Second LastPass Breach Exposes Customer Data Tied to Shared Cloud Storage

Password manager LastPass reveals that a second cyberattack exposes customer information after hackers use data stolen during an August incident. The breach impacts both LastPass and its parent company GoTo due to their shared cloud storage environment.

Password manager LastPass confirms that a second cyberattack exposes customer information after hackers leverage data stolen during an August incident. The initial breach compromises an employee's work account to access the development environment, but the subsequent November attack proves much more severe. The intruder uses the previously obtained information to access a third-party cloud storage service containing sensitive customer data for both LastPass and its parent company GoTo.

The severity of this incident stems from the fact that LastPass and GoTo share the same cloud storage infrastructure, likely Amazon Web Services. Storing data from different products on a single cloud service requires strict access controls and data segmentation to prevent a single set of stolen credentials from compromising an entire database. TechCrunch notes that LastPass fails to name the cloud provider or adequately explain why the hackers successfully bypass these expected security boundaries.

Both LastPass CEO Karim Toubba and GoTo CEO Paddy Srinivasan provide vague statements regarding the ongoing investigation, leaving customers in the dark about the exact scope of the compromised information. GoTo explicitly declines to comment on whether its customers face direct risks, mirroring the lack of transparency often seen in corporate breach disclosures. Security analysts annotate the official breach notice to highlight crucial missing details about the attack timeline and the specific failures of the company's cloud security architecture.

Read More at the original source →