The massive LastPass hack from 2022 is still haunting us
|
By
Judy Sanhz Published December 17, 2024 |
Just when you thought the LastPass breach of 2022 was over, we’re still learning just how detrimental the hack was. According to blockchain expert ZachXBT and spotted by The Block, $5.36 million was stolen from 40 users in a string of attacks. This is on top of the $4.4 million stolen in October 2023 and $6.2 million earlier this year in February 2024.
The original hack goes back to 2022 when hackers claimed to have accessed LastPass’ data, which contained API tokens, customer keys, multifactor authentication seeds (MFA), and encrypted password vaults. Although no official information explains how the breach happened, it’s possible that the hacker responsible gained access to information that aided the breach. Hackers forced their way in despite the password vaults being encrypted because users reused weak or previously leaked combinations. This access, combined with the users’ weak or reused passwords, led to the various accounts being compromised.
“Cannot stress this enough, if you believe you may have ever stored your seed phrase or keys in LastPass migrate your crypto assets immediately,” ZachXBT wrote in an X post last year.
Only time will tell if this string of attacks continues, which makes you wonder if LastPass is safe. But how did the original breach happen? LastPass revealed that the hackers stole the app’s source code. In a subsequent attack, the hackers merged the stolen data with information discovered in another data breach.
The hackers then exploited a weakness in a remote-access app that LastPass employees used. This allowed the hacker to install a keylogger onto the PC of a senior engineer at LastPass, which registered all the key inputs.
The breach highlights the importance of always having a strong password on all your accounts. Never reuse passwords or have easy-to-guess passwords that hackers will love you for. If creating long, strong passwords is not your thing, you can always use one of the best password generators.
Related Posts
Qualcomm is set to ratchet up chip prices in September, and your next gadget upgrade could bear the brunt
The price hike will be in effect from September 1, 2026, a recent Bloomberg report claims. Essentially, all the companies placing their chip orders after that will pay a higher price.
Stop fighting with your roomie over outlets and get one of these multi-port chargers before you head back to school
Back-to-school season is a smart time to buy one. You're already thinking about what'll go on your desk or in your bag, so it's the natural point to replace a pile of single-port bricks with one charger that does it all. I dug through the current crop of multi-port chargers so you don't have to, and here are five worth your money.
OpenAI’s rogue AI hack was just the beginning, Hugging Face warns
Speaking to the BBC, Wolf warned that AI-driven intrusions could become one of the most common forms of cyberattack and said many companies have yet to realize how dramatically the threat has changed. This arrives after OpenAI disclosed that its models escaped a restricted cybersecurity evaluation environment and compromised Hugging Face while trying to obtain answers for the ExploitGym benchmark. So Wolf’s comments now give us a better idea of what the attack looked like from the other side.