With more and more websites setting restrictions on the passwords you can use (ie it must have a capital letter, a unique symbol or your password must be 12 characters long), password managers such as Dashlane, KeePass, and 1Password have been gaining attraction among online users over the past 5 years.

One among the popular password managers, LastPass, reported in their official community blog post, that unfortunately their service was hacked this August 2022.

LastPass Image 1

The report states that the team has determined that two weeks ago, an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information.

In response to the security incident, the company states that it has deployed containment and mitigation measures, and engaged with a leading cybersecurity and forensics firm. The investigation regarding LastPass’ security incident is still ongoing, and the company has notified its users that currently there is no evidence that this incident involved any access to customer data or encrypted password vaults. 

LastPass’ products and services are operating normally, and with regard to the incident, the company has also implemented additional enhanced security measures and is evaluating further mitigation techniques to strengthen the cybersecurity environment.

Lastly, LastPass informs users that none of its users’ Master passwords have been compromised. LastPass says that it never stores or has knowledge of its users’ Master Passwords. The password manager utilizes an industry-standard Zero Knowledge architecture that ensures LastPass can never know or gain access to their customers’ Master Password.

 

RELATED:

(Source)