Wednesday, December 4, 2024
HomeTechnologyLastPass was hacked but the site says that no user data was...

LastPass was hacked but the site says that no user data was compromised

In August LastPassHad admittedAn “unauthorized party” gained access to its system. Although news of a hacker gaining access to password managers can be alarming, the company is now reminding its users that logins and other information were not compromised.

In his Recent updateKarim Toubba, CEO of LastPass, stated that the company’s investigation into cybersecurity firm Mandiant revealed that the bad actor had access to the company’s systems for four days. They were able smuggle some of the password manager’s source code and technical data, but only the service’s development environment was able to access the information. This environment is not connected to customers’ data and encrypted vaults. Toubba also pointed out that LastPass does not have access to the master passwords of users, which is required to decrypt their vaults.

The CEO stated that there was no evidence that the incident “involved any customer data or encrypted password vaults.” The hackers did not inject malicious code into the systems and there was no evidence that they gained unauthorized access after those four days. Toubba explained that the bad guy was able to hack into the service’s systems through the compromise of a developer’s computer. The hacker then impersonated the developer “once the developer had successfully authenticated using multi-factor authentication.” 

LastPass was back in 2015 Suffered a security breachIt compromised user email addresses, password reminders, authentication hashes, as well as other information. A similar breach today would be even more severe, considering that LastPass claims to have over 33 million users. Although LastPass doesn’t ask users to do anything to protect their data, it is a good idea to not reuse passwords and enable multi-factor authentication.

Engadget has chosen all products to recommend. We are not affiliated with our parent company. Affiliate links may be included in some of our stories. Affiliate commissions may be earned if you make a purchase through any of the links. All prices correct as of the date of publication.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular