Hackers were able to steal LastPass’ encrypted password vaults during an attack in August. The company told about it only now

Hackers were able to steal LastPass' encrypted password vaults during an attack in August.  The company told about it only now

In August of this year, it became known about a hacker attack on the largest password storage service LastPass. The company said at the time that the hackers were able to steal the company’s source code and confidential information, but that password data was not compromised and users did not need to take any action to protect their accounts. But now it turned out that in reality everything was worse than it was said at first.

On December 22, the LastPass administration announced that the latest hack turned out to be more destructive. The fact is that the hackers were able to gain access to user data and “copy a backup copy of customer storage data.” Thus, attackers have at least a complete set of encrypted personal data of LastPass users. And if they can crack the stolen vaults, then theoretically they will have access to all the customers’ passwords.

“During the August 2022 incident, there was no access to customer data,” said LastPass CEO Karim Tubba.

However, some of the app’s source code was stolen and then used to phish a Lastpass employee. As a result, it was possible to gain access to his credentials, and then the hackers used the keys obtained in this way to decrypt and copy some storage volumes in the cloud storage service.

The encrypted data obtained by hackers includes basic customer account details including company names, payment details, email address, IP addresses, phone numbers.

Course

EMPLOYER BRANDING

Build a high-quality and attractive employer brand in just one month.

REGISTER!EMPLOYER-BRANDING

“These encrypted fields remain secure with 256-bit AES encryption and can only be decrypted using a unique encryption key derived from each user’s master password using our zero disclosure architecture,” Tubba said. “A reminder that the master password is not known to, stored, or maintained by LastPass.”

However, given the scope of the leak and the potential threats, it makes sense for LastPass users to change all passwords for all their accounts, as well as change their master password.

Source: Engadget

Related Posts

Steven Spielberg to make a UFO movie, and Martin Scorsese a Frank Sinatra biopic with DiCaprio, and more

Advanced age does not prevent truly talented filmmakers from achieving success and then taking on new projects. Scorsese After 10 Oscar nominations for last year’s crime film…

10 differences between the games and the Amazon series

Against the background of the success of the Fallout series produced by Amazon, the number of players in the games of this post-apocalyptic series has increased. The…

how company shares make its employees millionaires

The state that can be obtained by helping to develop a successful company is vividly illustrated by the example of NVIDIA employees. One of them, a “middle-ranking”…

Warner Bros. earned $1 billion abroad in a record 15 weeks — almost half came from the second “Dune”

The studio also became the first to reach this milestone in 2024. Warner Bros. earned more than $1 billion at the international box office in a record…

44% of developers use two programming languages ​​at work

44% of developers most often use two programming languages ​​at work. But you can “enter IT” with only one language – 37% of developers who started working…

Microsoft has fixed a 2-year-old issue that prevented systems with certain Intel Rocket Lake chips from upgrading to Windows 11

Microsoft has made it easier to upgrade certain computers to Windows 11. In the latest Windows 11 update, the company fixed a bug that prevented computers with…

Leave a Reply

Your email address will not be published. Required fields are marked *