/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Password manager OneLogin compromised, says hackers have ability to decrypt encrypted data and all users served by US data center are affected

attackers access data and decryption keys Alvaro Hoyos / OneLogin Identity Management Blog : May 31, 2017 Security Incident (UPDATED June 1, 2017) JC Torres / SlashGear : OneLogin attacker may have gotten ability to decrypt data Gareth Halfacree / bit-tech.net : OneLogin hit by major data breach Joseph Cox / Motherboard : Identity Manager OneLogin Has Suffered a Nasty Looking Data Breach Devin Coldewey / TechCrunch : OneLogin admits recent breach is pretty dang serious Dell Cameron / Gizmodo : Workplace App Scrambles to Rescue Users Who Foolishly Used Its Service to Store Passwords Simon Sharwood / The Register : Identity management outfit OneLogin sugar coats impact of attack Kelly Fiveash / Ars Technica : OneLogin suffers breach—customer data said to be exposed, decrypted Pastebin : On Wednesday, May 31, 2017 we detected that there was unauthorized access to One Zeljka Zorz / Help Net Security : OneLogin suffers data breach, again Morgan Chalfant / The Hill : Password manager OneLogin suffers data breach Alfred Ng / CNET : OneLogin breach means you need a password fix, stat Brian Krebs / Krebs on Security : OneLogin: Breach Exposed Ability to Decrypt Data BBC : Password manager OneLogin hit by data breach David McCabe / Axios : Password manager OneLogin has been hacked Jai Vijayan Freelance / darkREADING : OneLogin Breach Reignites Concerns over Password Managers Eric David / SiliconANGLE : Password manager OneLogin compromised by data breach Rene Millman / SC Media UK : Sys Admins warned to be vigilant as OneLogin admits security breach Chris Brook / Threatpost : OneLogin Breach Compromised Customer Data, Ability to Decrypt Encrypted Data Swati Khandelwal / The Hacker News : OneLogin Password Manager Hacked; Users' Data Can be Decrypted Anthony Caruana / Lifehacker Australia : Have You Been Impacted By The OneLogin Breach? Dan Raywood / Infosecurity Magazine : OneLogin Reports Unauthorized Access, User Data Compromised Ashlee Kieler / Consumerist : Do You Use OneLogin? Change Your Password Now Roland Moore-Colyer / Silicon UK : OneLogin Password Manager Suffers Data Breach Doug Olenick / SC Media US : OneLogin breached, passwords possibly compromised AJ Dellinger / International Business Times : OneLogin Hacked: ID Manager Database Breached, User Information Compromised Tweets: Jason M. Lemkin / @jasonlk : every CEO needs to understand how their KeyStore works especially if nontechnical many trade-offs here and the risks are real http://twitter.com/... Leo Laporte / @leolaporte : Whatever happened to hashed and salted? “The company said that hackers have ‘the ability to decrypt encrypted data’: http://www.zdnet.com/... Chris Messina / @chrismessina : “While we encrypt certain sensitive data at rest, [we can't rule out that the hacker decrypted user and app] data.” http://www.onelogin.com/... @spencerdailey : services, especially password managers, should employ a trust-no-one encryption scheme for their end users. This hints OneLogin may not http://twitter.com/... Zack Whittaker / @zackwhittaker : Thread: A few people have said “don't use central authentication.” I get the logic, especially after OneLogin: http://www.zdnet.com/... (1/6) Thanks: @zackwhittaker

ZDNet Zack Whittaker

Context & Ripple Effects

OneLogin's disclosure is unusually severe for a credential vendor: attackers didn't just exfiltrate encrypted customer data, they also reached the ability to decrypt it, meaning every user served by its US data center has to assume their stored passwords are readable. The company is in emergency-response mode, scrambling users onto resets.

This is the first clear instance of a pattern that keeps repeating: five years later, LastPass disclosed hackers stole vault backups using cloud storage keys taken from a LastPass employee, after initially revealing access through third-party cloud storage shared with parent GoTo — and GoTo later confirmed an encryption key for some data was among what was stolen. In both cases the vault's own key material was within reach of the attacker, which is precisely what makes these breaches worse than ordinary data thefts.

First-order effects

  • Every OneLogin customer served by the US data center must treat all stored passwords and API credentials as compromised and rotate them immediately — for enterprises using it as an SSO/identity hub, that means resetting federated access across every connected service at once.
  • OneLogin faces immediate churn pressure: customers who chose it specifically to centralize credentials now have a single point of compromise that exposed everything they centralized.

Second-order effects

  • Rival password managers inherit both an opportunity and a burden: they gain panicked switchers from OneLogin, but the breach invites scrutiny of whether any vendor that holds decryption capability alongside encrypted vaults can credibly promise safety.
  • Enterprise buyers start pricing 'key custody' into identity-vendor selection, asking where decryption keys live relative to the encrypted store — a question OneLogin's architecture just failed publicly.

Third-order effects

  • If the OneLogin-then-LastPass sequence is the template, credential vaults converge on designs where the vendor structurally cannot decrypt customer data — client-side key handling, per-user keys — because 'encrypted at rest' proves meaningless when the keys sit on the same compromised infrastructure.
  • Repeated failures at the category's leaders push identity management itself under procurement and regulatory review as critical infrastructure, since one vault breach now cascades into every downstream system those credentials unlock.

The trend: Credential-vault providers keep getting breached through their own decryption infrastructure, forcing the industry toward architectures where the vendor never holds the keys that matter.