LastPass confirms data breach after hacker compromises supply chain
LastPass has confirmed a data breach after a hacker compromised its supply chain, gaining access to customer data through a developer's compromised device. The breach involved encrypted vaults, but the company stated that master passwords and customer accounts were not affected. The incident highlights ongoing security vulnerabilities in the password manager's infrastructure.
Background
- LastPass is a popular password manager that stores users' login credentials in a "vault" encrypted with a master password. It has over 30 million users and is owned by GoTo (formerly LogMeIn).
- Supply chain compromise means attackers broke into LastPass's internal systems not directly, but by exploiting a third-party service or vendor that LastPass uses — a common and difficult-to-defend attack vector.
- This is the latest in a series of security incidents. LastPass disclosed a smaller breach in August 2022, and the current incident was initially reported in November 2022 as "anomalous activity," later confirmed as a full breach.
- At stake: whether encrypted user vaults (master passwords, stored passwords, notes) were stolen. Even encrypted, weak master passwords can be cracked offline; if source code or encryption keys were also taken, the risk is severe.
- Password managers are trusted custodians of all a person's online accounts, so a breach erodes core user trust and raises questions about the security model of cloud-based password storage.