LastPass says a hacker stole portions of its source code and “proprietary LastPass technical information” two weeks ago, but users' master passwords are safe
Password management firm LastPass was hacked two weeks ago, allowing threat actors to steal the company's source code and proprietary technical information.
BleepingComputerLawrence Abrams
Context & Ripple Effects
LastPass had previously disclosed a 2015 compromise involving account-related data while saying its secure vault was not accessed. The August incident again began with an assurance that the most sensitive credential layer was outside the disclosed scope.
Later coverage made the August intrusion more consequential: LastPass disclosed four days of attacker access and then connected information stolen in August to a breach of cloud storage shared with GoTo, from which customer vault backups were taken.
First-order effects
LastPass must treat portions of its source code and proprietary technical information as exposed to attacker scrutiny, while maintaining that users' master passwords were not compromised.
Customers receive a limited initial assurance about master passwords, rather than confirmation that every system and data store remained untouched.
Second-order effects
The later disclosure of four days of access forced the incident's scope beyond a narrowly framed development-data theft and into a broader investigation of LastPass systems.
Information taken in August was later tied to the theft of customer vault backups from shared cloud storage, making the initial breach a precursor to customer-data exposure.
Third-order effects
For LastPass and other password managers, breach assurance increasingly has to cover employee access, development environments, and cloud-storage dependencies—not vault encryption alone.
The shared LastPass-GoTo cloud-storage exposure illustrates why password-manager security is becoming an ecosystem cyber-defense issue spanning connected corporate infrastructure.
The trend: Password-manager security is shifting from a vault-centric promise toward scrutiny of the full identity, development, and cloud-infrastructure chain.
We recently detected unusual activity within portions of the LastPass development environment and have initiated an investigation and deployed containment measures. We have no evidence that this involved any access to customer data. More info: https://blog.lastpass.com/... https:…
LastPass hack, as @troyhunt and others have said is a headache for the company but not a concern for customers. Passwords and vaults are safe. So these sorts of warnings from cyber firms are... excessive. https://twitter.com/...
Security incident at @LastPass. This feels like one of those “abundance of caution” things without tangible impact on subscribers https://blog.lastpass.com/... https://twitter.com/...
BleepingComputer learned of the LastPass breach on August 19th and was told employees were scrambling to contain the attack. BleepingComputer never received a response to our questions sent in multiple queries.
Today, LastPass released an advisory stating a developer's account was compromised two weeks ago and used to hack LastPass' developer systems. Using this access, the threat actors stole some of the company's source code and “proprietary LastPass technical information.”
Given what happened to the likes of SolarWinds, I think that there'll be questions from some around the integrity of their product. https://twitter.com/...