OneLogin Password Manager Reports Data Breach, Potential Decryption of Customer Data

Advertisement
By Sanket Vijayasarathy | Updated: 2 June 2017 15:44 IST
Highlights
  • OneLogin security officer Alvaro Hoyos reported breach
  • Severity of breach not yet known
  • Malicious actor may have ability to decrypt sensitive data

It's getting harder to avoid the fact that your personal data on the Internet is just not safe any more. Following the recent rise in data breaches that have already hit companies like Yahoo, Dropbox, and Telegram, it now seems OneLogin is the latest to join the list as the company reported Wednesday an "unauthorised access to OneLogin data in our US data region."

OneLogin is a password manager and single sign-on provider, which reported a data breach but has been unclear as to the nature of the attack. The firm's chief security officer Alvaro Hoyos said in a blog post that "a malicious actor had obtained access to our US operating region." The company reportedly found a threat actor had "obtained access to a set of Amazon Web Services (AWS) keys and used them to access the AWS API from an intermediate host with another, smaller service provider in the US."

Advertisement

The severity of the breach to consumers is not yet known but the company has stated that the hack allowed the threat actor to access database tables that contain personal information about users, apps, and various types of keys. While the company maintains that it encrypts certain sensitive data, it didn't rule out the possibility that the 'malicious actor' had the ability to decrypt them.

OneLogin updated the blog post saying that the staff was alerted about the attack at 9am PST (about seven hours after the attack started) and was "able to shut down the affected instance as well as the AWS keys that were used to create it." Although the firm mentioned that it encrypts sensitive information, many were curious about how the attacker was able to then get access to data that could be decrypted.

Advertisement

While the company tries to solve the breach, it has reportedly given its customers a list of actions to protect their accounts according to a tweet posted by @nerdybeard.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. These OnePlus Smartphones Could Receive the ColorOS 17 Update in India
  2. Xiaomi Pad 9 Could Launch Soon After Clearing Key Certification Hurdle
  3. OnePlus N6x Design, Colour Options Teased Ahead of India Launch
  4. Redmi Note 17 Pro Max Listed on NBTC Website Ahead of Imminent Launch
  1. Offline UPI Payments With NFC Support Could Launch in India Soon
  2. Samsung Galaxy S26 Ultra's Privacy Display Feature Gets a Major Upgrade in One UI 9 Beta
  3. OnePlus N6x Design, Colour Options Teased in New Marketing Material Ahead of Imminent Launch in India
  4. OnePlus 11, Nord 4, and Newer Models Tipped to Receive the Android 17-Based ColorOS 17 Update in India
  5. Redmi Note 17 Pro Max Appears on Thailand's NBTC Certification Database, Might Launch Soon
  6. Apple’s First Foldable iPhone Reportedly Appears in iOS 27 Beta Code With a Multi-Battery Setup
  7. X for Android App Undergoes Major Design Overhaul, Enhanced Performance and Reliability
  8. Samsung Galaxy Buds Able to Reportedly Skip Galaxy Unpacked Launch; Could Debut in October
  9. Dell Alienware 16X Aurora, Alienware 16 Area-51 and Alienware 18 Area-51 Launched in India: Price, Specifications
  10. Samsung Galaxy A55, Galaxy A35 One UI 9 Test Builds Reportedly Spotted Ahead of Android 17 Rollout
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.