LastPass is one of the biggest password management companies in the world, used by over 33 million people and 100,000 businesses.
LastPass was recently breached, resulting in an exposure of the company’s sensitive data. The company released a security advisory last week confirming that it was compromised via a developer account, giving access to the company’s developer environment.
LastPass claim no customer data or encrypted password vaults were compromised, however the hackers did steal portions of their source code and proprietary LastPass technical information. LastPass’s system stores passwords in ‘encrypted vaults’ that can only be decrypted using the customer’s master password; this aspect was apparently not compromised in this cyberattack. Containment and mitigation measures have been deployed, and a leading cybersecurity and forensics third-party firm has been employed.
As LastPass is one of the largest password management companies, it is always a concern that it is vulnerable to attacks. It also suffered an attack last year, via credential stuffing – that allowed hackers to confirm a user’s master password.
This event highlights that it is vital to enable as much security as possible (e.g. multi-factor authentication) on all accounts – especially those storing credentials and sensitive data. We also advise not trusting a third-party provider, like LastPass, with your credentials unless you are very sure of their own security practices and reliability. There are other, more reliable and transparent solutions for password management – such as BitWarden (which is open source).
Contact us to assess and secure your organisation’s data, and to discuss implementing ultra secure passwords solutions, such as a self-hosted instance of BitWarden.
