HomeSecurityGoTo: Hackers stole backups containing customer data

GoTo: Hackers stole backups containing customer data

LogMeIn, which was recently renamed to GoTo, warns its customers that cybercriminals breached its systems in November 2022 and stole encrypted backups of customer information along with an encryption key to unlock part of the data.

See also: GTA Online bug in PC version causes account problems

GoTo

GoTo provides a platform for remote work, collaboration and cloud-based communication, as well as remote IT management and technical support solutions.

In November 2022, the company disclosed a security breach in its development environment and a cloud storage service used by both itself and its subsidiary, LastPass.

The full impact of the breach on customer data had not yet been determined, as the investigation had just begun and Mandiant's cyber security team was assisting with it.

See also: Analysis of DragonSpark group attacks on East Asian orgs

So far, the internal investigation has revealed that the incident had a huge impact on GoTo's customers.

According to a tip shared with BleepingComputer by an anonymous reader, GoTo's Central and Pro product tiers have been affected due to a breach of a third-party cloud storage facility. Backups for both tiers have been compromised.

After extensive research, we concluded that a malicious hacker stole confidential backups of Central and Pro from an external cloud service. We are sending this notice to customers as a precautionary measure.

These stolen backup details include:

  • Central and Pro account usernames
  • Central and Pro account passwords (salted and hashed)
  • Development and provisioning information
  • One-to-Many scripts (Central only)
  • Multi-factor authentication information
  • Data such as emails, phone numbers, billing address and last four digits of credit card numbers.

To address the issue, GoTo resets the Central and Pro passwords for affected customers, while moving the accounts to a more secure identity management platform.

This platform provides additional security measures that make it significantly harder for anyone to exploit or take over your account without permission.

Although the company did not disclose what encryption was used for its backups, if asymmetric encryption such as Advanced Encryption Standard (AES) had been implemented, then decrypting these backups with the stolen key may be possible.

GoTo: Hackers stole backups containing customer data

The company adds that it has no evidence yet that the attackers ever accessed its production systems and says that man-in-the-middle attacks could not have any impact on customers because TLS 1.2 encryption and peer-to-peer technology are used to prevent eavesdropping.

See also: North Korean hackers stole millions of dollars in crypto

Man-in-the-middle attacks (MITM) are a type of cyber attack used by malicious actors to gain access to sensitive information. The attack is called “man-in-the-middle” because the attacker sits between two parties -the victim and the intended recipient of the data- and records or modifies the data as they pass through.

As GoTo continues to investigate the incident, it promised to keep customers informed of any related discoveries.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS