LastPass got hacked again, and this time it affects customers

LastPass got hacked again, and this time it affects customers

A shoe has dropped following LastPass’s August security breach.

Credit: Dreamstime

It's been a rough year for LastPass. Back in August, the popular password manager suffered a security breach, in which the company's developer environment was infiltrated.

At the time, LastPass said that while part of its source code and proprietary technical info were taken, customers were unaffected.

Now the company has experienced a second related hack, this time impacting customers. As reported Wednesday on its blog, LastPass recently detected unusual activity within a third-party cloud storage service.

An investigation has so far revealed that the breach stemmed from knowledge gained during the August 2022 incident, and that certain elements of customers' information have been accessed. Further information is unavailable, as the investigation is still ongoing. LastPass says that customer passwords remain safely encrypted, however.

If you find this news unsettling despite the service earning recommendations (including ours) for its day-to-day experience, your reaction is a fair one.

LastPass has suffered hacks of its service in previous years, with notable incidents including 2015's unauthorised access of user account email addresses, password reminders, and authentication hashes.

Other security lapses include 2017's browser extension vulnerability, which allowed websites to steal passwords. In 2019, the same security researcher who discovered the 2017 issue also discovered another browser extension vulnerability that allowed the last used password to be leaked.

The company has even made communication bumbles, like security alert emails sent to customers unaffected by a credential stuffing attack. Other top-notch password managers haven't reported nearly as many incidents over the years, and if you're so inclined, you can make a switch to one of them pretty easily.

You can also review the security on your LastPass account, making sure it falls in line with best practices, including the use of a strong password, enabling two factor authentication, and keeping a close eye on authorised devices.

But as discomforting as this transparency may be, the underlying issue isn't the general concept of a password manager. They remain a vital part of online security, and you can find ways of making them more comfortable to use, even in the face of security breaches. Don't abandon them outright.

Follow Us

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.


EDGE 2023

EDGE is the leading technology conference for business leaders in Australia and New Zealand, built on the foundations of collaboration, education and advancement.


ARN has celebrated gender diversity and recognised female excellence across the Australian tech channel since first launching WIICTA in 2012, acknowledging the achievements of a talented group of female front runners who have become influential figures across the local industry.

ARN Innovation Awards 2023

Innovation Awards is the market-leading awards program for celebrating ecosystem innovation and excellence across the technology sector in Australia.

Show Comments