Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Security News This Week: LastPass Users Had Their Data Stolen–Again

A security incident at LastPass resulted in another data breach affecting its users. The breach involved unauthorized access to user data, marking a recurring issue for the password management service. The article details the ongoing security concerns for LastPass customers.

Background

LastPass is a popular password manager that stores users' login credentials in an encrypted "vault." In 2022, it suffered a major breach where attackers stole encrypted vault data. This article reports that the same attackers—likely a known ransomware group—used information from that 2022 breach to launch a new wave of targeted attacks, specifically phishing LastPass users with the goal of stealing their master passwords. Once a master password is compromised, the attacker can decrypt the user's entire vault, gaining access to every account stored inside. The story underscores the particular danger of a password manager being compromised: because it holds the keys to everything else, a breach can have cascading consequences. LastPass has faced ongoing criticism over its security practices and communication with users since the original incident.