The LastPass Data Breach (Event Timeline And Key Lessons) | UpGuard
ID: a9222012-62f1-5758-98ea-4666a0f031ee
STIX ID: report--a9222012-62f1-5758-98ea-4666a0f031ee
Feed Name: UpGuard Blog
Between August 2022 and March 2023 LastPass suffered multiple incidents: an initial unauthorized access to development resources, attackers later using that information to access third-party cloud backup storage which contained customer vault backups (with unencrypted metadata), and a separate compromise of a DevOps engineer’s home computer that allowed keylogger malware to capture a master password and access decryption keys — the report details affected data categories and recommends network segmentation, transparency, stronger password policies, and tighter remote device controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
