Last month, LastPass admitted that an unauthorized party was able to break into the system and had access to sensitive information for about four days. LastPass’s CEO said the company worked closely with Mandiant’s security experts and the investigation revealed that no user data was compromised.

LastPass was hacked but no user data leaked, the CEO assures

The attacker, however, was able to access the LastPass password manager source code and technical information. Access was limited to the service development environment which has nothing to do with user data. Not to mention LastPass itself does not have access to users’ master passwords, which in turn are required to decrypt the data.

The investigation suggests that the attacker used a developer’s endpoint and impersonated the developer after successfully authenticating using multi-factor authentication.

Let's talk about "LastPass was hacked but no user data leaked, the CEO assures" with our community!
Start a new Thread

Philip Owell

Professional blogger, here to bring you new and interesting content every time you visit our blog.