Hackers hit Lastpass again ! This is the second hack in less than a year for the password manager. They would have succeeded in access user data and to steal sensitive information. Despite Lastpass' efforts to enhance security, the hackers managed to find a loophole and to get into the system.
It is important that users take extra steps to ensure that they are protect against computer attacksThe number of these people is constantly increasing.The management of the computer password manager has carried out a investigation to determine if the hackers succeeded or simply attempted to access this sensitive data. The results of this survey will be announced shortly. The platform is keen to reassure its users that their passwords are safe from malicious threats. It has put in place measures to protect personal data against attacks and the fraudulent e-mails. This is yet another blow for LastPass and its parent company Goto. The third-party cloud service has not been named as such, but rumors suggest that it will be Amazon's cloud.
Undisclosed Passwords
On November 30, LastPass said it detected "anomalous activity" at the cloud storage service. The attackers may have accessed customer information but CEO Karim Toubba remains vague. The amount of data involved remains unknown for now.The company would like to reassure its users and states: " Our customers' passwords remain encrypted and secure thanks to the Zero Knowledge architecture ".
GoTo and LogMeIn also hacked?
The breach would actually come from a common storage service to both companies. GoTo, formerly known as LogMeIn acquired LastPass in 2015. As a result, the platform explained that it was also carrying out investigations of its own, as there is no doubt that its own customers (of GoTO and LogMeIn) may also have been affected by the attack. This method ensures that only users can read the information they store in their safes. LastPass also said it has enlisted the help of cybersecurity specialist Mandiantas part of its risk management program and notified law enforcement of the malicious access."As always, we will keep you updated as soon as we know more," she added.Karim Toubba has nevertheless specified via a blog post that :
"customer passwords remain securely encrypted".