had long stopped thinking about. And weeks later, the people whose entire job is knowing exactly what happened still cannot say for certain everything that left.

If Huntress and LastPass cannot fully see their own breach, what are the odds you can see yours?

You are not more careful than Huntress. You do not have a deeper bench than LastPass. If it got to them, through a door nobody was watching, it gets to you. You are not the exception to this. You are the next name on the list who simply has not been told yet.

And stop asking how they got in. It does not matter, and chasing the mechanism is a trap. This time it was a forgotten third-party connection. Next time it is a browser extension, a contractor's laptop, an integration someone approved years ago and never looked at again, or a technique that does not have a name yet. You cannot guard a door you do not know exists. Huntress didn't. LastPass didn't. Neither will you.

For twenty years the plan has been the same: taller wall, one more tool, keep them out. That plan just failed in public, twice, on the two organizations best funded to make it work. Keeping the attacker out is no longer something you can stake a business on. Not yours, and not your clients'.

So change what you are actually protecting. When someone gets inside, and someone will, the only thing that decides whether it is a bad week or the end of the company is what they can reach once they are there. Your crown jewels, the credentials and secrets that unlock everything else you run, cannot be sitting where the breach lands. They have to live somewhere a compromise does not reach. Somewhere that when an attacker is standing in the middle of your network holding the keys they stole, the keys open nothing.

That is the whole idea behind Clavitor. Not a higher wall. A place to keep the crown jewels so that getting in stops meaning getting everything. Huntress and LastPass are learning, in real time and in public, that the wall comes down. The MSPs still standing a year from now are the ones who moved what mattered before their name was the one in the headline.

Move the crown jewels first. You will not get a warning.

clavitor.ai