/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LastPass says hackers stole a backup copy of users' encrypted and unencrypted vault data using cloud storage keys stolen from a LastPass employee in August 2022

Password manager giant LastPass has confirmed that cybercriminals stole its customers' encrypted password vaults …

TechCrunch Zack Whittaker

Context & Ripple Effects

LastPass’s August disclosure was initially limited to stolen source code and technical information; the later August breach disclosure said users’ master passwords were safe. By early December, the company had tied the incident to customer data accessed from third-party cloud storage shared with parent GoTo.

The newly disclosed vault backup connects those two events: stolen cloud-storage keys turned an internal compromise into access to the data customers entrust LastPass to protect. Subsequent reporting identifies the DevOps-engineer compromise that enabled the theft, sharpening the importance of credential and endpoint controls around backup systems.

First-order effects

  • LastPass customers’ vault backups, including encrypted and unencrypted data, are now in the attackers’ possession, materially expanding the exposure beyond the source-code theft disclosed in August.
  • LastPass must treat cloud-storage credentials and the employee systems able to access them as the immediate control failure behind the vault-data loss.

Second-order effects

  • GoTo and LastPass face heightened scrutiny of the shared third-party cloud environment previously identified in the customer-data access disclosure, because access to that environment enabled a much broader compromise.
  • Password-manager customers and business buyers gain a clearer reason to assess how providers isolate backup data, cloud keys, and privileged employee access rather than evaluating encryption alone.

Third-order effects

  • The incident points to password-manager security being governed by the full custody chain around encrypted vaults—backups, cloud credentials, and administrator endpoints—not solely by vault encryption.
  • If providers continue to centralize customer vault backups in cloud environments, differentiation will increasingly rest on limiting the blast radius of a single privileged-employee compromise.

The trend: Password-management providers are being judged on whether their operational controls protect encrypted customer data across the entire cloud backup and privileged-access chain.

Discussion

  • @swiftonsecurity @swiftonsecurity on x
    LastPass attackers now know all websites you have passwords stored for and the blobs, encrypted only by your master password https://blog.lastpass.com/... https://twitter.com/...
  • @gabsmashh Lady G on x
    LastPass update: The threat actor was also able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data as well as fully-encrypted sensitive fields. https://blog.lastpass.com/.…
  • @snipeyhead @snipeyhead on x
    FWIW, here's what I told my employees re: the LastPass breach. Feel free to re-use without attribution. Hope it helps. What a mess. https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    Latest #LastPass breach may be worse than you think. Attacker didn't just get encrypted passwords. They got unencrypted URLs. Think: URLs with account tokens, API keys & credentials, etc... 1/ https://blog.lastpass.com/... https://twitter.com/...
  • @astuyve AJ Stuyvenberg on x
    LastPass breach gets worse and worse. First: We were breached but no customer data was accessed Next: Okay some customer data was accessed, but not password vaults. Now: Customer password vaults were copied by the attacker but don't worry, it will be hard to crack your vault. htt…
  • @katebevan Kate Bevan on x
    This is great from @zackwhittaker - it explains what the LastPass breach means to you. If your master password is short/weak/been used elsewhere, change it. Your vault is safe unless your password is weak or compromised. https://techcrunch.com/...
  • @kevincollier Kevin Collier on x
    This is downright scandalous. Significantly more damning than anything in the Twitter files. More overt abuse of access to users' data from a tech company than anything I can think of in recent memory. https://www.ft.com/...
  • @tim_stevens Tim Stevens on x
    Whelp. Sometimes it's hard to know whether to recommend Lastpass or 1password when people ask me about managers. This'll make that a lot easier going forward. https://twitter.com/...
  • @jamesrbuk James Ball on x
    Feels like we need a much more decentralised framework for these - password managers are better than the alternative for most users, but they're *such* honeypots for hackers. https://twitter.com/...
  • @uk_daniel_card @uk_daniel_card on x
    also a few things: 1) it's never nice being ownd 2) our friends work in orgs that get pwn3d. don't be a shitty human 3) the passwords are encrypted, if you have a “good” master password then risk is much much much lower 4) there is always some risk 5) use MFA ... mor2 follow
  • @gcluley Graham Cluley on x
    Unfortunate timing with this latest disclosure. I'm sure LastPass wanted to be as transparent as possible about what occurred, and get the news out there as quickly as possible to users. It's just unfortunate some might not see it due to proximity to Christmas. https://twitter.co…
  • @b1ack0wl @b1ack0wl on x
    Big yikes from LastPass lol https://twitter.com/...
  • @carnage4life @carnage4life on x
    If you use LastPass this is extremely important news. Attackers have access to all your website URLs and encrypted passwords. This was effectively their only job and they failed. This feels somewhat inevitable given how big a prize the LastPass vault is but scary to see happen. h…
  • @gregosuri Greg Osuri on x
    Lastpass was hacked, and customer vaults are with the attacker that can run a brute force attack to reveal your password and secret notes — it's only a matter of time. Change your passwords and renew your secrets ASAP if you've ever used Lastpass. https://twitter.com/...
  • @chrismessina @chrismessina on x
    Merry Christmas you filthy LastPass threat actor https://twitter.com/... https://twitter.com/...
  • @stringstory @stringstory on x
    This is v. bad LastPass. Solution: - add 2FA - use Authenticator - move to new password manager https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    2/ #LastPass has a giant target on their back because of the juicy data & password trove that they handle. And they are absolutely failing their customers. At this point, each time I hear about Last Pass it's: hey, they had *another breach*
  • @jsrailton John Scott-Railton on x
    This #LastPass breach = worse than you think. Attacker didn't just get encrypted passwords. They got unencrypted URLs. Think: URLs with account tokens, API keys & credentials, etc... You or your company a LastPass customer? Change everything. https://blog.lastpass.com/... https:/…
  • @markvdnld Mark Aangenaam on x
    Not only was @LastPass breached - hackers got the binary blobs of all data and even some unencrypted URL data. This is the end of LastPass. How can you recover from this? Your company has been failing on providing proper updates to begin with. Zero trust left. https://twitter.com…
  • @matthew_d_green Matthew Green on x
    People seem to be misunderstanding this: as best I can tell it means that the attackers can now start running dictionary “password guessing” attacks against your master password.
  • @matthew_d_green Matthew Green on x
    Nice announcement, LastPass. https://blog.lastpass.com/... https://twitter.com/...
  • @swiftonsecurity @swiftonsecurity on x
    The fact LastPass doesn't encrypt website URLs is a known flaw it appears they never fixed on purpose, going back almost 6 years https://hackernoon.com/...
  • @cz_binance @cz_binance on x
    LastPass provided an update. The hacker has all the user info including email address and websites URLs unencrypted. If the you reused passwords for the master password or has a weak master password, then it is possible for the hacker to obtain all of his/her credentials.
  • @secresdoge Sebastian Bicchi on x
    This basically means you can offline brute force them (masterpasswords) and as it is done clientside, it is known *how* to do it. Fun. https://twitter.com/...
  • @dystopiabreaker @dystopiabreaker on x
    lastpass has been obviously shit ever since tavis ormandy found a relatively simple “extiltrate all passwords” bug in their chrome extension and they responded poorly to it
  • @swiftonsecurity @swiftonsecurity on x
    tldr LastPass attackers know your name and billing address and all websites you have saved passwords for, and if your master password isn't sufficiently strong may be possible to brute-force open everything on attacker's machines
  • @altcoinpsycho @altcoinpsycho on x
    PSA: Stop using cloud-based password managers. I was called paranoid for ages for bad talking LastPass The safest place to store a password is in your brain https://twitter.com/...
  • @accidentalciso @accidentalciso on x
    Folks that are migrating from LastPass to something else, what are you migrating to and why did you select that vendor? Is there something about that product's architecture that would materially reduce the potential risk that LastPass customers face right now?
  • @championswimmer Arnav Gupta on x
    Despite even many well known infosec researchers actually suggesting users to use password managers, I'll never use one, because exactly this reason. The entropy of generated passwords isn't useful. I can remember high entropy passwords myself. “correct horse battery staple” http…
  • @nixcraft @nixcraft on x
    Regarding lastpass, folks asking me: >>>LastPass just keeps having security incidents why do people still use it? For starters, having something like LastPass for the masses is more convenient. Second, it always depends upon your threat vector.
  • @evacide Eva on x
    Pour one out for all of the security practitioners who are going to have to patiently explain that using a password manager is still good, actually, to people who have glanced at a headline about the latest LastPass breach.
  • @seanwrightsec Sean Wright on x
    The LastPass incident is big news. But not for the reason why folk may think. We have a difficult time convincing folk to use password managers. This is most likely to harm that effort, sowing doubt with those who are a bit hesitant about doing so.
  • @afdudley0 Rick Dudley on x
    Friendly reminder the odds are such that if you use one of these services, they will be significantly compromised while you're using them and thus you shouldn't put anything important in them. https://twitter.com/...
  • @tomwarren Tom Warren on x
    I'm glad I use 1Password and not LastPass because this is 😬 https://www.theverge.com/...
  • @billym2k Shibetoshi Nakamoto on x
    lastpass was hacked 🤣 i think we should just assume that anything we do is public and will be hacked
  • @jsrailton John Scott-Railton on x
    The #LastPass breach (just the latest, btw) is frustrating. Users that didn't follow “best practices” for their master password are vulnerable (customer password vaults were stolen!). But also because we've collectively spent years trying to move users to password managers. 1/
  • @cz_binance @cz_binance on x
    LastPass suffered a breach recently. I recommended this password manager in my blog article before. They claim no impact to customer passwords, as it should be client side encrypted, but best to make sure you have 2FA enabled. https://www.npr.org/...