Lastpass Says Hackers Accessed Customer Data In New Breach
Data breaches occur on a regular basis and often lead to data leakage. Criminals can use the leaked data to do things like access corporate accounts or steal user details. In recent news, LastPass has announced that their cloud servers have been attacked and a breach occurred. This means attackers might have accessed user accounts. We look closely at the breach and what you should do in this post.

What Is LastPass?
LastPass is a password management platform that focuses on making it easier for users to sign into their accounts. The platform is available as both personal and corporate versions, and is used by a significant number of individuals. LastPass often did research to help companies find possible internal threats. The recent annual report from LastPass shows that employees use the same password for work accounts. They do this about 13 times.ย Only slightly more than 50% of companies are utilising multi-factor authentication.
Security Breach At LastPass
On November 30, 2022, LastPass announced on Twitter that they found unusual activity in their cloud storage service. The cloud storage service affected was a third-party one that they shared with GoTo, an affiliate of LastPass.
This was not the first or only security breach that LastPass experienced in 2022. Just three months prior to this particular incident, the company also announced a breach in their development environment. In August, a developer account was compromised, which gave hackers access to the backend development area of LastPass. The goal of the attack was to steal the source code that was used for the development of the application.
The latest attack did not hit the development environment. Instead, it targeted the cloud storage system the company uses to keep data safe.
While the breach did occur, LastPass notified users and customers that no passwords or user data were leaked during the breach. This is due to the fact that LastPass uses the Zero Knowledge architecture in encrypting the data that users store. This type of technology is tough to crack, which keeps passwords stored on user accounts secure during a data breach.
Even though user passwords were not leaked during the breach, customers are concerned with two breaches announced in just three months.
Keeping Your Data Protected
As data breaches happen in companies we trust, it is important to know what consumers and business owners can do. Keeping your data safe is crucial. There are a couple of steps that you can use to add extra protection to the LastPass account that you use. These practices should not only apply to your LastPass account, but also to other profiles that you have.
The password you use is one of the most important factors. Research shows that emotions, pet names, partner names, food, and colours represent some of the most commonly hacked password types. It is important to avoid common phrases when creating a password. Hackers can easily break through security with these passwords. Some apps, including password managers, offer a way to generate a more secure password.
This type of password will usually consist of numbers, letters, and symbols. The combination of these three with no obvious words in the password helps to enhance its overall efficacy. Hackers have a harder time decoding a password that uses this combination.
Activating multi-factor authentication is also another important step that people need to take. Two-step authentication lets you use your username and password to sign into your account. However, it needs one more step before you can access your profile.ย This step may involve a code sent to your email. You might also need to open a notification on your phone to approve access to your profile.
The mix of these two elements can make it harder for hackers to break in. This is important if they access a network like LastPassโs cloud servers. In these events, you have a double layer of protection that protects your stored content in your account against data breaches and hackers.
Conclusion
A new breach was detected in the cloud storage service that LastPass uses to store customer passwords. The breach did not expose user data. However, it is still a concern for people who use the app. Businesses need to ensure their data is kept secure to avoid breaches and compromises. Strong passwords can help reduce the risk of data leaks and encryption technology that uses secrets and tokens.
References
- https://www.lastpass.com/state-of-the-password/global-password-security-report-2019
- https://www.bleepingcomputer.com/news/security/lastpass-developer-systems-hacked-to-steal-source-code/
Written by The Original PC Doctor on 14/1/2023.




























































