LastPass’s source code stolen in data breach

The password management service reported that a data breach involved unauthorized access to its development environment

Add bookmark
LastPass confirms data breach

LastPass, a password manager which has 25 million users, has confirmed that its source code was stolen during a data breach.

Karim Toubba, CEO of LastPass, explained that the breach was discovered after noticing some suspicious activity within the LastPass development environment two weeks ago. A third party gained unauthorized access to the environment through a compromised developer account. This third party then took “some proprietary LastPass technical information” and “portions of source code”.

LastPass has taken measures while an investigation into the breach is ongoing, including “achieving a state of containment [and] implementing additional enhanced security”, and has reported that no further evidence of unauthorized access to the developer environment has been found.  
The company also said it was investigating further mitigation techniques to prevent future breaches and had “engaged a leading cybersecurity and forensics firm” in the investigation into the breach.

LastPass has confirmed that no passwords, master passwords or personal data or information were compromised during the breach. 


Recommended

info@cshub.com/r/n

We hope you enjoy All Access from CS Hub!!<\/p>\r\n<p>Best Regards,<\/p>\r\n<p><a href=https://www.cshub.com/"https:////www.cshub.com///" target=\"_blank\">CS Hub Team<\/a><\/p>\r\n<p>P.S. Be sure to check out our other upcoming <a href=https://www.cshub.com/"https:////www.cshub.com//events?filter_format=ONLINE\%22 target=\"_blank\">All Access events here<\/a>.<\/p>\r\n<p>--------------------------------<\/p>\r\nConnect with us on Social Media: <a href=https://www.cshub.com/"https:////www.linkedin.com//groups//12067996///" target=\"_blank\">LinkedIn<\/a> | <a href=https://www.cshub.com/"https:////twitter.com//CSHubUSA/" target=\"_blank\">Twitter<\/a><\/p>\r\n<p>--------------------------------<\/p>\r\n<p>FAQS<\/p>\r\n<p><b>Can I invite my colleagues?<\/b><br>Yes of course! Please send them this link so they can register for free! [WebUrl]<\/p>\r\n\r\n<p><b>How do I access the sessions?<\/b><br>\r\nAll Access is run on Zoom Events. You should receive an email shortly from Zoom Events with your unique All Access link to the event lobby. Please hold on to that email ahead of the event. We\u2019ll also send you a reminder 24 hours before we go live!<\/p>\r\n\r\n<p><b>Will the agenda be updated?<\/b><br>\r\nYes, the agenda will be continuously updated on the website with the latest sessions & speakers. As we get closer to the event, also look out for our weekly updates which will also include the latest updates information and link to access the event.<\/p>\r\n<p><b>Can I access the sessions On Demand?<\/b><br>\r\nEvery session will be available after the event via the event lobby. We\u2019ll also send you a reminder about the On Demand sessions which will be sent to you after the event is over.<\/p>\r\n<p>--------------------------------<\/p>\r\n<p>RELATED RESOURCES TO READ BEFORE YOUR EVENT<\/p>\r\n<ul>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//executive-decisions//reports//cs-hub-mid-year-market-report-2022?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CS Hub Mid-Year Market Report 2022<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//ciso-strategies-for-proactive-threat-prevention?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">CISO strategies for proactive threat prevention<\/a><\/li>\r\n <li><a href=https://www.cshub.com/"https:////www.cshub.com//security-strategy//reports//how-to-strengthen-email-security-and-protection-against-advanced-ransomware-attacks?utm_source=eco-event-confirmation-email&utm_medium=email&utm_campaign=eco-event-confirmation-email\%22 target=\"_blank\">How to strengthen email security and protection against advanced ransomware attacks<\/a><\/li>\r\n<\/ul>","event_registration_srs_confirmation_email":null,"assets_from_cdn":true},"bant_disabled":1,"sponsorship_disclaimer":null,"sponsorship_disclaimer_text":null,"sponsorship_disclaimer_checkbox_disabled":0,"ext_treat_id":null,"recording_url":null,"file_attachment":null,"ingo_enabled":null,"ingo_activator_id":null,"ingo_autofiller_id":null,"ingo_amplifier_id":null,"ingo_authorizer_id":null,"restricted_content":0,"featured_events_embedded":[],"featured_content_embedded":[{"id":"62ff6fc7b962cc3fb47d87ba","name":"Data breaches on gaming sites are becoming more common","description":"Cyber Security Hub takes a deep dive into why gaming sites may be a target for hackers","file":null,"url":"\/attacks\/articles\/data-breaches-on-gaming-sites-are-becoming-more-common"},{"id":"62f4e94acbeb1317b057d394","name":"IOTW: Twilio suffers data breach following phishing attack","description":"The company\u2019s employees were directly targeted by a phishing attack disguised to look like it came from Twilio\u2019s IT department","file":null,"url":"\/attacks\/news\/iotw-twilio-suffers-data-breach-following-phishing-attack"},{"id":"62a0cf741ffc11648c662d2a","name":"IOTW: US healthcare group data breach affects two million","description":"A data breach at Shields Health Care Group affects two million patients","file":null,"url":"\/data\/news\/iotw-us-healthcare-group-data-breach-affects-two-million"},{"id":"61a9ee78d1d92e03fb563c3f","name":"IOTW: Panasonic confirms data breach","description":"Japanese electronics manufacturer suffers illegal intrusion to file servers","file":null,"url":"\/attacks\/articles\/iotw-panasonic-confirms-data-breach"},{"id":"5d9b8549d1d92e0ea916c6d2","name":"IOTW: Multiple Yahoo data breaches across four years result in a $117.5 million settlement","description":"Phishing And Nation State Attacks Lead To Mega-Breach Of Former Leading Email Provider","file":null,"url":"\/attacks\/articles\/incident-of-the-week-multiple-yahoo-data-breaches-across-4-years-result-in-a-1175-million-settlement"}],"featured_content_portal_embedded":null}" >