LastPass hacked for the second time this year, customer data stolen by hacker

asset_upload_file39648_234597.png

If you use LastPass as a secure password-managing service, things might not be as secure as you think. Earlier this year in August, the password keeper disclosed that it had been breached, with an unknown hacker having gained access to LastPass' source code and proprietary data. At the time, the company stressed that despite this, customers were unaffected by the hack, and that their data was safe. Now, for the second time this year, LastPass is having to announce that they have been hacked for a second time this year, and that in this incident, customer data has indeed been accessed and stolen.

According to an internal investigation, that same hacker used the data (cloud storage access and dual storage container decryption keys from August in order to get ahold of a backup of LastPass customer data. This means that the individual was able to access billing addresses, telephone numbers, IP addresses, and email addresses saved to users' accounts. That isn't the end of the breach, though, because the hacker also copied a backup of vault data, which contains the most sensitive info; usernames, passwords, and saved form-field data. LastPass claims that no credit card data was accessed, as the service does not store complete credit card numbers and information.

While the information like email addresses and telephone numbers were not encrypted, the password vaults were, with a 256-bit AES encryption, requiring a special key in the form of a user's master password to access. So despite having this information, LastPass claims that this would make it incredibly difficult for the hacker to actually obtain the data from the customer vault. That being said, there is the potential for someone to either brute force the master password, or eventually decrypt the data.

The threat actor may also target customers with phishing attacks, credential stuffing, or other brute force attacks against online accounts associated with your LastPass vault. In order to protect yourself against social engineering or phishing attacks, it is important to know that LastPass will never call, email, or text you and ask you to click on a link to verify your personal information. Other than when signing into your vault from a LastPass client, LastPass will never ask you for your master password.

With all this in mind, LastPass says that there isn't a need to take action at this time, unless your master password was not as secure as recommended. This is just the latest in a string of numerous hacks that the password managing service has suffered over the past few years, with incidents taking place in 2015, 2017, and 2019, all resulting in customer data being accessed by hackers.

:arrow: Source
 

64bitmodels

Professional Nintendo Hater
Member
Joined
Aug 1, 2019
Messages
1,451
Trophies
1
Age
18
XP
2,883
Country
United States
single point if failure.
true, but it's very unlikely someone's gonna be able to break into your house and steal all the passwords on a sheet of paper.... it's even more secure with the third method, since USB sticks are very easy to hide (and you can just set a password/code on your PC to prevent anyone from seeing that txt file)

also, there's method #1, yknow. Just remember your damn passwords, they're your livelihood.
 
  • Like
Reactions: SylverReZ

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
13,079
Trophies
4
Location
WA State
Website
ko-fi.com
XP
17,289
Country
United States
Or just don't and use an external device to keep all of your passwords on, much more secure than keeping all of it stored on your device.
I keep mine in my locked Samsung Notes app. Each note is locked and encrypted with my biometrics.
 
  • Like
Reactions: SylverReZ

kisamesama

Well-Known Member
Member
Joined
Sep 29, 2008
Messages
564
Trophies
1
XP
1,445
Country
United States
Or just don't and use an external device to keep all of your passwords on, much more secure than keeping all of it stored on your device.
what happen if the external device gets lost, stolen or damaged? I used to store my passwords locally on my phone but phone got a problem and I had to factory reset.
 
  • Sad
Reactions: impeeza

SylverReZ

Certified GBATemp Boomer
Member
Joined
Sep 13, 2022
Messages
7,409
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
22,865
Country
United Kingdom
any suggestion how to store the passwords and easily backup on several devices?
Note any passwords for what accounts you mostly use on your device, make sure to encrypt them so that nobody sees it. Use something like a note pad, phone, tablet or any device to keep said information in the event of an emergency.
 

KitChan

Well-Known Member
Member
Joined
May 1, 2022
Messages
154
Trophies
0
Age
30
Location
あなたの心
XP
467
Country
New Zealand
Maybe storing your passwords outside your home or other secure place that you have exclusive physical access to was never a good idea.
Post automatically merged:

Note any passwords for what accounts you mostly use on your device, make sure to encrypt them so that nobody sees it. Use something like a note pad, phone, tablet or any device to keep said information in the event of an emergency.
I would recommend an encrypted USB drive as unlike a smartphone, it can't get hacked while it's disconnected and unlike a notepad, people going through your belongings can't read it.
 
Last edited by KitChan,
  • Like
Reactions: SylverReZ

RAHelllord

Literally the wurst.
Member
Joined
Jul 1, 2018
Messages
746
Trophies
1
XP
2,846
Country
Germany
any suggestion how to store the passwords and easily backup on several devices?
KeePass2 that someone previously linked, it's a highly encrypted container that's just a regular file, and you can copy it anywhere. There are also clients to use that container on pretty much any device under the sun so if you want you can use and read it on Android, windows, Linux, iOS, and MacOS.
 

EpikJimmer

Screw hater
Member
Joined
Jun 9, 2018
Messages
589
Trophies
0
Age
19
Location
Somewhere, that's for sure ¯\_(ツ)_/¯
XP
2,289
Country
Greece
I just write all my passwords on a txt file but I feel like I should be writing them on actual paper instead since THAT can't be possibly hacked.
Like, yeah, I memorized most of them, but for websites I don't use anymore / stay logged in at all times until I get a new device, I wrote them down (or typed them down idk)
 

tech3475

Well-Known Member
Member
Joined
Jun 12, 2009
Messages
3,704
Trophies
2
XP
6,125
Country
I just write all my passwords on a txt file but I feel like I should be writing them on actual paper instead since THAT can't be possibly hacked.
Like, yeah, I memorized most of them, but for websites I don't use anymore / stay logged in at all times until I get a new device, I wrote them down (or typed them down idk)

Houses can be burgled, computers can be hacked, brains can be stupid.

Tl;dr we’re screwed.
 

tpax

Well-Known Member
Member
Joined
Nov 16, 2014
Messages
532
Trophies
0
Age
44
XP
3,046
Country
Ukraine
Using a password manager like LastPass is far more secure than storing it in your brain, paper, browser or anywhere else, considering you have a solid master password and 2FA. Even if the database has been stolen.

I use Bitwarden, self-hosted, and all my passwords are randomly generated. That wouldn't be possible if I would have been using my brain to remember all passwords.
 

RAHelllord

Literally the wurst.
Member
Joined
Jul 1, 2018
Messages
746
Trophies
1
XP
2,846
Country
Germany
Using a password manager like LastPass is far more secure than storing it in your brain, paper, browser or anywhere else, considering you have a solid master password and 2FA. Even if the database has been stolen.

I use Bitwarden, self-hosted, and all my passwords are randomly generated. That wouldn't be possible if I would have been using my brain to remember all passwords.
The important distinction here is "self-hosted" which LastPass is not.
 
  • Like
Reactions: impeeza

console

Elvira fans ❤ :-) I'm rocking Windows 7 for 11 yrs
Member
Joined
Mar 1, 2013
Messages
399
Trophies
1
Location
In heart of Windows XP, 7. I ❤ 👠! 🥰
Website
www.startpage.com
XP
3,425
Country
United States
I never use any password managing since year 2001 from Windows ME, Windows XP, Windows 7 to now.

I stored my passwords in my brain memory cells to save them. Hackers would never steal my passwords.

When people get older like 50s, 60s and later must write on papers then put in safe lock with important documents and money. That's all.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Plus technology cost iirc even a water jet drill is 1k per
  • cearp @ cearp:
    @K3Nv2 that's crazily expensive. how long will that take to pay off?

    Although diet is largely education, people don't need to go to university to learn what's healthy and what's not,
    it's the whole country, big corporations and advertising that is to blame for leading most of the population to believe that poptarts and froot loops are healthy to feed a child
  • mthrnite @ mthrnite:
    i would think the population knows better but with food deserts and abject poverty, sometimes a poptart gonna have to do.
  • mthrnite @ mthrnite:
    it's a big ol complicated world innit
    +1
  • Sicklyboy @ Sicklyboy:
    As someone who went through the grade school system in the US some time within the past 30 or so years, not nearly enough is done to promote and educate on how to eat healthy in a way that is feasible to do on a regular basis and also affordable. Eating healthy is, comparatively, fucking expensive. So is eating unhealthy, but in many cases eating unhealthy is more affordable than eating healthy
    +1
  • cearp @ cearp:
    90k could get you a 3 bedroom house in some poorer parts of the country
  • K3Nv2 @ K3Nv2:
    @cearp, it's like buying a new car most dentists say so $250 per the rest of your life
  • cearp @ cearp:
    Jesus
  • K3Nv2 @ K3Nv2:
    These are actual implants to dentures though
  • cearp @ cearp:
    Well once it's all done I'm sure you'll be happy with the result
  • K3Nv2 @ K3Nv2:
    Just a flappity denture would probably be 5k
  • mthrnite @ mthrnite:
    sold
  • K3Nv2 @ K3Nv2:
    I got some faith implants are going to justbe included with a crown cost
  • K3Nv2 @ K3Nv2:
    Procedures bullshit wait 4 months for graft to heal wait another four months the post to heal then get crown
  • SylverReZ @ SylverReZ:
    Only 1 tempycoin.
    +1
  • K3Nv2 @ K3Nv2:
    Got kfc for dinner fucking dinner box is a joke
  • BigOnYa @ BigOnYa:
    Just go gummy, ancientboi would like you better that way anyways, and you save money on toothbrushes/toothpaste
  • cearp @ cearp:
    @Sicklyboy I agree, but also it's about self control and realistic thinking. We wouldn't feed a dog soda, so why feed it to ourselves? Eating unhealthy food because it's cheap is one thing, but I'm sure you know people who drink soda routinely when they should be drinking water which is free.
    I get it can feel mean to say "no treat sweet beverage for you anymore" but for many people it's just in their way of life.
  • K3Nv2 @ K3Nv2:
    I drink soda twice out of the week
  • K3Nv2 @ K3Nv2:
    Plus decay can start as young as 15 tons of factors
  • cearp @ cearp:
    Even sugar free isn't good, as the acid is bad enough.
  • cearp @ cearp:
    oh earlier than 15 Ken, babies, children can get decay
  • K3Nv2 @ K3Nv2:
    So dentists give. Us these caps that'll last a few years to fight thrm
  • K3Nv2 @ K3Nv2:
    Yeah but babies get a new set
  • K3Nv2 @ K3Nv2:
    Screw godfor not giving us a new adult set after we mess up
    +1
    K3Nv2 @ K3Nv2: Screw godfor not giving us a new adult set after we mess up +1