LastPass Cops to Massive Breach Including Customer Vault DataLastPass Cops to Massive Breach Including Customer Vault Data
The follow-on attack from August's source-code breach could fuel future campaigns against LastPass customers.
![Screen capture of LastPass home page Screen capture of LastPass home page](https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltdb444ce99cff994c/64f15ddbf169c58149886dad/lastpass_screen_cap.png?width=1280&auto=webp&quality=95&format=jpg&disable=upscale)
LastPass has issued a statement acknowledging that a recent cyberattack has resulted in the theft of customer data, in addition to offering cybercrooks access to encrypted customer vaults.
The attack was a follow-on from a previous breach in August that resulted in the theft of the LastPass source code.
"To date, we have determined that once the cloud storage access key and dual storage container decryption keys were obtained, the threat actor copied information from backup that contained basic customer account information and related metadata including company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service," the company statement said.
LastPass added that a backup copy of encrypted customer vault data was also stolen, including website usernames, passwords, secure notes, and form-filled data.
The company warns customers to be on the lookout for phishing, credential stuffing, and brute-force attacks as a result of the compromise.
About the Author
You May Also Like
Uncovering Threats to Your Mainframe & How to Keep Host Access Secure
Feb 13, 2025Securing the Remote Workforce
Feb 20, 2025Emerging Technologies and Their Impact on CISO Strategies
Feb 25, 2025How CISOs Navigate the Regulatory and Compliance Maze
Feb 26, 2025Where Does Outsourcing Make Sense for Your Organization?
Feb 27, 2025