Password management firm LastPass was hacked that allowed threat actors to steal the company’s source code and proprietary technical information.
The security breach that occurred two weeks ago, targeted its development environment. LastPass released a security advisory confirming that it was breached through a compromised developer account that hackers used to access the company’s developer environment.
The company claims that there is no evidence that customer data or encrypted password vaults were compromised. But, the threat actors managed to steal portions of their source code and “proprietary LastPass technical information.”
LastPass in response to the incident have deployed containment and mitigation measures, and engaged a leading cybersecurity and forensics firm.
They did not provide further details regarding the attack, how the threat actors compromised the developer account, and what source code was stolen.
LastPass is one of the largest password management companies in the world, which is used by over 33 million people and 100,000 businesses.
LastPass stores passwords in ‘encrypted vaults’ that can only be decrypted using a customer’s master password, which LastPass says was not compromised in this cyberattack.















Comments