Site navigation

LastPass Cybersecurity Breach | Here’s What You Need to Know

Ross Kelly

,

LastPass
LastPass had assured users that passwords remain safe.

LastPass, one of the world’s most popular password manager platforms, has revealed that customer information may have been accessed following a cybersecurity breach.

In a statement yesterday (Wednesday 31st November), the firm published an update following a months-long investigation into a data breach first uncovered in August.

At the time, the firm said a threat actor had gained unauthorised access to some of the company’s source code through a compromised third-party cloud storage device.

The LastPass investigation found that the hacker used data obtained in the August breach to view customer information and gain unauthorised access to the firm’s developer environment.

In total, the threat actor only gained access to internal systems for four days, and the investigation found no evidence of serious tampering.

“We have determined that an unauthorised party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information,” said LastPass CEO, Karim Toubba.

“Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture,” Toubba added.

Despite the breach, the company insisted that user passwords had not been exposed. This is due to the company’s policy of maintaining separate production and developer environments.

As such, the firm said that no sensitive customer data or master passwords had been compromised, meaning that only users have the ability to decrypt password information.

“Developers do not have the ability to push source code from the development environment into production,” the company said in its August statement.

“This capability is limited to a separate build release team and can only happen after the completion of rigorous code review, testing, and validation processes.”


Recommended


LastPass is one of the most popular password managers available on the market and is used by more than 33 million users globally.

The platform allows users to save and encrypt their passwords in a secure storage space. Users can use the service across multiple devices to save time remembering passwords.

Ongoing investigation

LastPass revealed it had employed the services of cybersecurity firm Mandiant as part of its investigation into the August breach and is working with law enforcement.

The firm’s investigation into the incident is still ongoing, and Toubba confirmed that updates on its progress will be revealed in the interest of transparency.

“We are working diligently to understand the scope of the incident and identify what specific information has been accessed,” Toubba continued.

“In the meantime, we can confirm that LastPass products and services remain fully functional.”

Following the incident, LastPass said it will employ more robust security measures to “help detect and prevent further threat actor activity”.

The firm also plans to expand monitoring capabilities across its infrastructure.

“As part of our efforts, we continue to deploy enhanced security measures and monitoring capabilities across our infrastructure to help detect and prevent further threat actor activity.”


Get all the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data