{"id":474859,"date":"2022-12-23T07:08:28","date_gmt":"2022-12-23T05:08:28","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=474859"},"modified":"2022-12-23T07:09:32","modified_gmt":"2022-12-23T05:09:32","slug":"lastpass-data-breach-passwords-and-sensitive-information-stolen","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/474859-lastpass-data-breach-passwords-and-sensitive-information-stolen.html","title":{"rendered":"LastPass data breach &#8211; Passwords and sensitive information stolen"},"content":{"rendered":"<p>LastPass, a password management service, announced on Thursday that hackers stole encrypted copies of customer passwords and other sensitive data such as billing addresses, phone numbers and IP addresses.<\/p>\n<p>The\u00a0announcement\u00a0is the latest update from a breach that occurred in August. At that time, the company said they had seen no evidence that the hackers had access to customer data or encrypted password vaults.<\/p>\n<p>But the company\u2019s statement on Thursday said that source code and technical information that were stolen as part of that hack was used to target another employee.<\/p>\n<p>The hackers were then able to obtain credentials and keys to access and decrypt data stored on a third-party cloud storage space.<\/p>\n<p>They were able to copy such things as basic customer account information, including email addresses and the IP addresses from which customers accessed LastPass, and \u201cfully-encrypted sensitive fields such as website usernames and passwords, secure notes and form-filled data.\u201d<\/p>\n<p>Password managers are a way for customers to store usernames and passwords in one place and can be accessed using a master password that a customer creates.<\/p>\n<p>The master password isn\u2019t known to LastPass nor is stored or maintained by the company, it said in its statement.<\/p>\n<p>The other encrypted data can only be decrypted \u201cwith a unique encryption key derived from each user\u2019s master password,\u201d the company said.<\/p>\n<p>Nonetheless, LastPass warned customers that they could be targeted for social engineering, phishing attempts or other methods.<\/p>\n<p>\u201cThe threat actor may attempt to use brute force to guess your master password and decrypt the copies of vault data they took,\u201d the company said in a statement.<\/p>\n<p>\u201cBecause of the hashing and encryption methods we use to protect our customers, it would be extremely difficult to attempt to brute force guess master passwords for those customers who follow our password best practices.\u201d<\/p>\n<p>For those who follow LastPass\u2019s password guidance, \u201cit would take millions of years to guess your master password using generally available password-cracking technology,\u201d the company said.<\/p>\n<p>A representative for LastPass didn\u2019t respond to messages seeking comment.<\/p>\n<p>The company said that it has hired cybersecurity firm Mandiant to investigate the breach. It also said that it is rebuilding its entire development environment from scratch, an indication that hackers had thoroughly comprised the company\u2019s sensitive systems.<\/p>\n<p>LastPass said that its investigation is ongoing, and that it has notified law enforcement and \u201crelevant regulatory authorities.\u201d<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/broadcasting\/474801-netflix-password-sharing-crackdown-starting-soon.html\" rel=\"bookmark\">Netflix password sharing crackdown starting soon<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>LastPass, a password management service, announced on Thursday that hackers stole encrypted copies of customer passwords and other sensitive data such as billing addresses, phone numbers and IP addresses.\u00a0<\/p>\n","protected":false},"author":341034,"featured_media":449088,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[26872,31054,31056],"class_list":["post-474859","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-data-breach","tag-lastpass","tag-lastpass-hacked"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/474859"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341034"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=474859"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/474859\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/449088"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=474859"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=474859"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=474859"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}