LastPass Says Hackers Stole Customer Data, Encrypted Passwords in Breach That Occured in August

In August, LastPass said it had seen no evidence that hackers had access to customer data or encrypted password vaults.

Advertisement
By William Turton, Bloomberg | Updated: 23 December 2022 10:30 IST
Highlights
  • LastPass said that the initial breach had happened in August
  • It does not store the master password created by users
  • LastPass has hired cybersecurity firm Mandiant to investigate the breach

Hackers were able to copy email addresses, IP addresses from which customers accessed LastPass

Photo Credit: LastPass

LastPass, a password management service, announced on Thursday that hackers stole encrypted copies of customer passwords and other sensitive data such as billing addresses, phone numbers and IP addresses. The announcement is the latest update from a breach that occurred in August. At that time, the company said they had seen no evidence that the hackers had access to customer data or encrypted password vaults.

But the company's statement on Thursday said that source code and technical information that were stolen as part of that hack was used to target another employee. The hackers were then able to obtain credentials and keys to access and decrypt data stored on a third-party cloud storage space.

Advertisement

They were able to copy such things as basic customer account information, including email addresses and the IP addresses from which customers accessed LastPass, and “fully-encrypted sensitive fields such as website usernames and passwords, secure notes and form-filled data.”

Password managers are a way for customers to store usernames and passwords in one place and can be accessed using a master password that a customer creates. The master password isn't known to LastPass nor is stored or maintained by the company, it said in its statement.

Advertisement

The other encrypted data can only be decrypted “with a unique encryption key derived from each user's master password,” the company said.

Nonetheless, LastPass warned customers that they could be targeted for social engineering, phishing attempts or other methods.

Advertisement

“The threat actor may attempt to use brute force to guess your master password and decrypt the copies of vault data they took,” the company said in a statement. “Because of the hashing and encryption methods we use to protect our customers, it would be extremely difficult to attempt to brute force guess master passwords for those customers who follow our password best practices.”

For those who follow LastPass's password guidance, “it would take millions of years to guess your master password using generally available password-cracking technology,” the company said.

Advertisement

A representative for LastPass didn't respond to messages seeking comment.

The company said that it has hired the cybersecurity firm Mandiant to investigate the breach. It also said that it is rebuilding its entire development environment from scratch, an indication that hackers had thoroughly comprised the company's sensitive systems.

LastPass said that its investigation is ongoing, and that it has notified law enforcement and “relevant regulatory authorities.”

© 2022 Bloomberg L.P.


Where did Realme go wrong with the 10 Pro+ 5G? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: LastPass, LastPass Hack, cyberattack
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases This Week: Cocktail 2, Bharat Bhhagya Viddhaata, and More
  2. iQOO Neo 11 Ultra Will Launch With This Custom MediaTek SoC
  3. Google Pixel 11 Pro Fold vs Pixel 10 Pro Fold: What's The Difference
  4. Realme 16x 5G Goes on Sale in India With These Offers
  5. Vivo's New S50t Vitality Edition Packs a Snapdragon 8s Gen 3 Chipset
  6. Moto G Max Debuts in India With 120Hz Display, 7,000mAh Batter
  7. Xiaomi Unveils HyperOS 4 With New Glass UI, AI Features, Faster App Loading
  8. This Could Help Apple Reduce Its iPhone 18 Pro Series Manufacturing Costs
  9. Love Photography? These Are the Best Camera Phones Under Rs. 40,000 Right Now
  10. Samsung Galaxy S26 FE, Galaxy Tab S12+ and Galaxy A07s Spotted on Google Play Console
  1. Netflix Is Shutting Down Two Game Studios, Including Oxenfree and Unhinged Maker Night School Studio
  2. Moto G Max Launched in India With Snapdragon 6s Gen 4 Chip, 7,000mAh Battery: Price, Specifications
  3. Apple Seeks Publisher Partnerships to Strengthen Siri’s AI Capabilities: Report
  4. Microsoft Merges Copilot and Microsoft 365 Copilot Into One App, Retires Several AI-Powered Tools
  5. Securitize Share Drops 20 Percent as Tokenisation Revenue Falls Short of Expectations
  6. Apple’s iPhone Ultra to Reportedly Be US-Only at Launch Due to Supply Issues, Pricing Challenges
  7. Xiaomi Unveils HyperOS 4 With Liquid Glass-Inspired UI, Super AI Assistant 2.0: Eligible Devices, New Features
  8. Samsung Galaxy S26 FE, Galaxy Tab S12+ and Galaxy A07s Spotted on Google Play Console
  9. Vivo X500 Pro Max Reportedly Bags 3C Certification, Charging Speed Revealed
  10. CD Projekt Red Confirms Layoffs at Project Sirius Witcher Multiplayer Spinoff
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.