Site icon Auspreneur

Hacker copied the source code for LastPass

Australia

LastPass, a well-known password management firm, has once again fallen victim to a cyberattack, but consumers can rest confident that their accounts are secure.

CEO Karim Toubba said on the business blog that LastPass had discovered a single compromised developer account had provided access to an unauthorised party.

According to Toubba, the hacker was able to take “portions of the source and certain confidential LastPass technical knowledge.”

We have implemented containment and mitigation strategies in response to the incident, as well as hired a top cybersecurity and forensics firm.

While our investigation is still ongoing, we have reached a state of containment, put further, enhanced security measures in place, and we have not found any additional indications of unauthorised activity,” Toubba noted.

The CEO of LastPass claimed that users’ Master Passwords had not been compromised because the firm uses an industry-standard zero knowledge architecture and does not keep user information on its servers.

Additionally, neither user vaults nor private data were accessed, according to LastPass.

The popular password manager LastPass has been breached several times over the course of its existence, including a 2011 incident in which certain users’ email addresses and salted password hashes were taken from a business database.

2015 saw another data breach at LastPass, this time exposing user account information.

Exit mobile version