Password management firm LastPass has confirmed that it was the victim of a hack.
Threat actors stole the company’s source code along with proprietary technical information.
As one of the largest password management companies on the market, with over 33 million customers, the hack has raised concerns over whether its users’ credentials have been compromised.
The news was revealed by BleepingComputer. According to it, the attack took place two weeks ago, with the news site learning about the hack last week. It reached out to LastPass on August 21st, but received no response.
BleepingComputer cited sources that said employees at the company were working to contain the breach.
Since then, LastPass has released a security advisory confirming that it was breached. It warned that the hackers accessed its developer environment through a compromised developer account.
“After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults,” the company said.
“In response to the incident, we have deployed containment and mitigation measures, and engaged a leading cybersecurity and forensics firm. While our investigation is ongoing, we have achieved a state of containment, implemented additional enhanced security measures, and see no further evidence of unauthorized activity.
“Based on what we have learned and implemented, we are evaluating further mitigation techniques to strengthen our environment.”
LastPass reassured its customers that the hack did not access any master passwords used to protect its users’ account details.
“We never store or have knowledge of your Master Password. We utilize an industry standard Zero Knowledge architecture that ensures LastPass can never know or gain access to our customers’ Master Password,” it added.
As such, the company added that it did not recommend its users take additional security measures.
Recommended
- How Scotland’s IT infrastructure has transformed public services
- NATO investigating missile firm hack: What you need to know
- Deepfake tech creates AI hologram of Binance exec
Commenting on the LastPass hack, CEO and Co-founder of CyberSmart Jamie Akhtar said: “Understandably, the news of LastPass falling victim to a cyberattack may cause some distress; particularly, when cybersecurity experts advise time and again to utilise such password manager tools to create complex and unique passwords across accounts.
“However, it is important to remember that nothing is ever 100% secure and free of risk. Rather, people need to adopt a holistic approach to cybersecurity. That means also implementing multi-factor authentication, updating software regularly, undergoing security awareness training and even taking up cyber insurance to transfer the little bit of risk that we can’t always account for.
“There is no one-off fix, but a combination of steps that internet users must proactively incorporate into their everyday online habits.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





