ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Password manager LastPass suffers second major data breach of 2022

Password management leader LastPass has suffered yet another data breach that has compromised certain customer information.In a recent incident notification, LastPass confirmed that it identified “unusual activity within a third-party cloud storage service”, that is used by both LastPass and its affiliate, GoTo. The company immediately launched an investigation and involved one of the leading security firms, Mandiant, to understand the scope of the cyber attack.“We have determined that an unauthorised party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information,” LastPass said.LastPass has, however, confirmed that customers’ passwords were not compromised as they are safely encrypted by the company’s Zero Knowledge architecture. LastPass also said that while the investigation is still ongoing, its products and services remain fully functional.“As part of our efforts, we continue to deploy enhanced security measures and monitoring capabilities across our infrastructure to help detect and prevent further threat actor activity,” LastPass added.This is the second cyber security incident LastPass suffered in less than six months. Earlier this year, in August, LastPass suffered a much-publicised breach that involved hackers gaining access to its development environment and stealing portions of the source code and proprietary technical information.Upon detecting the suspicious activity, the company initiated an investigation that confirmed that a threat actor gained access to portions of the LastPass development environment by using a compromised developer account.The company, at that time, also confirmed that it did not find any evidence of unauthorised access to encrypted vault data that stored user passwords and could be decrypted using the customer’s master password. LastPass stated that this incident did not compromise the user’s Master Password as it was never stored by the company.“While our investigation is ongoing, we have achieved a state of containment, implemented additional enhanced security measures, and see no further evidence of unauthorised activity. Based on what we have learned and implemented, we are evaluating further mitigation techniques to strengthen our environment,” the company said at that time.Commenting on the latest cyber attack on LastPass, Jamie Akhtar, CEO and co-founder of CyberSmart, said, “The ramifications of a successful breach of LastPass’s third-party cloud storage are serious. If customer data was stored there – which it appears it was – the company is potentially facing a situation in which personal data has been accessed by cybercriminals. This could be used to launch any number of different threats from social engineering attacks to classic phishing scams.“However, it’s important to note that LastPass does have a failsafe in place. LastPass’s Zero Knowledge architecture means that customers’ passwords are secured with virtually unbreakable encryption and this really limits the amount of damage a threat actor can do,” he added.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543