Password manager LastPass announced Wednesday it had suffered its second data breach in three months.

CEO Karim Toubba said the company recently detected unusual activity within a third-party cloud storage service that is shared by LastPass and affiliate GoTo.

He said an investigation was immediately launched into the incident by security firm Mandiant and that law enforcement had been alerted.

“We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information. Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture,” Toubba said.

CALIFORNIA DOJ RELEASED GUN DATA ACCIDENTALLY, DISPLAYED ‘POOR JUDGMENT’ IN BUNGLED RESPONSE, REVIEW FINDS

In this photo illustration, the logo for online password manager service LastPass is reflected on the internal discs of a hard drive.
(Leon Neal/Getty Images)

LastPass is working to identify what specific information has been accessed and the scope of the incident. 

Products and services remain fully functional, and LastPass said it continues to deploy enhanced security measures and monitoring capabilities across its infrastructure. 

Toubba said further updates would be provided as LastPass learns more details. 

In this photo illustration, a LastPass logo is displayed on a smartphone.

In this photo illustration, a LastPass logo is displayed on a smartphone.
(Mateusz Slodkowski/SOPA Images/LightRocket via Getty Images)

LAWMAKERS CONCERNED ABOUT CHINESE DRONES IN RESTRICTED SPACES AROUND CAPITOL

In August, LastPass said an unauthorized party had gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information.

Following an investigation, Toubba said in September that the threat actor’s activity had been limited to a four-day period and confirmed that there is no evidence this incident involved any access to customer data or encrypted password vaults

CLICK HERE TO GET THE FOX NEWS APP 

“We recognize that security incidents of any sort are unsettling but want to assure you that your personal data and passwords are safe in our care,” he said then.

Source link

You May Also Like

This Week in Apps: The year’s best apps, Twitter rival Hive’s security woes, App Store backlash grows

Welcome back to This Week in Apps, the weekly TechCrunch series that…

Tax prep companies shared private taxpayer data with Google and Meta for years, congressional probe finds | CNN Business

CNN  —  Some of America’s largest tax-prep companies have spent years sharing…

A Breach at LastPass Has Password Lessons for Us All

While many of us were unplugging from the internet to spend time…

WhatsApp suffers major outage | CNN Business

Hong Kong CNN Business  —  WhatsApp suffered a serious outage on Tuesday,…