LastPass hack: Customer data at risk after second attack

VG word pixels

data leak

After the popular password manager LastPass was targeted by hackers in August, the company got caught again – this time customer data is also said to be affected.

News

VG word pixels

CyberVor hackers' password theft is making itself felt.

© Sergey Nivens – Fotolia.com

The data theft from the password manager LastPass that took place in August is spreading: Like CEO Karim Toubba in one blog post reports that data once again fell into the hands of hackers during a “security incident” while on duty. In contrast to the attack of a few months ago, in which the source code of the software was primarily stolen, this time certain categories of user data were captured.

As the company goes on to explain, unusual activities have been identified within a third-party cloud storage service used by the company. Within these, unauthorized persons are said to have gained access to sensitive customer data, but passwords were not stolen. These are securely encrypted due to LastPass’ zero-knowledge architecture.

The incident is currently being investigated and processed internally. What has been clarified, however, is that the recent data leak is linked to the August attack. In addition, LastPass turned on IT security companies to take a closer look at the hack.

Like the online magazine hot reported that the captured data from the company behind LastPass, Bitwarden, is said to have already appeared in relevant forums. These are log files in which sensitive user data can be viewed in plain text. However, Bitwarden immediately denied this: There are “no concerns about a system break-in or a database compromise”.

As the company continues to assure, sensitive information in particular is only stored in encrypted form, which takes place on the local user device before the data is sent to the cloud server. Accordingly, the log file that appeared could not come from the recent hack.

Benchmark test security suites

security

Antivirus test 2023: What is the best virus scanner?

Which antivirus offers the best protection for PC, personal data and privacy in 2023? – We have the test.

1.12.2022 from
Yusuf Hatic

Continue to home page

more on the subject

emotet trojan protection

Malware back

Emotet is infecting computers again

The Emotet malware is back and infecting machines again. After a break, the Trojan is now active again worldwide.

Password manager test 2021

Online Safety

Apple, Google and Microsoft encourage login without a password

Large companies such as Apple, Google and Microsoft want to encourage logins without a password in the future. As an alternative, the extended FIDO standard…

Password manager test 2021

Password manager

LastPass: Face Recognition Authentication and…

The password manager LastPass now also allows passwordless authentication on desktop devices via fingerprint or face recognition.

Windows 10 updates

patch day

Windows 10 update: what does patch KB5019959 bring?

For Patchday, Microsoft has put patch KB5019959 on the download list for Windows 10. This has the following security patches in its luggage.

An exclamation mark on a red background with ones and zeros

Black Friday

Amazon: consumer center warns of phishing attempts

Black Friday 2022 attracts numerous customers to Amazon. The consumer advice center warns: Cyber ​​criminals want sensitive account data with phishing emails…

Reference-www.pc-magazin.de