LastPass, one of the world’s most popular password manager platforms, has revealed that customer information may have been accessed following a cybersecurity breach.
In a statement yesterday (Wednesday 31st November), the firm published an update following a months-long investigation into a data breach first uncovered in August.
At the time, the firm said a threat actor had gained unauthorised access to some of the company’s source code through a compromised third-party cloud storage device.
The LastPass investigation found that the hacker used data obtained in the August breach to view customer information and gain unauthorised access to the firm’s developer environment.
In total, the threat actor only gained access to internal systems for four days, and the investigation found no evidence of serious tampering.
“We have determined that an unauthorised party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information,” said LastPass CEO, Karim Toubba.
“Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture,” Toubba added.
Despite the breach, the company insisted that user passwords had not been exposed. This is due to the company’s policy of maintaining separate production and developer environments.
As such, the firm said that no sensitive customer data or master passwords had been compromised, meaning that only users have the ability to decrypt password information.
“Developers do not have the ability to push source code from the development environment into production,” the company said in its August statement.
“This capability is limited to a separate build release team and can only happen after the completion of rigorous code review, testing, and validation processes.”
Recommended
- New initiative offers free mentorship to tech companies
- EV charging infrastructure needs private sector investment to grow
- Now is the Time to Put Customers at the Heart of Your Business
LastPass is one of the most popular password managers available on the market and is used by more than 33 million users globally.
The platform allows users to save and encrypt their passwords in a secure storage space. Users can use the service across multiple devices to save time remembering passwords.
Ongoing investigation
LastPass revealed it had employed the services of cybersecurity firm Mandiant as part of its investigation into the August breach and is working with law enforcement.
The firm’s investigation into the incident is still ongoing, and Toubba confirmed that updates on its progress will be revealed in the interest of transparency.
“We are working diligently to understand the scope of the incident and identify what specific information has been accessed,” Toubba continued.
“In the meantime, we can confirm that LastPass products and services remain fully functional.”
Following the incident, LastPass said it will employ more robust security measures to “help detect and prevent further threat actor activity”.
The firm also plans to expand monitoring capabilities across its infrastructure.
“As part of our efforts, we continue to deploy enhanced security measures and monitoring capabilities across our infrastructure to help detect and prevent further threat actor activity.”
Get all the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





