LastPass: Security Incident Update and Recommended Actions (1st March 2023)
blog.lastpass.com
blog.lastpass.com
Your corporate vault, with all of your database keys, was stored and accessed from someone's personal computer?
> We assisted the DevOps Engineer with hardening the security of their home network and personal resources.
And even after this incident, you let them keep using a personal computer???
This really just reflects incredibly poorly on LastPass's internal security team. I was under considerably more robust endpoint protection policies as a random intern at a legacy Fortune 500.
Edit: I'm quoting from a separate linked blog post here: https://support.lastpass.com/help/incident-2-additional-deta...
Looks like they were a part of it but even worse the attacker also got the decryption key (yikes!)
"Backup of LastPass MFA/Federation Database – contained copies of LastPass Authenticator seeds, telephone numbers used for the MFA backup option (if enabled), as well as a split knowledge component (the K2 “key”) used for LastPass federation (if enabled). This database was encrypted, but the separately-stored decryption key was included in the secrets stolen by the threat actor during the second incident."
I've since switched to 1password and rotated every (damn) password. That was an entire weekend burned.
How unacceptable.
https://support.lastpass.com/help/security-bulletin-recommen...
A software engineer’s corporate laptop was compromised, allowing the unauthorized threat actor to gain access to a cloud-based development environment and steal source code, technical information, and certain LastPass internal system secrets.
Hello 1password