Lastpass has had a breach: our recommendations if you are a user

Just a few days before Christmas last year, LastPass revealed that hackers gained access to users’ password vaults.

This sounds pretty serious, we know, but not completely out of nowhere. Back in August 2022, LastPass announced that a hacker had managed to gain access to a developer’s account and had stolen some source code.

At the time, LastPass claimed it had ‘seen no evidence that this incident involved any access to customer data or encrypted password vaults’.

However, just because no evidence was seen doesn’t mean it didn’t happen. 

In fact, just before Christmas, LastPass confirmed that the stolen information had been ‘used to target another employee, obtaining credentials and keys which were used to access and decrypt some storage volumes’.

What this means

First, let’s establish how at-risk you are. If you’re one of the top 100,000 businesses worldwide that use LastPass, a government worker or politician, a journalist or celebrity, a cryptocurrency investor or a person of interest to an authoritarian regime – you will be at greater risk.

Hackers will only gain access to your master password by putting in their time and resources, so this will be a lot more likely if you’re a person of interest to them or part of a large business.

Now, let’s cover what data has been compromised. 

Decrypted customer data:

  • Company names
  • End user names
  • Telephone numbers
  • Email addresses
  • Billing addresses
  • Website URLs from your password vault
  • IP address LastPass was last accessed from

Encrypted customer data:

  • Website usernames and passwords
  • Form-filled data
  • Secure notes

This means hackers now know that you use LastPass and how to contact you, as well as which websites you use. This means you will need to be especially wary of phishing attempts. The hackers could easily impersonate one of the websites you’ve recently visited and send a convincing email to try to coax more information out of you. They may also have access to any password reset links for websites or other sensitive information that you stored in LastPass. 

You might think only the decrypted data is at risk, but if the cybercriminals determine what your master password is, they have access to all of it.

Even if you have 2FA enabled on your LastPass account, it won’t make any difference in this case. Hackers have already gained access and stolen password vault data, so they won’t need to log in to anyone’s account. 

As of 2018, LastPass requires a 12-character minimum for your password. But even this character length doesn’t ensure a secure password.

Additionally, we now know that those who have been with LastPass since before 2018 have not been required to update their master passwords to meet the 12-character requirements. This puts these individuals at much greater risk.

What we recommend you do 

Even if you’re not in one of the most at-risk targets, the sensible thing to do would be to assume the worst. We recommend you migrate away from LastPass to a more trusted and secure password manager. Then you can change all your passwords.

This probably seems like a huge amount of work, with potentially thousands of passwords. But consider the damage that your information leaking could have. It’s worth taking the time to ensure your own peace of mind. Additionally, any business information lost may cause more damage than you could imagine.

Our suggested alternative password manager

We used to be advocates for LastPass, but after this incident, we cannot recommend it anymore. 

Our recommended alternative is Keeper. 

Please note, we have no connection or affiliation to Keeper, but we’re impressed with what we’ve seen.

Keeper has data centres based in the EU and USA to choose from, and it encrypts all vault data, including URLs and metadata, locally on the user’s device. Its cloud does not receive, store or process any plaintext vault information. In comparison, LastPass’ architecture only supports encryption at the vault level—making user information more vulnerable to cyberattacks. 

Keeper has many other features that you can read on their website

On top of these, Keeper has a tool to make the switch from LastPass quick and easy. Here’s a guide on how to make the switch.

In conclusion

Like the National Cyber Security Centre, Securious recommends the use of password managers as a general rule. We have recommended LastPass as a good option in the past, but can no longer maintain that position.

If you do use it, we recommend you take action now to change your LastPass password and all your passwords, just in case the hackers crack access to your account from the stolen encrypted data.

However, we would also recommend migrating from LastPass (you’ll still need to change your individual passwords) to an alternative password manager. We suggest looking at Keeper.

If you need to discuss this further, contact us at info@securious.co.uk