Technology

Customers’ password vaults were accessed as a result of the LastPass security breach.

LastPass came back with the latest news of its security breach. The details of the attack were unclear as the incident happened. The company has generated details about a security breach. In the incident, customer passwords along with their personal information (names, emails, billing addresses, contact numbers, etc.) were stolen.

The update was published today by CEO Karim Toubba on the company’s official blog.

A system hacking incident was reported by the company on November 30, following the incident of August 2022. A more detailed picture of the whole issue was shared today.

LastPass’s initial claim depicted the violation of users’ names, emails, and other personal information.

The latest statement revealed the results of investigations until now. The inquiry has made the hypothesis that access to cloud storage and a dual-storage container were compromised. A hacker had accessed the information from a backup that was storing initial details about customers and meta-related data such as the company’s name, end user names, bill address, email, contact numbers, and IP address that users were availing of the LastPass services through.

The access to and copying of the customer’s password vaults were more concerning.

The malicious attacker was also able to gain access to a backup of client cellar information from the protected storage container, which is saved in a secret binary sequence and contains both crucial areas such as site passwords and usernames. Private memos and form-filled data, as well as unprotected data like website URLs, are still encrypted with 256-bit AES and can only be unlocked with a special encryption key derived from each user’s master password. Reminder: LastPass never has access to and does not keep track of the master password. Data encryption and decryption are exclusively handled locally by the LastPass client.

However, the remaining password resources are protected by a single password key that the hacker could try to access.You need to be careful about it if you are using this website.

According to information from LastPass, the investigation is still in progress, and the company will keep customers updated about more clues and patterns that lead to the reveal of the complete incident.

Recent Posts

Android 17: Google finally lets users design the quick settings freely

Google has released the third beta version of Android 17 QPR2. The update brings users…

16 hours ago

Baby with iPhone: Apple has to remove advertising poster after heavy criticism

A huge Apple advertising poster in Milan has sparked heated debate. The motif showed a…

16 hours ago

After criticism of a lame player: VLC makers blame Windows

If the VLC player takes over 30 seconds to play a simple MP3 file, you're…

16 hours ago

Teams: Microsoft is discontinuing the chat function after 18 months

After only around 18 months, Microsoft is ending support for the live chat widget in…

16 hours ago

68 billion well spent: Blizzard becomes Microsoft’s Xbox savior

After the billion-dollar takeover by Microsoft, Blizzard Entertainment rescues the ailing Xbox division. The studio…

16 hours ago

Instagram or Instagzam? Users scoff at the new Insta logo

Meta is giving Instagram a new text logo for the first time in ten years.…

16 hours ago