A major password management company with more than 33 million users — LastPass — this week confirmed its second breach within four months. In August, the company discovered that a threat actor gained access to its development environment; and this time, it detected unusual activity within a third-party cloud storage service, possibly the same unauthorized party using information obtained from the last incident.
Unlike the August breach, LastPass CEO Karim Toubba noted in a notice that the threat actor was able to gain access to “certain elements” of its customers’ information. “We are working diligently to understand the scope of the incident and identify what specific information has been accessed.”
But Toubba emphasized that customers’ passwords remained encrypted and their master password didn’t get compromised.
The company claims it’s benefited from the industry-standard zero-knowledge architecture which ensures managers like LastPass can never know or gain access to customers’ master password.
At this time, LastPass doesn't recommend any action for users but continues to follow the company’s best practices around setup and configuration, according to Toubba.
Security experts suggest LastPass users enable multi-factor authentication (MFA) for their password management accounts and also other accounts stored in LastPass. “This extra layer of security can be vital when breaches occur,” Tanium VP Chris Vaughan said.
LastPass’ Breach in AugustLastPass announced on August 25 that it had detected unusual activity and completed the investigation and forensics process partnering with Mandiant in mid-September.
The threat actor potentially bypassed LastPass’s MFA and gained initial access. “Our investigation determined that the threat actor gained access to the Development environment using a developer’s compromised endpoint. While the method used for the initial endpoint compromise is inconclusive, the threat actor utilized their persistent access to impersonate the developer once the developer had successfully authenticated using multi-factor authentication,” according to an earlier post from Toubba.
The activity was during a four-day period in August however LastPass contained the incident. “We can also confirm that there is no evidence that this incident involved any access to customer data or encrypted password vaults,” the company claims.
After the incident, LastPass enhanced its security control and monitoring and deployed additional threat intelligence capabilities. The company said it committed to continuing that effort after the latest breach.
LastPass also said its services remained fully functional, and it alerted law enforcement while working with security vendor Mandiant again for investigation.
Comments