LastPass disclosed that attackers expanded an initial August 2022 development-environment breach into a broader compromise that reached customer vault backups and account data. According to the company and subsequent reporting, the intruders used source code and technical information stolen in the first intrusion, combined with intelligence from a separate third-party breach, to target a DevOps engineer with access to decryption keys and AWS resources. The attackers compromised the engineer’s home computer through a vulnerable media software package, installed a keylogger, captured the employee’s master password after MFA, and then accessed the engineer’s corporate vault and shared folders.
The stolen material included encrypted secure notes containing credentials and decryption keys for AWS S3 production backups, other cloud storage resources, and related database backups, allowing access to a separate cloud storage environment. LastPass said the attackers copied customer account information and metadata, plus backups of customer vault data containing unencrypted website URLs and AES-256-encrypted usernames, passwords, secure notes, and form data; later guidance urged users with weak master passwords to change stored credentials. The fallout triggered lawsuits, regulatory scrutiny including action by the UK ICO, and ongoing concern that weak master passwords could allow criminals to crack vault contents offline.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Security researchers and incident responders warned that criminals appeared to be cracking data stolen in the LastPass breach, particularly where users had weak or less-protected master passwords. The concern marked a significant downstream impact from the 2022 theft of encrypted vaults.
LastPass issued a detailed security update describing how the attackers targeted a DevOps engineer, exported vault entries containing cloud access keys, and reached AWS-hosted backups. The company also recommended that customers with weak master passwords change passwords stored in LastPass.
A proposed class-action lawsuit was filed against LastPass following disclosure that attackers stole customer vault backups and account information. The suit alleged the company failed to adequately protect user data.
LastPass announced that attackers had accessed a cloud storage environment and copied customer account information and metadata, along with backups of customer vault data. The company said the stolen vault backups included unencrypted website URLs and encrypted usernames, passwords, secure notes, and form data.
LastPass said AWS GuardDuty alerts identified unusual behavior when the intruder attempted unauthorized actions using cloud IAM roles, helping reveal the broader compromise of backup-related resources.
The attacker activity ran through October 26, 2022, during which the intruders used stolen vault entries and decryption material to access a separate cloud-based storage environment containing production backups and related cloud resources.
During the follow-on intrusion, attackers exploited vulnerable third-party software on a LastPass DevOps engineer's home computer, installed a keylogger, captured the engineer's master password after MFA, and accessed the engineer's corporate vault and shared folders.
LastPass disclosed that an attacker had compromised a developer account and stolen source code and proprietary technical information from its development environment. This was the company's first public notice of the 2022 incident.
According to LastPass and later reporting, attackers started a follow-on campaign on August 12, 2022 using information stolen from LastPass's earlier development-environment breach, combined with data from a third-party breach, to target a DevOps engineer with access to cloud backup resources.
10 references tracked. Mallory keeps watching after this page renders.
blog.lastpass.com
Open sourcekrebsonsecurity.com
Open sourcepcmag.com
Open sourcetherecord.media
Open sourceblog.lastpass.com
Open sourcearstechnica.com
Open sourcepcmag.com
Open sourceico.org.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.