lastpass-breach-feature-image

Another Data Breach At LastPass

LastPass had another data breach! LastPass disclosed that attackers gained access to customer information through a compromise of a third-party vendor called Klue, a market-intelligence platform integrated with LastPass’s Salesforce environment. Attackers reportedly stole OAuth tokens from Klue and used them to access LastPass customer data.

What Data Was Exposed?

According to LastPass, the exposed information may include:

  • Customer names
  • Email addresses
  • Phone numbers
  • Postal addresses
  • Customer support case information and related records

The company says customer password vaults, master passwords, and stored credentials were not affected in this incident.

Why Is It Important?

Even though vault contents were not reportedly accessed, stolen contact and support case data can be valuable for phishing and social engineering attacks. Attackers may impersonate LastPass support or send convincing emails designed to trick users into revealing credentials or MFA codes.

LastPass Has A Long History Of Incidents

2011 Security Incident

On May 3, 2011, LastPass discovered an anomaly in its incoming and outgoing traffic networks. Data such as email addresses, the server salt, and the salted password hashes were copied from the LastPass database. LastPass rebuilt the servers and requested all users to change their master passwords.

2015 Security Breach

On June 15, 2015, LastPass account email addresses, password reminders, server-per-user salts, and authentication hashes were compromised; however, encrypted user vault data was not affected.

2016 Security Incident

In July 2016, due to poorly written URL parsing code in the LastPass extension, a method was found for reading plain text passwords for arbitrary domains from a LastPass user’s vault when that user visited a malicious website. LastPass was notified privately and fixed its browser extension.

2017 Security Incidents

On March 20, 2017, a vulnerability in the LastPass Chrome extension was discovered. The exploit applies to all LastPass clients, including Chrome, Firefox, and Edge. These vulnerabilities were patched.

On March 25, an additional security flaw was discovered, allowing remote code execution based on the user navigating to a malicious website. This vulnerability was also patched.

2019 Security Incident

On August 30, 2019, a vulnerability was found in the LastPass browser extension where websites with malicious JavaScript code could obtain a username and password inserted by the password manager on the previously visited site. By September, LastPass publicly announced the vulnerability, acknowledged the issue, and patched all platforms.

2021 Third-Party Trackers And Security Incident

In 2021, it was discovered that the LastPass Android app contained third-party trackers. Also, at the end of 2021, an article in Bleeping Computer reported that LastPass users were warned that their master passwords were compromised.

2022 Data Breach

Two related security incidents were disclosed by the password manager LastPass in 2022. In the first incident, an attacker accessed parts of LastPass’s development environment and exfiltrated source code repositories and technical documentation, including an encrypted copy of the key used to protect backups of customer data. I wrote about them here and here.

In a second incident, a senior DevOps engineer’s personal computer was compromised, and the attacker used a keystroke logger to obtain the employee’s credentials and access an internal vault holding further keys. Jim Hillier wrote about this

Bottom Line

LastPass has a long history of security incidents. The newest LastPass incident appears to be a supply-chain breach involving a third-party vendor that exposed customer contact and support data, but not users’ password vaults or master passwords. Concerned LastPass customers may want to consider an alternative password manager.

Even though recent changes at Bitwarden are concerning, it is still a solid value-oriented password manager. Two good cloud-based password managers are Bitwarden and 1Password. I have used 1Password in the past, and I currently have a premium Bitwarden subscription. Jim Hillier recommends Bitwarden’s free version if you do not need the premium features. 

15 thoughts on “Another Data Breach At LastPass”

  1. I left them back in the dust the last time this happened. So happy with Bitwarden. I just could not get any support from them. Good riddance.

    1. Hi Harry,
      Yes, for a security software company, they have a extremely poor security history. I wouldn’t trust my most sensitive data with their history!

  2. At this point with all their breaches all one can do is laugh . It is blatantly obvious they do not take their users security seriously. I am actually surprised people still use it let alone pay for it, even more surprised the company hasn’t tanked yet.

      1. Hey John,
        I really cannot see how anyone or any business with any common sense would even use it. They have had so many breaches it is not even funny anymore. I’d like to be a fly on the wall in meetings with their business users to hear what line of crap they are feeding them to keep them on the chain.
        I myself gave it a test drive a very long time ago for a short period of time , luckily I never went with it, but even IF I did , after the second breach I would have dumped it like a hot potato.

  3. Terry Hollett

    You can’t trust them to protect your data when they can’t even protect their own. I use the free Bitwarden version.

    1. Hey Terry,

      Bitwarden is not perfect either. They recently had a breach of a supply-chain attack against their npm distribution of the Bitwarden CLI. However, they only had a 93 minute incident between injection of the infected npm and remedy. No customer data was affected.

      It took 10 days for LastPass to even disclose their breach, who knows how long the breach existed in their system before they discovered it. Not to mention their LONG history of breaches. They do not appear to take security seriously!

      Plus, Bitwarden software is open-source vs LastPass’s closed-source.

    1. Hey Mindblower,
      From a security perspective, a dedicated password manager (DPM) is generally safer. It typically uses a zero-knowledge architecture, encrypts your vault with a separate master password, offers stronger security features, and reduces reliance on your browser account. Also, DPMs work across browsers/devices.
      Still, browser password management is better than using the same password everywhere.

      1. I hear you John. Firefox adds an extra layer of security by allowing users to use a Primary Password. So even if someone gains access to my device, they won’t be able to view or use my stored passwords without entering your Primary Password. They claim this ensures most sensitive information—such as banking and email credentials—remains protected from unauthorized access.
        Hopefully this makes a difference, Mindblower!

        1. Hey Mindblower,

          Firefox passwords are stored in logins.json and protected by keys in key4.db using AES-256 encryption, and the encryption key is derived from the Primary Password, which is less robust than third-party managers. If your using synced data, it uses end-to-end encryption via a key derived from your Firefox account password. But Mozilla stores a backup of this key to allow account recovery, which theoretically reduces the “zero-knowledge” security compared to managers like Bitwarden. The manager is technically vulnerable to malware that can scrape profile files or capture keystrokes, and its key derivation (PBKDF2) iterations is lower standard than Argon2 say, potentially making offline brute-force attacks easier if the profile is stolen.

          Still, the Firefox Password Manager is reasonably secure for everyday use when paired with a strong Primary Password. Although not as secure as a password manager like Bitwarden.

  4. Thanks, John. Have Kaspersky Password Manager as part of my security package. Am cautious not to entrust too much to one package. There are mixed reviews, and some are more politically based. Can you share your thoughts on this password manager, Mindblower!

    1. Hey Mindblower,

      The following countries have banned or restricted Kasperssky as unsafe : Australia, Canada, Germany, Italy, Lithuania, Netherlands, Romania, United Kingdom, and United States

      Why take the chance when there are so many other options.

      1. John. I am aware certain countries banned Kaspersky software. In Canada, private individuals can continue to use it.
        I am one of those world wide users who trust Kaspersky software. Appreciate your comments, Mindblower!

        1. Hey Mindblower,
          If you trust it, use it. Just be aware that if you travel internationally, because of its ties to FBS, having Kaspersky on a laptop could trigger intensive security questioning or device confiscation at customs. Probably should remove it from your deveice before travelling.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top