"Unusual Activity" Within the LastPass Development Environment

plat

Level 29
Thread author
Top Poster
Sep 13, 2018
1,793

Notice of Recent Security Incident

To All LastPass Customers,

I want to inform you of a development that we feel is important for us to share with our LastPass business and consumer community.
Two weeks ago, we detected some unusual activity within portions of the LastPass development environment. After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults.
We have determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information. Our products and services are operating normally.

source

 

plat

Level 29
Thread author
Top Poster
Sep 13, 2018
1,793
Blah blah blah This is their second or maybe third Security incident in the last few years
I for one with use this software,

I understand your point of view. However, if there is a choice between disclosure and keeping this a secret, I am glad LastPass chose to reveal it, even though it had a limited impact and reportedly, no user info was corrupted. Beat the bad guys to the punch, as well as forging a bond between LP and its users is the right way to go, in my opinion.
 

Lightning_Brian

Level 15
Verified
Top Poster
Content Creator
Sep 1, 2017
742
Very interested to see if more details will be released or not. I agree with @plat here - much rather see organizations let everyone know what is up. It puts everything out there and makes sure folks are aware of what's going on while not adding to potential fear the company is trying to hide something. Having companies be forward and honest does go a long way in my opinion for any security incident.
 

Brahman

Level 17
Verified
Top Poster
Well-known
Aug 22, 2013
821



You are wrong. Watch this:
hxxps://www.youtube.com/watch?v=8vIq2Gc6SSE

No I am not. It's not for the first time they had issues with security. This time it just may be source code, but who knows tomorrow it can be something more serious and I am still holding on to my argument that there are better options both on paid and free segments.
 

amirr

Level 27
Verified
Top Poster
Well-known
Jan 26, 2020
1,628
who knows tomorrow it can be something more
Who knows? God knows. "In God we trust" the official motto of the United States. I personally try every day to live in the present and be positive, and not think about what happens for tomorrow. What I mentioned, is based on my own thoughts.

Don't get me wrong, but I can understand your point of view, especially in terms of security and privacy.

What happened in the past with LP, did not bother me. And I don't judge their future based on their past events.
Also in the video, he mentioned that such things happen for many companies, but they are not transparent enough to talk about it.
 
Last edited:

CyberPanther

Level 6
Verified
Well-known
Oct 1, 2019
298
LastPass says the attacker behind the August security breach had internal access to the company's systems for four days until they were detected and evicted.

In an update to the security incident notification published last month, Lastpass' CEO Karim Toubba also said that the company's investigation (carried out in partnership with cybersecurity firm Mandiant) found no evidence the threat actor accessed customer data or encrypted password vaults.

"Although the threat actor was able to access the Development environment, our system design and controls prevented the threat actor from accessing any customer data or encrypted password vaults," Toubba said.
 

Lightning_Brian

Level 15
Verified
Top Poster
Content Creator
Sep 1, 2017
742
This is indeed interesting. Why they weren't very forthcoming of this part is interesting.. Probably came out of the investigation. Being open about this and the other information is key though. I view it as them doing the right thing by letting others know.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top