infotechlead

LastPass reveals hackers copy backup of customer vault data

Encrypted password manager LastPass has revealed hackers were able to copy a backup of customer vault data in a recent data breach.
IT network security issuesLastPass is a freemium password manager that stores encrypted passwords online.

LastPass in a statement said the hacker was able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.

It means that hacker may attempt to use brute force to guess your master password and decrypt the copies of vault data they took.

Hackers may target customers with phishing attacks, credential stuffing, or other brute force attacks against online accounts associated with “your LastPass vault”.

LastPass recommended its users to never reuse master passwords on other websites.

“If you reuse your master password and that password was ever compromised, a threat actor may use dumps of compromised credentials that are already available on the Internet to attempt to access your account,” LastPass said.

Earlier this month, Karim Toubba, CEO of LastPass, admitted its systems were compromised for the second time this year.

LastPass detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo.

The earlier security breach in August this year allowed hackers internal access to the company’s systems for four days until they were detected and evicted.

Latest

More like this
Related

Aflac probes cybersecurity breach exposing customer data

Aflac reported a cybersecurity incident on June 12, after...

Hackers target gamers with malicious Minecraft modifications

A new cybersecurity threat has emerged in the gaming...

Qatar’s top cybersecurity leaders honored at 2025 IDC Security Roadshow

IDC has recognized 23 outstanding cybersecurity leaders in Qatar...

UBS caught in cybersecurity breach linked to Swiss vendor Chain IQ

Swiss banking giant UBS has confirmed it was impacted...