LastPass Suffers Second Breach as Hackers Exploit Earlier Stolen Data
Password manager LastPass reveals a second security breach where hackers use data stolen in August to access customer information in a shared cloud environment. The company insists that user passwords remain safely encrypted.
Password manager LastPass investigates a second security incident this year after an unauthorized party gains access to customer information. Chief executive Karim Toubba reveals that hackers use information stolen during an August breach to infiltrate a third-party cloud service shared by LastPass and its parent company GoTo, formerly known as LogMeIn.
The company does not name the specific cloud provider, though historical records point to Amazon Web Services, and it remains unclear exactly what customer data is compromised. LastPass states that it works to understand the scope of the incident, while GoTo issues a similarly vague statement confirming its own investigation into the matter.
Despite this secondary intrusion, Toubba reassures users that the system design prevents the threat actor from accessing encrypted password vaults. Customers' passwords remain safely encrypted, but the repeated security failures raise ongoing concerns about the overall safety of data stored within the platform.