/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LastPass says a hacker stole portions of its source code and “proprietary LastPass technical information” two weeks ago, but users' master passwords are safe

Password management firm LastPass was hacked two weeks ago, allowing threat actors to steal the company's source code and proprietary technical information.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

LastPass had previously disclosed a 2015 compromise involving account-related data while saying its secure vault was not accessed. The August incident again began with an assurance that the most sensitive credential layer was outside the disclosed scope.

Later coverage made the August intrusion more consequential: LastPass disclosed four days of attacker access and then connected information stolen in August to a breach of cloud storage shared with GoTo, from which customer vault backups were taken.

First-order effects

  • LastPass must treat portions of its source code and proprietary technical information as exposed to attacker scrutiny, while maintaining that users' master passwords were not compromised.
  • Customers receive a limited initial assurance about master passwords, rather than confirmation that every system and data store remained untouched.

Second-order effects

  • The later disclosure of four days of access forced the incident's scope beyond a narrowly framed development-data theft and into a broader investigation of LastPass systems.
  • Information taken in August was later tied to the theft of customer vault backups from shared cloud storage, making the initial breach a precursor to customer-data exposure.

Third-order effects

  • For LastPass and other password managers, breach assurance increasingly has to cover employee access, development environments, and cloud-storage dependencies—not vault encryption alone.
  • The shared LastPass-GoTo cloud-storage exposure illustrates why password-manager security is becoming an ecosystem cyber-defense issue spanning connected corporate infrastructure.

The trend: Password-manager security is shifting from a vault-centric promise toward scrutiny of the full identity, development, and cloud-infrastructure chain.

Discussion

  • @lastpass @lastpass on x
    We recently detected unusual activity within portions of the LastPass development environment and have initiated an investigation and deployed containment measures. We have no evidence that this involved any access to customer data. More info: https://blog.lastpass.com/... https:…
  • @seldo Laurie Voss on x
    It has been [0] months since Lastpass announced a major security breach: https://www.bleepingcomputer.com/ ... https://twitter.com/...
  • @sarthakgh @sarthakgh on x
    Literally the only job they had https://twitter.com/...
  • @joetidy Joe Tidy on x
    LastPass hack, as @troyhunt and others have said is a headache for the company but not a concern for customers. Passwords and vaults are safe. So these sorts of warnings from cyber firms are... excessive. https://twitter.com/...
  • @troyhunt Troy Hunt on x
    Security incident at @LastPass. This feels like one of those “abundance of caution” things without tangible impact on subscribers https://blog.lastpass.com/... https://twitter.com/...
  • @bleepincomputer @bleepincomputer on x
    BleepingComputer learned of the LastPass breach on August 19th and was told employees were scrambling to contain the attack. BleepingComputer never received a response to our questions sent in multiple queries.
  • @lawrenceabrams Lawrence Abrams on x
    Was told about this breach last week. LastPass never got back to me. At least we got an advisory out of it. https://www.bleepingcomputer.com/ ...
  • @bleepincomputer @bleepincomputer on x
    Today, LastPass released an advisory stating a developer's account was compromised two weeks ago and used to hack LastPass' developer systems. Using this access, the threat actors stole some of the company's source code and “proprietary LastPass technical information.”
  • @seanwrightsec Sean Wright on x
    Given what happened to the likes of SolarWinds, I think that there'll be questions from some around the integrity of their product. https://twitter.com/...