LastPass Says DevOps Engineer Home Computer Hacked

TL;DR

Password management software firm LastPass says one of its DevOps engineers had a personal home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud storage resources. “The threat actor then exported the native corporate vault entries and content of shared folders, which contained encrypted secure notes with access and decryption keys needed to access the AWS S3 LastPass production backups, other cloud-based storage resources, and some related critical database backups,” LastPass confirmed.  Related: GoTo Says Hackers Stole Encrypted Backups, MFA SettingsRelated: LastPass Says Password Vault Data Stolen in Data BreachRelated: GoTo, LastPass Notify Customers of New Data Breach Related to Previous IncidentRelated: LastPass Says Source Code Stolen in Data BreachSubmit TipAdvertising

Like summarized versions? Support us on Patreon!