Popular password manager, LastPass, revealed that hackers had gained access to third-party cloud storage earlier this year, using information stolen from an attack in August 2022, resulting in the theft of its customers' vault data.

While no data during the August incident, technical information and source code from the company’s development environment were stolen and used to target another employee. The attackers obtained credentials and keys that were used to access and decrypt certain storage volumes on the cloud storage service.
See also: Top 10 – cybersecurity stories: 2022 in review
Last month, Karim Toubba, the company's CEO, had only said that a malicious actor had gained access to "certain elements" of customer data.
Now, Toubba has announced that LastPass uses the cloud to store backups of production data. The attacker gained access to Lastpass' cloud storage using "cloud storage access keys and dual storage container decryption keys" stolen from the developer environment.
“The threat actor copied information from backups that contained key customer account information and related metadata, including company names, end user, billing addresses, email addresses, phone numbers, and IP addresses from which customers accessed the LastPass service,” Toubba said in the recent announcement.
“The threat actor was also able to copy a backup of customer vault data from the encrypted storage container stored in a proprietary binary format that contains both unencrypted data, such as website URLs, and fully encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data.”
See also: Nio hacked – hackers are holding it for ransom
LastPass: Some of stolen customer vault data is “securely encrypted”
Fortunately, each user's sensitive data is protected by 256-bit AES and can only be unlocked with a unique decryption key generated from the user's master password.
Toubba confirmed that LastPass does not have access to the master password, as it is not stored on its systems.
LastPass warned customers that hackers may attempt to use brute-force to crack and gain access to master passwords, so they can gain further access to encrypted vault data.
However, if users follow the password best practices recommended by LastPass, they will make it much harder for cybercriminals.
If you do, “it would take millions of years to guess your master password using generally available password-cracking technology,” Toubba added.

“Your sensitive vault data, such as usernames and passwords, secure notes, attachments, and form fields, remains securely encrypted using LastPass' Zero Knowledge architecture“.
See also: Knox College ransomware: Hackers demand ransom from students
LastPass is the company behind one of the most popular password management software. It claims that the password manager is used by more than 33 million people and 100,000 businesses. So any breach of data could have devastating consequences.
Password managers like LastPass are a great help, as you can use them to store your passwords, which should all be long, complex, and unique for each site or service. However, security like this are a reminder that cybercriminals are looking for ways to attack any service they can.
Source: www.bleepingcomputer.com
