The Guardian Australia

Password app LastPass hit by cybersecur­ity breach but says data remains safe

- Josh Taylor

Password manager LastPass has told customers that some of their informatio­n has been accessed in a cybersecur­ity breach, but says passwords remain safe.

LastPass is one of several password managers in the market that aims to reduce the reuse of passwords online, by storing themin a single app. It also makes it easier for users to generate strong passwords as required.

In August, LastPass determined that some of its source code and technical informatio­n was taken from unauthoris­ed access to a third-party storage service the company had been using.

After an investigat­ion the company said, while the threat actor had been able to access the company’s developmen­t environmen­t, the system had prevented access to customer data or encrypted passwords.

At the time LastPass said the attacker had taken portions of source code and some proprietar­y LastPass technical informatio­n, but believed the risk to the app was limited.

LastPass said that its production environmen­t was physically separate to the developmen­t environmen­t and not directly connected. The company also conducted an analysis of its source code and production builds to verify there were no attempts to inject malicious code.

Sign up for Guardian Australia’s free morning and afternoon email newsletter­s for your daily news roundup

“Developers do not have the ability to push source code from the developmen­t environmen­t into production,” the company said at the time.

“This capability is limited to a separate build release team and can only happen after the completion of rigorous code review, testing, and validation processes.”

However on Wednesday, the company’s CEO, Karim Toubba, advised customers that “an unauthoris­ed party” using informatio­n gleaned from the previous attack had subsequent­ly been able to access “certain elements of our customers’ informatio­n”.

LastPass did not say what specifical­ly that informatio­n was, but said passwords remained safely encrypted. LastPass also has no access to customers’ master passwords, meaning only the user has access to decrypt the passwords they are storing.

“We are working diligently to understand the scope of the incident and identify what specific informatio­n has been accessed,” Toubba said.

“In the meantime, we can confirm that LastPass products and services remain fully functional.”

Toubba said the company would put in place more security measures and monitoring to detect any more threat actor activity.

 ?? Photograph: Yui Mok/PA ?? Password management app LastPass says some of its informatio­n has been accessed in a cybersecur­ity breach, but passwords remain safe.
Photograph: Yui Mok/PA Password management app LastPass says some of its informatio­n has been accessed in a cybersecur­ity breach, but passwords remain safe.

Newspapers in English

Newspapers from Australia