Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

LastPass notifies users of yet another data breach

LastPass has notified users of another data breach, exposing encrypted vault data including URLs, usernames, and passwords. The company states that master passwords were not compromised, but advises users to remain vigilant against potential phishing attacks and to update their credentials.

Background

- LastPass is a popular password manager that stores users' login credentials (usernames, passwords) in an encrypted "vault," accessed via a single master password. It has been owned by the American company GoTo (formerly LogMeIn) since 2015. - This article reports another data breach at LastPass — the company has disclosed multiple security incidents since 2022, including a major 2022 breach where source code and customer vault data were stolen. - Password managers are a prime target for hackers because they hold the keys to all of a user's online accounts. Breaches at such services raise serious concerns about whether the provider can be trusted with sensitive data. - The repeated breaches have eroded user trust, prompting many to migrate to rival services like 1Password, Bitwarden, or Apple's iCloud Keychain. LastPass has also faced criticism over its communication and response to these incidents.