Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Eugene

(61,819 posts)
Sat Dec 24, 2022, 11:16 PM Dec 2022

LastPass says hackers stole customers' password vaults

Statement from LastPass: Notice of Recent Security Incident

______________________________________________________________________

Source: TechCrunch

LastPass says hackers stole customers’ password vaults

It's time to start changing your passwords

Zack Whittaker@zackwhittaker / 4:46 PM EST•December 22, 2022

Password manager giant LastPass has confirmed that cybercriminals stole its customers’ encrypted password vaults, which store its customers’ passwords and other secrets, in a data breach earlier this year.

In an updated blog post on its disclosure, LastPass CEO Karim Toubba said the intruders took a copy of a backup of customer vault data by using cloud storage keys stolen from a LastPass employee. The cache of customer password vaults is stored in a “proprietary binary format” that contains both unencrypted and encrypted vault data, but technical and security details of this proprietary format weren’t specified. The unencrypted data includes vault-stored web addresses. It’s not clear how recent the stolen backups are.

LastPass said customers’ password vaults are encrypted and can only be unlocked with the customers’ master password, which is only known to the customer. But the company warned that the cybercriminals behind the intrusion “may attempt to use brute force to guess your master password and decrypt the copies of vault data they took.”

Toubba said that the cybercriminals also took vast reams of customer data, including names, email addresses, phone numbers and some billing information.

-snip-

Read more: https://techcrunch.com/2022/12/22/lastpass-customer-password-vaults-stolen/

______________________________________________________________________

Related: Hackers stole encrypted LastPass password vaults, and we’re just now hearing about it (The Verge)

2 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
LastPass says hackers stole customers' password vaults (Original Post) Eugene Dec 2022 OP
JFC, just when I *finally* capitulated and went with a pw manager intrepidity Dec 2022 #1
I figured something like this would happen sooner or later. Susan Calvin Dec 2022 #2

Susan Calvin

(1,646 posts)
2. I figured something like this would happen sooner or later.
Mon Dec 26, 2022, 11:29 AM
Dec 2022

This is why I keep all my passwords in one place. My head.

Latest Discussions»Help & Search»Computer Help and Support»LastPass says hackers sto...