LastPass hacked for the second time this year, customer data stolen by hacker

asset_upload_file39648_234597.png

If you use LastPass as a secure password-managing service, things might not be as secure as you think. Earlier this year in August, the password keeper disclosed that it had been breached, with an unknown hacker having gained access to LastPass' source code and proprietary data. At the time, the company stressed that despite this, customers were unaffected by the hack, and that their data was safe. Now, for the second time this year, LastPass is having to announce that they have been hacked for a second time this year, and that in this incident, customer data has indeed been accessed and stolen.

According to an internal investigation, that same hacker used the data (cloud storage access and dual storage container decryption keys from August in order to get ahold of a backup of LastPass customer data. This means that the individual was able to access billing addresses, telephone numbers, IP addresses, and email addresses saved to users' accounts. That isn't the end of the breach, though, because the hacker also copied a backup of vault data, which contains the most sensitive info; usernames, passwords, and saved form-field data. LastPass claims that no credit card data was accessed, as the service does not store complete credit card numbers and information.

While the information like email addresses and telephone numbers were not encrypted, the password vaults were, with a 256-bit AES encryption, requiring a special key in the form of a user's master password to access. So despite having this information, LastPass claims that this would make it incredibly difficult for the hacker to actually obtain the data from the customer vault. That being said, there is the potential for someone to either brute force the master password, or eventually decrypt the data.

The threat actor may also target customers with phishing attacks, credential stuffing, or other brute force attacks against online accounts associated with your LastPass vault. In order to protect yourself against social engineering or phishing attacks, it is important to know that LastPass will never call, email, or text you and ask you to click on a link to verify your personal information. Other than when signing into your vault from a LastPass client, LastPass will never ask you for your master password.

With all this in mind, LastPass says that there isn't a need to take action at this time, unless your master password was not as secure as recommended. This is just the latest in a string of numerous hacks that the password managing service has suffered over the past few years, with incidents taking place in 2015, 2017, and 2019, all resulting in customer data being accessed by hackers.

:arrow: Source
 

Kioku

僕は階段を嫌い!!
Member
Joined
Jun 24, 2007
Messages
11,617
Trophies
2
Location
In the Murderbox!
Website
www.twitch.tv
XP
14,828
Country
United States
Unhackable means that there is no place from which they can be hacked.
Post automatically merged:

Other options are stateless passwords, dynamical passwords, generated on demand passwords.
I'd rather have a physical security key than the last two password options...
 

I_g_o_r

New Member
Newbie
Joined
Jan 10, 2023
Messages
3
Trophies
0
Age
48
XP
12
Country
Canada
I'd rather have a physical security key than the last two password options...
physical security keys can be broken, stolen, damaged, confiscated, etc.

Some of them rely on encryption.
Researchers claim that they can break encryption with 372 qubits quantum computer
IBM has 433 qubits quantum computer
In 2023 IBM will have 1000 qubits quantum computer and promises 4000 qubits quantum computer in 2025.
 

Kioku

僕は階段を嫌い!!
Member
Joined
Jun 24, 2007
Messages
11,617
Trophies
2
Location
In the Murderbox!
Website
www.twitch.tv
XP
14,828
Country
United States
physical security keys can be broken, stolen, damaged, confiscated, etc.

Some of them rely on encryption.
Researchers claim that they can break encryption with 372 qubits quantum computer
IBM has 433 qubits quantum computer
In 2023 IBM will have 1000 qubits quantum computer and promises 4000 qubits quantum computer in 2025.
Nothing is "unhackable".. That's kind of the point, ain't it?

Also, what generates "on demand" passwords if not a physical device? Can that not be stolen? There are holes in virtually every security "solution"... Most 2FA can be circumvented just by taking someone's phone...
 
Last edited by Kioku,
General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    Hope they made lots of spaget
  • K3N1 @ K3N1:
    Chill dog
  • SylverReZ @ SylverReZ:
    Chilli dog
  • Skelletonike @ Skelletonike:
    Damn, I'm loving the new zelda.
  • xtremegamer @ xtremegamer:
    loving the new zelda, i started a game, it was so fucking good, so i
    am waiting on my friend to get home so we can start a new one together
  • Skelletonike @ Skelletonike:
    I just dislike that they don't let me choose the voices before the game starts. Happened with botw as well, had to change to japanese and restart.
  • K3N1 @ K3N1:
    But the important question is can you choose gender
  • Skelletonike @ Skelletonike:
    Same way you can choose Gerald's gender.
  • Skelletonike @ Skelletonike:
    *Geralt, damn autocorrect.
  • Psionic Roshambo @ Psionic Roshambo:
    But can he be trans? Lol
  • K3N1 @ K3N1:
    Zelda transforms into link
  • Psionic Roshambo @ Psionic Roshambo:
    Link I'm not the princess your looking for.... *Pulls a crying game*
  • K3N1 @ K3N1:
    *skirt up* it's exactly what I always wanted
  • Skelletonike @ Skelletonike:
    Just scanned all my zelda amiibos, took a while but didn't get anything that cool, did get the lon lon ranch hylian fabrics though.
  • Skelletonike @ Skelletonike:
    It was pretty funny when I scanned wolf link and got a shit load of meat.
  • K3N1 @ K3N1:
    @Skelletonike, btw I ran that custom for mgs4 on the deck I'm amazed it got that far in game
  • K3N1 @ K3N1:
    Plug in*
  • K3N1 @ K3N1:
    Your favorite activity
  • BentlyMods @ BentlyMods:
    My fav actvity is:

    mario-dancing.gif
  • Psionic Roshambo @ Psionic Roshambo:
    Do the Mario lol
  • K3N1 @ K3N1:
    🍑
    K3N1 @ K3N1: 🍑