LastPass says hackers stole a backup copy of users' encrypted and unencrypted vault data using cloud storage keys stolen from a LastPass employee in August 2022
Password manager giant LastPass has confirmed that cybercriminals stole its customers' encrypted password vaults …
TechCrunch Zack Whittaker
Context & Ripple Effects
LastPass’s August disclosure was initially limited to stolen source code and technical information; the later August breach disclosure said users’ master passwords were safe. By early December, the company had tied the incident to customer data accessed from third-party cloud storage shared with parent GoTo.
The newly disclosed vault backup connects those two events: stolen cloud-storage keys turned an internal compromise into access to the data customers entrust LastPass to protect. Subsequent reporting identifies the DevOps-engineer compromise that enabled the theft, sharpening the importance of credential and endpoint controls around backup systems.
First-order effects
- LastPass customers’ vault backups, including encrypted and unencrypted data, are now in the attackers’ possession, materially expanding the exposure beyond the source-code theft disclosed in August.
- LastPass must treat cloud-storage credentials and the employee systems able to access them as the immediate control failure behind the vault-data loss.
Second-order effects
- GoTo and LastPass face heightened scrutiny of the shared third-party cloud environment previously identified in the customer-data access disclosure, because access to that environment enabled a much broader compromise.
- Password-manager customers and business buyers gain a clearer reason to assess how providers isolate backup data, cloud keys, and privileged employee access rather than evaluating encryption alone.
Third-order effects
- The incident points to password-manager security being governed by the full custody chain around encrypted vaults—backups, cloud credentials, and administrator endpoints—not solely by vault encryption.
- If providers continue to centralize customer vault backups in cloud environments, differentiation will increasingly rest on limiting the blast radius of a single privileged-employee compromise.
The trend: Password-management providers are being judged on whether their operational controls protect encrypted customer data across the entire cloud backup and privileged-access chain.
Related: LastPass · LastPass says customer data was accessed after cloud breach · LastPass says hacker stole source code and technical information · LastPass explains how 2022 password vault data was stolen
Related Coverage
- Notice of Recent Security Incident The LastPass Blog · Karim Toubba
- Cybercriminals Stole LastPass Customers' Encrypted Password Vaults Metacurity · Cynthia Brumfield
- LastPass Password Vaults Stolen By Hackers—Change Your Master Password Now Forbes · Davey Winder
- LastPass confirms hackers stole customer data from cloud storage Silicon Republic · Leigh Mc Gowran
- Hackers stole encrypted LastPass password vaults, and we're just now hearing about it The Verge · Mitchell Clark
- LastPass: Hackers Stole Customers' Encrypted Passwords, Other Sensitive Data CRN · Jay Fitzgerald
- LastPass users: Your info and password vault data are now in hackers' hands Ars Technica · Dan Goodin
- LastPass Confirms Customer Password Vaults Stolen by Hackers Tech Times · Urian B.
- LastPass Hack Gets Worse: Culprit Stole Customers' Encrypted Password Vaults PCMag · Michael Kan
- LastPass Confirms Hackers Stole Personal Data and Encrypted Password Vaults Petri IT Knowledgebase · Rabia Noureen
- LastPass security breach update: Customer password vaults were obtained 9to5Mac · Michael Potuck
- LastPass data breach is worse than first thought; user data and password vaults grabbed by hackers BetaNews · Sofia Wyciślik-Wilson
- You should stop using LastPass immediately Android Headlines · Hisan Kidwai
- The worst just happened: LastPass customer password vaults were stolen Phandroid · Tyler Lee
- LastPass hackers stole your encrypted passwords, Merry Christmas! BGR · Chris Smith
- LastPass confirms customer password vaults were stolen TechRadar · Sead Fadilpašić
- LastPass: Customer Vault Data Was Taken Infosecurity · Phil Muncaster
- LastPass admits attackers have a copy of customers' password vaults The Register · Simon Sharwood
- I will take the opportunity to post out what 1Password does differently. … @jpgoldberg@ioc.exchange · Jeffrey Goldberg
- LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolen The Hacker News
- LastPass revealed that encrypted password vaults were stolen Security Affairs · Pierluigi Paganini
- LastPass Hack Update: user vault data and information stolen gHacks Technology News · Martin Brinkmann
- LastPass reveals hacker copied encrypted customer password vaults SiliconANGLE · Duncan Riley
- The Lastpass hack was worse than the company first reported Engadget · Andrew Tarantola
- LastPass Says Hackers Stole Customer Data, Encrypted Passwords Bloomberg · William Turton
- Hackers obtained LastPass customer data vaults in recent data breach AppleInsider · Amber Neely
- LASTPASS NEWS ALERT AND COMMENTARY: LastPass attackers know your name and billing address and all websites you have saved passwords for, and if your master password isn't sufficiently strong may be possible to brute-force open everything on attacker's machines. … @SwiftOnSecurity@infosec.exchange
- If you were using Lastpass to store seeds for crypto wallets with any meaningful amount of coins in them, this might be a good time to move those funds to new wallets with fresh new seeds. @accidentalciso@infosec.exchange
- middot; Content warning: From the Birbsite @snipe@hackers.town
- @eric_capuano@infosec.exchange @spencerdailey@journa.host Oh, we know why: bEcAuSe ThAt'S nOt PeRsOnAl IdEnTiFyInG iNfOrMaTiOn. 🫠 @Aaron@social.aaroncrocco.com
- Here's the immediate problem I see with the #LastPass breach... I think it's news to most of us (it is for me at least) that the URLs of every saved credential were unencrypted … @eric_capuano@infosec.exchange · Eric Capuano
- Infosec Mastodon tonight is feeling a lot like Twitter did on a good day. @dangoodin@infosec.exchange · Dan Goodin
- Getting ChatGPT to write a phishing email https://www.youtube.com/... @malwaretech@infosec.exchange
- if you run into anyone trying to discount the severity of the lastpass breach by saying the master keys are impossible to crack, ask them how lastpass' key derivation works, what a credential stuffing attack is … @gsuberland@chaos.social
- * We were breached, but don't worry, your data was *not* stolen. * Ok, we were breached, and your data *was* stolen, but don't worry, it was encrypted. … @og@infosec.exchange
- Anyway, like other sane people have said, you don't have to stop using LastPass - for gods' sakes just use a password manager. If you use it, spend some time over the holidays changing all your meaningful passwords in it and your master password. … @hacks4pancakes@infosec.exchange
- I'm also worried about all y'all going “lololol pEoPle UsE LasTPaSs” when getting just one person on a reputable password manager they'll actually understand how to use is a massive, uphill battle. @hacks4pancakes@infosec.exchange
- LastPass customers should ensure they have changed their master password and all passwords stored in their vault. They should also make sure they're using settings that exceed the LastPass default. … @dangoodin@infosec.exchange · Dan Goodin
- I guess this is the major holiday week companies designate for dumping terrible breach news. @matthew_d_green@ioc.exchange · Matthew Green
- If you use LastPass this is extremely important news. Attackers have access to all your website URLs and encrypted passwords. This was effectively their only job and they failed. … @carnage4life@mas.to · Dare Obasanjo
- @malanalysis “why don't you roll your own encryption in Arch to create a custom vault and” as they shrivel into a corncob @hacks4pancakes@infosec.exchange
Discussion
-
@swiftonsecurity
@swiftonsecurity
on x
LastPass attackers now know all websites you have passwords stored for and the blobs, encrypted only by your master password https://blog.lastpass.com/... https://twitter.com/...
-
@gabsmashh
Lady G
on x
LastPass update: The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data as well as fully-encrypted sensitive fields. https://blog.lastpass.com/.…
-
@snipeyhead
@snipeyhead
on x
FWIW, here's what I told my employees re: the LastPass breach. Feel free to re-use without attribution. Hope it helps. What a mess. https://twitter.com/...
-
@jsrailton
John Scott-Railton
on x
Latest #LastPass breach may be worse than you think. Attacker didn't just get encrypted passwords. They got unencrypted URLs. Think: URLs with account tokens, API keys & credentials, etc... 1/ https://blog.lastpass.com/... https://twitter.com/...
-
@astuyve
AJ Stuyvenberg
on x
LastPass breach gets worse and worse. First: We were breached but no customer data was accessed Next: Okay some customer data was accessed, but not password vaults. Now: Customer password vaults were copied by the attacker but don't worry, it will be hard to crack your vault. htt…
-
@katebevan
Kate Bevan
on x
This is great from @zackwhittaker - it explains what the LastPass breach means to you. If your master password is short/weak/been used elsewhere, change it. Your vault is safe unless your password is weak or compromised. https://techcrunch.com/...
-
@kevincollier
Kevin Collier
on x
This is downright scandalous. Significantly more damning than anything in the Twitter files. More overt abuse of access to users' data from a tech company than anything I can think of in recent memory. https://www.ft.com/...
-
@tim_stevens
Tim Stevens
on x
Whelp. Sometimes it's hard to know whether to recommend Lastpass or 1password when people ask me about managers. This'll make that a lot easier going forward. https://twitter.com/...
-
@jamesrbuk
James Ball
on x
Feels like we need a much more decentralised framework for these - password managers are better than the alternative for most users, but they're *such* honeypots for hackers. https://twitter.com/...
-
@uk_daniel_card
@uk_daniel_card
on x
also a few things: 1) it's never nice being ownd 2) our friends work in orgs that get pwn3d. don't be a shitty human 3) the passwords are encrypted, if you have a “good” master password then risk is much much much lower 4) there is always some risk 5) use MFA ... mor2 follow
-
@gcluley
Graham Cluley
on x
Unfortunate timing with this latest disclosure. I'm sure LastPass wanted to be as transparent as possible about what occurred, and get the news out there as quickly as possible to users. It's just unfortunate some might not see it due to proximity to Christmas. https://twitter.co…
-
@b1ack0wl
@b1ack0wl
on x
Big yikes from LastPass lol https://twitter.com/...
-
@carnage4life
@carnage4life
on x
If you use LastPass this is extremely important news. Attackers have access to all your website URLs and encrypted passwords. This was effectively their only job and they failed. This feels somewhat inevitable given how big a prize the LastPass vault is but scary to see happen. h…
-
@gregosuri
Greg Osuri
on x
Lastpass was hacked, and customer vaults are with the attacker that can run a brute force attack to reveal your password and secret notes — it's only a matter of time. Change your passwords and renew your secrets ASAP if you've ever used Lastpass. https://twitter.com/...
-
@chrismessina
@chrismessina
on x
Merry Christmas you filthy LastPass threat actor https://twitter.com/... https://twitter.com/...
-
@stringstory
@stringstory
on x
This is v. bad LastPass. Solution: - add 2FA - use Authenticator - move to new password manager https://twitter.com/...
-
@jsrailton
John Scott-Railton
on x
2/ #LastPass has a giant target on their back because of the juicy data & password trove that they handle. And they are absolutely failing their customers. At this point, each time I hear about Last Pass it's: hey, they had *another breach*
-
@jsrailton
John Scott-Railton
on x
This #LastPass breach = worse than you think. Attacker didn't just get encrypted passwords. They got unencrypted URLs. Think: URLs with account tokens, API keys & credentials, etc... You or your company a LastPass customer? Change everything. https://blog.lastpass.com/... https:/…
-
@markvdnld
Mark Aangenaam
on x
Not only was @LastPass breached - hackers got the binary blobs of all data and even some unencrypted URL data. This is the end of LastPass. How can you recover from this? Your company has been failing on providing proper updates to begin with. Zero trust left. https://twitter.com…
-
@matthew_d_green
Matthew Green
on x
People seem to be misunderstanding this: as best I can tell it means that the attackers can now start running dictionary “password guessing” attacks against your master password.
-
@matthew_d_green
Matthew Green
on x
Nice announcement, LastPass. https://blog.lastpass.com/... https://twitter.com/...
-
@swiftonsecurity
@swiftonsecurity
on x
The fact LastPass doesn't encrypt website URLs is a known flaw it appears they never fixed on purpose, going back almost 6 years https://hackernoon.com/...
-
@cz_binance
@cz_binance
on x
LastPass provided an update. The hacker has all the user info including email address and websites URLs unencrypted. If the you reused passwords for the master password or has a weak master password, then it is possible for the hacker to obtain all of his/her credentials.
-
@secresdoge
Sebastian Bicchi
on x
This basically means you can offline brute force them (masterpasswords) and as it is done clientside, it is known *how* to do it. Fun. https://twitter.com/...
-
@dystopiabreaker
@dystopiabreaker
on x
lastpass has been obviously shit ever since tavis ormandy found a relatively simple “extiltrate all passwords” bug in their chrome extension and they responded poorly to it
-
@swiftonsecurity
@swiftonsecurity
on x
tldr LastPass attackers know your name and billing address and all websites you have saved passwords for, and if your master password isn't sufficiently strong may be possible to brute-force open everything on attacker's machines
-
@altcoinpsycho
@altcoinpsycho
on x
PSA: Stop using cloud-based password managers. I was called paranoid for ages for bad talking LastPass The safest place to store a password is in your brain https://twitter.com/...
-
@accidentalciso
@accidentalciso
on x
Folks that are migrating from LastPass to something else, what are you migrating to and why did you select that vendor? Is there something about that product's architecture that would materially reduce the potential risk that LastPass customers face right now?
-
@championswimmer
Arnav Gupta
on x
Despite even many well known infosec researchers actually suggesting users to use password managers, I'll never use one, because exactly this reason. The entropy of generated passwords isn't useful. I can remember high entropy passwords myself. “correct horse battery staple” http…
-
@nixcraft
@nixcraft
on x
Regarding lastpass, folks asking me: >>>LastPass just keeps having security incidents why do people still use it? For starters, having something like LastPass for the masses is more convenient. Second, it always depends upon your threat vector.
-
@evacide
Eva
on x
Pour one out for all of the security practitioners who are going to have to patiently explain that using a password manager is still good, actually, to people who have glanced at a headline about the latest LastPass breach.
-
@seanwrightsec
Sean Wright
on x
The LastPass incident is big news. But not for the reason why folk may think. We have a difficult time convincing folk to use password managers. This is most likely to harm that effort, sowing doubt with those who are a bit hesitant about doing so.
-
@afdudley0
Rick Dudley
on x
Friendly reminder the odds are such that if you use one of these services, they will be significantly compromised while you're using them and thus you shouldn't put anything important in them. https://twitter.com/...
-
@tomwarren
Tom Warren
on x
I'm glad I use 1Password and not LastPass because this is 😬 https://www.theverge.com/...
-
@billym2k
Shibetoshi Nakamoto
on x
lastpass was hacked 🤣 i think we should just assume that anything we do is public and will be hacked
-
@jsrailton
John Scott-Railton
on x
The #LastPass breach (just the latest, btw) is frustrating. Users that didn't follow “best practices” for their master password are vulnerable (customer password vaults were stolen!). But also because we've collectively spent years trying to move users to password managers. 1/
-
@cz_binance
@cz_binance
on x
LastPass suffered a breach recently. I recommended this password manager in my blog article before. They claim no impact to customer passwords, as it should be client side encrypted, but best to make sure you have 2FA enabled. https://www.npr.org/...