# LastPass: Yet Another Data Breach
LastPass, the popular password manager, has once again faced a data breach. This time, the incident occurred through an external partner, the market research firm Klue. This news comes after several security incidents that have already shaken user trust.
Details of the Breach
According to a report by TechCrunch, LastPass has emailed users affected by this breach, which allowed hackers to access customer information and support case data. The compromised information includes customer names, phone numbers, email addresses, physical addresses, as well as sales and support data. Fortunately, the password vaults, which are the core of LastPass's offering, have not been affected.
Measures Taken by LastPass
Following the incident, LastPass revoked employee access to Klue, rotated the exposed API tokens, and notified law enforcement. A detailed investigation was launched to fully understand the scope of the event. LastPass is working closely with Klue and Salesforce, as Klue's platform integrates with Salesforce and Gong systems.
Impact on Users
LastPass users are encouraged to remain vigilant against potential phishing attacks or social engineering attempts that could leverage the compromised information. The company also shared IP addresses and email sender domains associated with the attackers to help detect suspicious activity.
History of Security Incidents at LastPass
This latest breach is part of a series of security incidents affecting LastPass. In 2015, hackers obtained account email addresses, password reminders, authentication hashes, and cryptographic salts. In 2022, a developer account was compromised, allowing an attacker to steal source code and technical information, and later access cloud backups containing customer records.
Recommendations for Users
Although LastPass's password vaults have not been directly compromised, it is crucial for users to take steps to protect their accounts. This includes enabling two-factor authentication, regularly reviewing third-party app access, and being aware of phishing attempts.
Conclusion
This latest incident underscores the importance of choosing trustworthy partners and maintaining constant vigilance in data security. With the increase in technological integrations, companies must double down on efforts to secure their ecosystems.
Let's discuss your project in 15 minutes.