World’s Most Popular Password Manager, LastPass, Says It Was Hacked | Tech News

World’s Most Popular Password Manager, LastPass, Says It Was Hacked

LastPass, a password manager used by more than 33 million people around the world, said a hacker recently stole source code and proprietary information after breaking into its systems.

By:BLOOMBERG
| Updated on: Aug 26 2022, 19:43 IST
Password
The attack struck a company that generates and stores hard-to-crack, auto-generated passwords for multiple accounts, like Netflix or Gmail.  (AFP/Istock.com)

LastPass, a password manager used by more than 33 million people around the world, said a hacker recently stole source code and proprietary information after breaking into its systems.

The company doesn't believe any passwords were taken as part of the breach and users shouldn't have to take action to secure their accounts, according to a blog post on Thursday.

You may be interested in

MobilesTablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage

An investigation determined that an “unauthorized party” cracked into its developer environment, which is the software that employees use to build and maintain LastPass's product. The perpetrators were able to gain access through a single compromised developer's account, the company said.

Also read
Looking for a smartphone? To check mobile finder click here.

The attack struck a company that generates and stores hard-to-crack, auto-generated passwords for multiple accounts, like Netflix or Gmail, on behalf of its users -- without the need to manually enter credentials. LastPass lists Patagonia, Yelp Inc. and State Farm as customers on its website.

Cybersecurity website Bleeping Computer reported that it had asked LastPass about the breach two weeks ago.

Allan Liska, an analyst on the Computer Security Incident Response Team at cybersecurity company Recorded Future, said he was impressed with the “speedy notification” from LastPass.

“While two weeks might seem like a long time to some, it can take a while for incident response teams to fully assess and report on a situation,” he said. “it will take time to fully determine the extent of any damage that may have been as result of the breach. However, for now it appears to not be client-impacting.”

LastPass didn't immediately respond to a request for further comment.

There was speculation on social media that hackers may be able to access the keys to password vaults after stealing source code and proprietary information.

“It is unlikely that the stolen source code will give the criminals access to customer passwords,” Liska said.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on Whatsapp channel,Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 26 Aug, 19:43 IST
NEXT ARTICLE BEGINS