LastPass Updates Data Breach Advisory with New Details
ID: 080df401-f419-50db-a532-04dcaf9f322e
STIX ID: report--080df401-f419-50db-a532-04dcaf9f322e
Feed Name: Arctic Wolf Blog
LastPass updated its incident disclosure on Feb 27, 2023, reporting that a threat actor used information stolen in an earlier (Aug 2022) breach to target a senior DevOps engineer with malware, access their corporate vault, and pivot into production backups. The actor accessed backups containing unencrypted metadata (e.g., site URLs) and encrypted customer vaults, and also exfiltrated LastPass Authenticator seeds, MFA backup phone numbers, and the K2 federated key/decryption material; Arctic Wolf recommends federated customers rotate K1/K2, consider restricting authentication to enterprise-managed devices, and follow LastPass administrator guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
