LastPass attack saw employee’s home computer hacked

designer491 – stock.adobe.com

The ongoing investigation into a series of linked security incidents at LastPass has found that the attacker was successfully able to compromise a developer’s home PC using a vulnerability in a media software package

Alex Scroxton

By

Published: 28 Feb 2023 12:45

The threat actor behind a series of compromises of credential management specialist LastPass attacked a DevOps engineer’s home computer to gain access to the organisation’s decryption keys, it has emerged.

The first attack took place in August 2022, and saw LastPass praised for its swift response to the incident, which saw the attacker access some source code and proprietary technical information.

They then used the information obtained at that point – prior to a reset completed by LastPass – to enumerate and exfiltrate data from cloud storage resources, in a second, deeper and longer-lasting intrusion, disclosed in December 2022, that saw them access customer data.

Compromised customer data included account information such as company and user names, billing addresses, email addresses, telephone numbers and IP addresses from where they accessed LastPass.

The cyber criminals also accessed a backup of customer vault data including encrypted fields, but as these are encrypted with 256-bit AES encryption and can only be decrypted using a key derived from the user’s master password, which is never known by LastPass, this would be very difficult to achieve as long as the user was following recommended best practice.

Initially, LastPass revealed only that the attacker targeted a developer’s endpoint, but the investigation has now turned up more details.

“Due to the security controls protecting and securing the on-premise datacentre installations of LastPass production, the threat actor targeted one of the four DevOps engineers who had access to the decryption keys needed to access the cloud storage service,” LastPass revealed in a new update.

“This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote code execution [RCE] capability and allowed the threat actor to implant keylogger malware. The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault.

“The threat actor then exported the native corporate vault entries and content of shared folders, which contained encrypted secure notes with access and decryption keys needed to access the AWS S3 LastPass production backups, other cloud-based storage resources and some related critical database backups,” the organisation said.

It added that the engineer in question has been receiving support in hardening their home network and equipment.

LastPass said that due to the differing tactics, techniques and procedures (TTPs) used in the attack chain, it had not been immediately obvious that what appeared at first to be two different incidents were in fact linked.

Additionally, it added, alerting and logging had been enabled throughout the events but did not immediately indicate the anomalous behaviour that later became more obvious. The fact that the unlucky engineer’s valid credentials were being used to access a shared cloud storage environment made it harder to differentiate between legitimate and illegitimate activity.

Ultimately, LastPass said, it had AWS to thank – it was the supplier’s GuardDuty Alerts that flagged anomalous behaviour as the attacker tried to use cloud identity and access management roles to perform unauthorised activity.

Since the attack, LastPass has taken a number of steps to harden its own cyber security, including rotating critical and high-privilege credentials, revoking and reissuing the compromised certificates, and applying additional hardening measures to its AWS S3 resources.

Given the apparent failings in its ability to respond swiftly to alerts, it has also revised its threat detection and response coverage, and on-boarded new automated and managed services to assist with this, including custom analytics to detect potential abuse of AWS resources.

Read more on Data breach incident management and recovery

Read More
Qiana Buresh

Latest

Churchill Trends As Old Clip Of Tonto Dikeh Alleging She Funded Their Wedding Goes Viral

A video of Tonto Dikeh discussing her marriage to Olakunle Churchill has resurfaced online. The renewed interest follows Churchill’s recent comments about his current marriage to Rosy Meurer. In the video, Tonto shares her emotional experience during their wedding, claiming she financed most of the ceremony while pregnant. An old video of Nollywood actress Tonto

The Home Depot is blowing out Ryobi 40V electric yard tools during this limited spring sale

The system works flawlessly together so buying in makes chores simpler. Ryobi We may earn revenue from the products available on this page and participate in affiliate programs. Learn more › Sign Up For Goods 🛍️ Product news, reviews, and must-have deals. Spring lawn season is the right time to catch a Ryobi 40V outdoor

“I don’t think it’s a good idea”: Van Dijk breaks speaks out on Liverpool star’s exit rumours

Van Dijk breaks silence on key Liverpool teammate’s uncertain future April 29th 2026, 17:10 Alisson Becker hugs Virgil van Dijk (Photo by Carl Recine/Getty Images) Alisson Becker has been linked with a move away from the club at the end of the season. He has been an exceptional servant for Liverpool over the years, and

Watch: YG Teases New Boy Group; Reveals New Girl Group Member + Plans For BABYMONSTER And TREASURE

YG Entertainment has revealed some of its plans for the months ahead—along with the third member of its upcoming girl group! On April 30 at midnight KST, YG Entertainment released an announcement video in which founder Yang Hyun Suk spoke about what the agency has coming up. With BABYMONSTER gearing up to make a comeback

Newsletter

Don't miss

Churchill Trends As Old Clip Of Tonto Dikeh Alleging She Funded Their Wedding Goes Viral

A video of Tonto Dikeh discussing her marriage to Olakunle Churchill has resurfaced online. The renewed interest follows Churchill’s recent comments about his current marriage to Rosy Meurer. In the video, Tonto shares her emotional experience during their wedding, claiming she financed most of the ceremony while pregnant. An old video of Nollywood actress Tonto

The Home Depot is blowing out Ryobi 40V electric yard tools during this limited spring sale

The system works flawlessly together so buying in makes chores simpler. Ryobi We may earn revenue from the products available on this page and participate in affiliate programs. Learn more › Sign Up For Goods 🛍️ Product news, reviews, and must-have deals. Spring lawn season is the right time to catch a Ryobi 40V outdoor

“I don’t think it’s a good idea”: Van Dijk breaks speaks out on Liverpool star’s exit rumours

Van Dijk breaks silence on key Liverpool teammate’s uncertain future April 29th 2026, 17:10 Alisson Becker hugs Virgil van Dijk (Photo by Carl Recine/Getty Images) Alisson Becker has been linked with a move away from the club at the end of the season. He has been an exceptional servant for Liverpool over the years, and

Watch: YG Teases New Boy Group; Reveals New Girl Group Member + Plans For BABYMONSTER And TREASURE

YG Entertainment has revealed some of its plans for the months ahead—along with the third member of its upcoming girl group! On April 30 at midnight KST, YG Entertainment released an announcement video in which founder Yang Hyun Suk spoke about what the agency has coming up. With BABYMONSTER gearing up to make a comeback

We Investigated Pastor Jerry Eze For Alleged Money Laundering – EFCC Chairman

Ola Olukoyede, chairman of the Economic and Financial Crimes Commission (EFCC), has disclosed that Pastor Jerry Eze of Streams of Joy International was investigated for about six months over suspected money laundering before being cleared. The EFCC Chairman disclosed this on Wednesday while speaking at the Jerry Eze Foundation Business Grant Award Ceremony in Abuja.

Tesla’s Business Has Become Much More Diversified in Just the Past Five Years. Does That Make Its Stock a Better Buy Today?

Key Points Tesla's energy generation and storage segment generated 27% revenue growth last year. The company's non-automotive segments were able to help offset a double-digit decline in auto revenue in 2025. These 10 stocks could mint the next wave of millionaires › Tesla (NASDAQ: TSLA) is known for its electric vehicles (EVs), and while they

WD sees sustainability as key business driver in an ‘AI economy’

Hard drive company WD promoted long-term operations and sustainability executive Jackie Jung to become its first chief sustainability officer in February, as it steps up sales to companies building AI data centers. Her vision: Turn sustainability into a “brand” for WD, a strategy that reduces risk for the $6 billion company (formerly known as Western

5 Business Ideas Worth Starting in 2026

If there is one thing Nigerians understand well, it is how to spot opportunity inside hardship. In 2026, that mindset will matter more than ever. The economy is tough, competition is rising, and many people are looking for smarter ways to earn, build, and survive. But even in a difficult environment, some businesses still stand