Password management security company LastPass confirmed that a security breach occurred around early August 2022. The breach was said to have infiltrated the company’s development environment.
LastPass CEO Karim Toubba sent a notice to all of the company’s customers, informing them of the security incident.
He notes, “We have determined that an unauthorised party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information.”
The CEO notes that the company did not see evidence of stolen customer data or encrypted password vaults. Toubba additionally guarantees that LastPass products and services are operating normally.
The company also discloses that it has employed containment and mitigation measures. It has also engaged undisclosed leading cybersecurity and forensics firm to help with its investigation. The notice also provided a list of frequently asked questions for its customers while stipulating that no action must be taken.
Toubba reassures that no data was compromised because the LastPass zero-knowledge model ensures that only the customers can decrypt and view their vault data.
According to ZDNet senior contributing editor Steven Vaughan-Nichols, this wasn’t the first time LastPass was hacked. Nichols outlines that the security researchers uncovered a security problem in 2019.
In 2020 the company had a significant outage, wherein users could not log into their accounts. In 2021 it appeared that some users’ LastPass Master Passwords might have been disclosed as users received alerts that their master passwords were used by someone else. The company assured its customers that their information was safe and their security wasn’t breached.
Nichols points out that despite LastPass having significant annual security problems and its recent breach revealing its proprietary source code and technical secrets, it is still an excellent password security company due to its zero-knowledge model.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...