LastPass’ password manager is hacked for the second time this year

If passwords give you a hard time and you’re thinking about getting something like LastPass to remember them, you might want to think again. The password manager admitted Wednesday that an unauthorized party was able to “access certain elements” of its “customer information.”

This isn’t even the first time LastPass has encountered an incident like this. Last August, the company admitted that hackers gained access to some of its source code through a compromised developer account. According to the company, the hackers not only the source code but also “some technical information proprietary to LastPass”. However, the company said at the time that they had no reason to believe that hackers managed to gain access to customer data.

So far and the official blog post of the latest incident indicated that information stolen from the previous hack helped the hackers to breach a second time. “We recently detected unusual activity within a third-party cloud storage service, currently shared by both LastPass and its subsidiary, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security company, and alerted law enforcement,” the blog post says.

However, LastPass has not yet disclosed what specific information was accessed in the breach. The company says it is “working diligently to understand the scope of the incident.” But it ensured that customers’ stored passwords remain securely encrypted due to the Zero Knowledge architecture.

Zero Knowledge architecture helps LastPass maintain an extra layer of security. The company does not have access to customers’ master passwords, which means that only users can decrypt the passwords they store. Still, it would make sense to at least change the master password, just to be safe, since there’s no telling what hackers might have had access to.

Leave a Comment

Your email address will not be published. Required fields are marked *