The encyclopedia · Software & IT · Operational decision · 2022
LastPass was hacked twice in 2022 — the second breach exposed password vaults
LastPass was breached in August and November 2022. The second breach exposed encrypted password vaults. Users were told to change all passwords.
LastPass · GoTo · 2022-11
What happened
In August 2022, LastPass, one of the most popular password managers, disclosed that hackers had accessed its internal systems and stolen source code. The company initially assured users that no customer data had been compromised.
In November 2022, LastPass disclosed a second, more serious breach: the hackers had used information from the first breach to access a third-party cloud storage service and steal encrypted customer password vaults. The vaults contained users' encrypted passwords, website URLs and other sensitive data.
The breach was particularly damaging because LastPass's entire value proposition was security: users trusted the service to protect their most sensitive credentials. The company was criticized for its initial downplaying of the first breach, its slow disclosure of the second, and its failure to protect the cloud storage backup. The case illustrated how a security company's breach is more damaging than any other company's breach, because the product is the trust.
Why it happened
- The first breach (August 2022) exposed source code and was initially downplayed.
- The second breach (November 2022) exposed encrypted customer password vaults.
- LastPass's value proposition was security; the breach undermined the core product.
- The company was criticized for slow disclosure and inadequate protection of backups.
The lesson
A security company's breach is a contradiction. LastPass sold trust, and the hackers stole it. When your product is security, transparency after a breach is the product.
Aftermath
LastPass was criticized by security researchers and lost users to competitors (1Password, Bitwarden). The company overhauled its security infrastructure. The case prompted a broader discussion about password manager security and the risks of centralized credential storage.
Sources
spotted an error? The club wants to know.
More like this
Okta's support engineer was screen-shared into — and 366 customers were breached
Hackers exploited zero-days in Microsoft Exchange — and 250,000 servers were compromised
Hackers hid in SolarWinds' update — 18,000 organizations installed the backdoor
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.