LastPass breached for the second time in 2022

LastPass, one of the most popular password management tools on the market, disclosed that it has been breached. This is the second time this year the company has disclosed a breach. LastPass CEO Karim Toubba said in a press release that “certain elements of our customers’ information” was accessed by the attackers.

“We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement,” said Toubba. 

Despite the attackers accessing customer information, Toubba believes that customer passwords remain intact.

“We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information. Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture,” continued Toubba.

While the third-party cloud service provider was not named, according to TechCrunch it is believed that it is most likely AWS. A 2020 company blog post by AWS cited the company’s transition of a billion customer records to Amazon’s cloud platform.

In August, Toubba said that an “unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account.” Product source code was part of the stolen data.

LastPass is still working with Mandiant to understand what specific data was accessed.

You May Also Like

Wiz Cloud Cybersecurity Platform raises $1B at $12B valuation

Wiz is one of the fastest-growing cybersecurity startups, with an IPO on the horizon

RSAC 2024: Google Threat Intelligence unveiled

Google’s new cybersecurity threat intelligence offering is powered by Gemini, VirusTotal, and Mandiant

Microsoft Deploys GPT-4 to Azure Government Top Secret Cloud for DoD

OpenAI’s GPT-4 multimodal large language model is coming to Azure Government Cloud Top Secret