- Customer Names
- Company Names
- Email Address
- Billing Address
- Telephone Numbers
- IP addresses (from where customers accessed the service)
- Website URLs saved in LastPass vaults (LastPass doesn't encrypt the website URLs)
- Encrypted vaults
That is a massive privacy violation and a puts every customer at risk for massive automated phishing, blackmail, and doxing. They marketed the whole vault as being encrypted in their Zero Knowledge architecture(TM).
And LastPass probably knew since AUGUST and tells us the day before Christmas. Note to obfuscating, dense language in the blog notice. Specifically "unencrypted fields such as website URLs", implying other vault fields could have been unencrypted but they can't/won't say.
LastPass will not survive the pending customer exodus and class action lawsuits.
Seems like instead of spending Christmas with my family, I will spend it changing passwords for 100s of accounts.