Thursday, September 11, 2025
  • Login
ANONYMOUSWIRE
  • Home
  • top News
  • Technology
  • Health
  • World Sport
  • adventure
  • Business
  • Entertainment
  • Privacy Policy
  • Website Terms of Use
  • About Us
  • Contact Us
No Result
View All Result
  • Home
  • top News
  • Technology
  • Health
  • World Sport
  • adventure
  • Business
  • Entertainment
  • Privacy Policy
  • Website Terms of Use
  • About Us
  • Contact Us
No Result
View All Result
Anonymous  Wire
No Result
View All Result
Home News

LastPass says hackers broke into an employee PC to steal the company’s password vault

лашо199225 by лашо199225
February 28, 2023
in News
0
LastPass says hackers broke into an employee PC to steal the company’s password vault
0
SHARES
70
VIEWS
Share on FacebookShare on Twitter

LastPass says hackers broke into an employee PC to steal the company’s password vault

vEiW9C

LastPass has posted an update on its investigation regarding a couple of security incidents that took place last year, and they’re sounding graver than previously thought. Apparently, the bad actors involved in those incidents also infiltrated a company DevOps engineer’s home computer by exploiting a third-party media software package. They implanted a keylogger into the software, which they then used to capture the engineer’s master password for an account with access to the LastPass corporate vault. After they got in, they exported the vault’s entries and shared folders that contained decryption keys needed to unlock cloud-based Amazon S3 buckets with customer vault backups.

This latest update in LastPass’ investigation gives us a clearer picture of how the two security breach incidents it went through last year were connected. If you’ll recall, LastPass revealed in August 2022 that an “unauthorized party” gained entry into its system. While the first incident ended on August 12th, the company said in its new announcement that the threat actors were “actively engaged in a new series of reconnaissance, enumeration, and exfiltration activities aligned to the cloud storage environment spanning from August 12th, 2022 to October 26th, 2022.”

When the company announced the second security breach in December, it said the bad actors used information obtained from the first incident to get into its cloud service. It also admitted that the hackers made off with a bunch of sensitive information, including its Amazon S3 buckets. To be able to access the data saved in those buckets, the hackers needed decryption keys saved in “highly restricted set of shared folders in a LastPass password manager vault.” That’s why the bad actors targeted one of the four DevOps engineers who had access to the keys needed to unlock the company’s cloud storage. 

In a support document (PDF) the company released (via BleepingComputer), it detailed the data accessed by the threat actors during the two incidents. Apparently, the cloud-based backups accessed during the second breach included “API secrets, third-party integration secrets, customer metadata and backups of all customer vault data.” The company insisted that all sensitive customer vault data aside from some exceptions “can only be decrypted with a unique encryption key derived from each user’s master password.” The company added that it doesn’t store users’ master passwords. LastPass also detailed the steps it has taken to strengthen its defenses going forward, including revising its threat detection and making “a multi-million-dollar allocation to enhance [its] investment in security across people, processes, and technology.”

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission. All prices are correct at the time of publishing.

Published at Tue, 28 Feb 2023 07:49:48 +0000

Previous Post

FIFA The Best 2023 award winners, voting results: Lionel Messi, Alexia Putellas voted best players

Next Post

How long is LeBron James out? Foot injury timeline, return date, latest updates on Lakers star

лашо199225

лашо199225

Next Post

How long is LeBron James out? Foot injury timeline, return date, latest updates on Lakers star

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • DAPT After CABG Surgery: Why Aspirin Alone May Be Enough
  • U.S. Troop Deployment in Caribbean: Not Training
  • France Faces Political Instability Amid No-Confidence Vote
  • Why Gold Prices Are Surging to Record Highs in 2025
  • Epigenetic DNA Aging Map Reveals Organ-Specific Changes
Advertisement

Get our top stories in your inbox.

No spam. Unsubscribe anytime.

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • October 2022
Advertisement

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About AnonymousWire

Independent news & analysis covering world events, technology, health, culture and more. Fast, factual, and reader-first.

Learn more →

Quick Links

  • Top News
  • Technology
  • Health
  • Adventure
  • Business
  • Games
  • Entertainment

Help & Legal

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA Notice
  • Advertise
  • Cookie Policy

Follow & Subscribe

X (Twitter) · Facebook · YouTube · Telegram

No spam. Unsubscribe any time.
Advertisement
  • Home
  • top News
  • Technology
  • Health
  • World Sport
  • adventure
  • Business
  • Entertainment
  • Privacy Policy
  • Website Terms of Use
  • About Us
  • Contact Us

No Result
View All Result
  • Home
  • top News
  • Technology
  • Health
  • World Sport
  • adventure
  • Business
  • Entertainment
  • Privacy Policy
  • Website Terms of Use
  • About Us
  • Contact Us

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In