LastPass, the popular password manager which has over 33 million customers and 100,000 business users, has been hacked, again.
The company confirms that, unlike the last time, user data was exposed this time, but the company assures that passwords were not compromised.
LastPass CEO Karim Toubba stated that LastPass recently detected unusual activity within a third-party cloud storage service that the organization and affiliate GoTo currently share.
The hackers managed to gain access to “certain elements” of customers’ data. This was made possible using information acquired from the hack on LastPass in August when cybercriminals took portions of the site’s internal source code and documents relating to propriety technical information.
At that time the hackers gained access using a compromised developer account and snooped around the systems for four days before being discovered and booted.
LastPass emphasizes that the passwords remain safe because of its Zero Knowledge architecture, which ensures only the user knows the master password and encryption occurs only on the device level. As such, LastPass is not recommending that users change their passwords.
LastPass is continuing to work on understanding the scope of the incident and identifying what specific information has been accessed. Leading security firm Mandiant was engaged and they have alerted law enforcement.
This is not the first time LastPass’ security practices have come under question. In 2019, the company patched a security flaw that could have allowed hackers to scrape login details from the last site users visited. There was also a browser extension vulnerability in 2017.
In December, LastPass users reported that people were attempting to log in to their accounts from unknown locations using their correct master passwords. The company claimed these were likely the result of customers reusing passwords across multiple sites.
Those who use LastPass are recommended to download the authenticator app to help safeguard the account by enabling two-factor authentication codes when signing in to add an extra layer of protection.















Comments