LastPass Confirms Cybercriminals Steal Encrypted Customer Password Vaults

Hackers steal encrypted password vaults and customer personal data from LastPass by exploiting a compromised employee's cloud storage key. The company warns that attackers may attempt brute-force attacks to guess users' master passwords.

Password manager LastPass confirms that cybercriminals steal customers' encrypted password vaults in a recent data breach. The intruders access this sensitive data by using cloud storage keys stolen from a single LastPass employee to grab a backup of customer vault data. These vaults contain both unencrypted data, such as website addresses, and encrypted secrets, though the exact age of the stolen backups remains unclear.

The company states that the stolen vaults remain encrypted and require the customer's master password to unlock, but warns that attackers may attempt brute-force attacks to guess these passwords. Along with the vault data, the hackers take vast amounts of customer personal information, including names, email addresses, phone numbers, and billing details. This incident highlights that even heavily secured password managers are vulnerable to sophisticated attacks.

Security experts advise all LastPass users to immediately change their master password to a strong, unique passphrase that is not used anywhere else. If a user suspects their master password is weak or reused on other sites, they should quickly update the passwords stored inside their vault, starting with the most critical accounts. A compromised password vault is ultimately only as strong as the master password that protects it.

Read More at the original source →