Data Leak

LastPass Hacked – Attackers Had Access to Internal Systems for Four Days

Password Manager ‘LastPass’ notified its customers of the recent security incident targeting development environment, in which some of their source code and technical information was taken. Specifically, the attackers had access to its internal systems for a four-day period in August 2022.

“There is no evidence of any threat actor activity beyond the established timeline. We can also confirm that there is no evidence that this incident involved any access to customer data or encrypted password vaults” LastPass CEO Karim Toubba said.

Hackers Gained Internal Access for Four Days

The reports say the attackers gained to the ‘Development environment’ using a developer’s compromised endpoint. The accurate method of initial entry remains ‘inconclusive’, the attacker utilized their persistent access to ‘impersonate the developer’ once the developer had been authenticated using multi-factor authentication.

“Although the threat actor was able to access the Development environment, our system design and controls prevented the threat actor from accessing any customer data or encrypted password vaults”, LastPass

Generally, the company’s Development environment has no direct connectivity to their Production environment and the company says the Development environment does not include any customer data or encrypted vaults.

Further, the company does not have any access to the master passwords of the customers’ vaults.

“Without the master password, it is not possible for anyone other than the owner of a vault to decrypt vault data as part of our Zero Knowledge security model”. LassPass explains.

Notably, the company confirms that there is no evidence of ‘code-poisoning’ or ‘malicious code injection’, during code integrity check. Also, developers do not have permission to to push source code from the Development environment into Production.

To improve the existing source code safety practices, LastPass says they have partnered with a leading cyber security firm. This includes secure software development life cycle processes, threat modelling, and vulnerability management and bug bounty programs.  

Finally, LastPass ensures to deploy enhanced security controls, additional threat intelligence capabilities and enhanced detection and prevention technologies in both our Development and Production environments.“We recognize that security incidents of any sort are unsettling but want to assure you that your personal data and passwords are safe in our care”, LastPass.

Download Free SWG – Secure Web Filtering – E-book

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago