
LastPass Hackers Allegedly Stole $5 Million This Week—Report
A staggering amount of cryptocurrency has been allegedly stolen from LastPass users, according to a recent report. Cybersecurity investigator ZachXBT claims that hackers have made off with an astonishing $5.36 million in just two days.
The alleged theft is reportedly linked to the 2022 data breach incident involving the password management company’s developer account. The hack initially seemed to involve only minor access to LastPass’ source code and proprietary technical information, but a subsequent investigation revealed that attackers had accessed and decrypted storage volumes from a third-party cloud-based storage service.
This compromised backup storage contained sensitive user data, including vault data backups, which has now led to the massive theft. It appears that hackers have used stolen passwords to raid users’ crypto accounts, further emphasizing the importance of strong master passwords and regular password changes.
LastPass CEO Karim Toubba initially downplayed the severity of the breach, stating that only “portions of source code and some proprietary LastPass technical information” was accessed. However, four months into the investigation, it became clear that the hacker had much more extensive access to sensitive data.
In response to the latest report, LastPass has urged users with weak master passwords to reevaluate their password security, advising those who have stored site passwords in LastPass to change them and minimizing risk by doing so.
Source: www.forbes.com