All vulnerabilities
CRITICALOpSec

OPSEC-LASTPASS-2022

Identity · LastPass

Summary

LastPass suffered two linked breaches in 2022. In August, an attacker compromised a developer account and stole source code and technical documentation. Using that information, the attacker targeted a senior DevOps engineer, one of only four people with access to production backup decryption keys, by exploiting an unpatched vulnerability in Plex media software on the engineer's home computer to install a keylogger and capture the master password after MFA. Between August 12 and October 26, 2022, the attacker exfiltrated cloud backups including encrypted customer vaults (with unencrypted URLs), AWS S3 production backups, DevOps secrets, and MFA seed databases, putting customers with weak master passwords at offline brute-force risk.

References

Related vulnerabilities

All OpSec →