Luckily, the vaults are encrypted with a Master Password, which should prevent the attacker from being able to read them. These vaults contain the website passwords that each user stores with the LastPass service. In addition, some customers’ encrypted vaults were stolen. However, the company has investigated and discovered that the attacker used this technical information to attack another employee’s device, which was then used to obtain keys to customer data stored in a cloud storage system.Īs a result, unencrypted customer metadata has been revealed to the attacker, including “company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service.” LastPass first disclosed the breach in August 2022 but at that time, it appeared that the attacker had only obtained source code and technical information, not any customer data. Notice of Recent Security Incident - The LastPass Blog #lastpasshack #hack #lastpass #infosec - Thomas Zickell December 23, 2022 This means that the attacker may be able to crack some website passwords of LastPass users through brute force guessing. Password management service LastPass was hacked in August 2022, and the attacker stole users’ encrypted passwords, according to a Dec.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |