Connect with us

Technologies

Here’s What LastPass Subscribers Need to Do After the Latest Breach

If you’re a LastPass subscriber, you need to start looking for a different password manager immediately.

LastPass, one of the world’s most popular password managers, is yet again the subject of intense scrutiny after its latest security breach. Just before Christmas, LastPass CEO Karim Toubba revealed in a blog post that a security incident the company first disclosed in August had eventually led to an unauthorized party stealing customer account information and vault data. This is the latest in a lengthy string of security incidents involving LastPass that date back to 2011. It’s also the most alarming.

An unauthorized party now has access to unencrypted subscriber account information like LastPass usernames, company names, billing addresses, email addresses, phone numbers and IP addresses, according to Toubba. That same unauthorized party also has a copy of customer vault data, which includes unencrypted data like website URLs and encrypted data like the usernames and passwords for all the sites customers have saved in their vaults. If you’re a LastPass subscriber, the severity of this breach should have you looking for a different password manager.

What should LastPass subscribers do?

The company didn’t specify how many users were affected by the breach, and LastPass didn’t respond to CNET’s request for additional comment on the breach. But if you’re a LastPass subscriber, you need to operate under the assumption that your user and vault data are in the hands of an unauthorized party with ill intentions. Though the most sensitive data is encrypted, the problem is that the threat actor can run “brute force” attacks on those stolen local files. LastPass estimates it would take “millions of years” to guess your master password — if you’ve followed its best practices.

If you haven’t — or if you just want total peace of mind — you’ll need to spend some serious time and effort changing your individual passwords. And while you’re doing that, you’ll probably want to transition away from LastPass, too.

With that in mind, here’s what you need to do right now if you’re a LastPass subscriber:

1. Find a new password manager. Given LastPass’ history with security incidents and considering the severity of this latest breach, now’s a better time than ever to seek an alternative.

2. Change your most important site-level passwords immediately. This includes passwords for anything like online banking, financial records, internal company logins and medical information. Make sure these new passwords are strong and unique.

3. Change every single one of your other online passwords. It’s a good idea to change your passwords in order of importance here too. Start with changing the passwords to accounts like email and social media profiles, then you can start moving backward to other accounts that may not be as critical.

4. Enable two-factor authentication wherever possible. Once you’ve changed your passwords, make sure to enable 2FA on any online account that offers it. This will give you an added layer of protection by alerting you and requiring you to authorize each login attempt. That means even if someone ends up obtaining your new password, they shouldn’t be able to gain access to a given site without your secondary authenticating device (typically your phone).

5. Change your master password. Though this doesn’t change the threat level to the stolen vaults, it’s still prudent to help mitigate the threats of any potential future attack — that is, if you decide you want to stay with LastPass.

LastPass alternatives to consider

  • Bitwarden: CNET’s top password manager is a highly secure and open-source LastPass alternative. Bitwarden’s free tier allows you to use the password manager across an unlimited number of devices across device types. Read our Bitwarden review.
  • 1Password: Another excellent password manager that works seamlessly across platforms. 1Password doesn’t offer a free tier, but you can try it for free for 14 days.
  • iCloud Keychain: Apple’s built-in password manager for iOS, iPadOS and MacOS devices is an excellent LastPass alternative available to Apple users at no additional cost. iCloud Keychain is secure and easy to set up and use across all of your Apple devices. It even offers a Windows client, too, with support for Chrome and Edge browsers.

How did it come to this?

In August 2022, LastPass published a blog post written by Toubba saying that the company “determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information.”

At the time, Toubba said that the threat was contained after LastPass “engaged a leading cybersecurity and forensics firm” and implemented “enhanced security measures.” But that blog post would be updated several times over the following months as the scope of the breach gradually widened.

On Sept. 15, Toubba updated the blog post to notify customers that the company’s investigation into the incident had concluded.

“Our investigation revealed that the threat actor’s activity was limited to a four-day period in August 2022. During this timeframe, the LastPass security team detected the threat actor’s activity and then contained the incident,” Toubba said. “There is no evidence of any threat actor activity beyond the established timeline. We can also confirm that there is no evidence that this incident involved any access to customer data or encrypted password vaults.”

Toubba assured customers at the time that their passwords and personal data were safe in LastPass’s care.

However, it turned out that the unauthorized party was indeed ultimately able to access customer data. On Nov. 30, Toubba updated the blog post once again to alert customers that the company “determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information.”

Then, on Dec. 22, Toubba issued a lengthy update to the blog post outlining the unnerving details regarding precisely what customer data the hackers were able to access in the breach. It was then that the full severity of the situation finally came to light and the public found out that LastPass customers’ personal data was in the hands of a threat actor and all of their passwords were at serious risk of being exposed.

Still, Toubba assured customers who follow LastPass’s best practices for passwords and have the latest default settings enabled that no further action on their part is recommended at this time since their “sensitive vault data, such as usernames and passwords, secure notes, attachments, and form-fill fields, remain safely encrypted based on LastPass’ Zero Knowledge architecture.”

However, Toubba warned that those who don’t have LastPass’s default settings enabled and don’t follow the password manager’s best practices are at greater risk of having their master passwords cracked. Toubba suggested that those users should consider changing the passwords of the websites they have stored.

What does all of this mean for LastPass subscribers?

The initial breach ended up allowing the unauthorized party to access sensitive user account data as well as vault data, which means that LastPass subscribers should be extremely concerned for the integrity of the data they have stored in their vaults and should be questioning LastPass’s capacity to keep their data safe.

If you’re a LastPass subscriber, an unauthorized party may have access to personal information like your LastPass username, email address, phone number, name and billing address. IP addresses used when accessing LastPass were also exposed in the breach, which means that the unauthorized party could also see the locations from which you used your account. And because LastPass doesn’t encrypt users’ stored website URLs, the unauthorized party can see all of the websites for which you have login information saved with the password manager (even if the passwords themselves are encrypted).

Information like this gives a potential attacker plenty of ammunition for launching a phishing attack and socially engineering their way to your account passwords. And if you have any password reset links stored that may still be active, an attacker can easily go ahead and create a new password for themselves.

LastPass says that encrypted vault data like usernames and passwords, secure notes and form-filled data that was stolen remains secured. However, if an attacker were to crack your master password at the time of the breach, they would be able to access all of that information, including all the usernames and passwords to your online accounts. If your master password wasn’t strong enough at the time of the breach, your passwords are especially at risk of being exposed.

Changing your master password now will, unfortunately, not help solve the issue because the attackers already have a copy of your vault that was encrypted using the master password you had in place at the time of the breach. This means the attackers essentially have an unlimited amount of time to crack that master password. That’s why the safest course of action is a site-by-site password reset for all of your LastPass-stored accounts. Once changed at the site level, that would mean the attackers would be getting your old, outdated passwords if they managed to crack the stolen encrypted vaults.

For more on staying secure online, here are data privacy tips digital security experts wish you knew and browser settings to change to better guard your information.

Technologies

Bessent tells Russia no economic relief will come until Ukraine war ends as Europe isolates Moscow at G20

U.S. Treasury Secretary Scott Bessent told Russian Finance Minister Anton Siluanov that no economic relief or new agreements can be made while the war in Ukraine continues, during a rare G20 meeting in Asheville, North Carolina.

U.S. Treasury Secretary Scott Bessent reportedly told Russian Finance Minister Anton Siluanov that no sanctions relief or new agreements with Moscow were possible, as long as the war in Ukraine continues.

The two officials met on the sidelines of a Group of 20 finance leaders gathering in Asheville, North Carolina.

Bessent’s remarks came as Siluanov’s first in-person appearance at the summit since Russia’s invasion of Ukraine in 2022 drew objections from other European leaders. European governments have planned to expand sanctions to further squeeze Moscow’s economy and finances.

The rare meeting underscored Washington’s willingness to reopen high-level diplomatic channels with Moscow, even as European allies have intended to keep the nation isolated while the war continues.

Bessent made it clear to Siluanov that “nothing is possible until the war is over,” when the Russian minister brought up other areas of mutual interest, Reuters reported.

The meeting centered on President Donald Trump’s peace plan for Ukraine and economic growth, according to Axios, while Russia’s finance ministry described the discussions as covering financial cooperation between the two nations within the G20 framework.

Russia’s surprise return to the table sparked dismay among European officials, who opposed appearing with Siluanov in the traditional G20 photo, which was ultimately taken without the Russian minister.

Continue Reading

Technologies

Venezuela grants U.S.-backed oil firm NABEP 100-year concessions for 17 oil fields, White House says

Venezuelan interim authorities have granted North American Blue Energy Partners 100-year concessions for 17 oil fields, White House says.

Venezuelan interim authorities have granted U.S.-backed North American Blue Energy Partners, or NABEP, 100-year concessions for 17 oil fields, with proven reserves of about 65 billion barrels, the White House said on Monday.

NABEP is the second-largest private oil producer in Venezuela. The company has granted the U.S. Department of War’s Office of Strategic Capital an equity stake of 35% in its corporate parent, according to the White House, representing up to “hundreds of billions in value and dividends for the United States.”

President Donald Trump announced Friday a deal with Caracas that would give the U.S. majority control over 65 billion barrels, or about 20% of the South American nation’s massive oil reserves. The U.S. had about 46 billion barrels in proven oil reserves as of end-2024, according to official figures.

In a fact sheet published Monday evening stateside, the U.S. government said it would enjoy the right to purchase, at production cost, a guaranteed 20% of the off-take from all current and future fields NABEP will operate, as part of an effort to facilitate refilling the U.S. strategic petroleum reserves.

The U.S. government also has the “right of first refusal” to purchase the remaining 80% of NABEP’s production, making Washington the prioritized buyer for its energy reserves.

Analysts, however, remained skeptical that the landmark oil deal could meaningfully boost the U.S. energy production and bring down gas prices for Americans in the near term. Huge investments are needed to extract the rich resources in Venezuela, whose oil output remains at a fraction of its capacity due to decades of mismanagement, lack of investment and sanctions.

NABEP also planned to invest up to $100 billion in new oil infrastructure in Venezuela to scale production, the White House said. Under the agreement, the company is expected to pay $200 billion in royalty and tax payments to Venezuelan governments over the first 25 years.

Continue Reading

Technologies

Tanker hit in Strait of Hormuz, sparking escalation fears as Trump pledges severe response to Iran

A tanker was struck by three unidentified projectiles in the Strait of Hormuz on Monday, raising concerns about a potential escalation in the Middle East conflict, as President Trump vowed a severe response to Iran.

A tanker was struck by three unidentified projectiles while navigating the Strait of Hormuz on Monday, raising concerns that the Middle East conflict could flare up again.

The vessel was traveling in the southern shipping lane near the Omani coast, according to a Tuesday statement from the UK Maritime Trade Operations agency, posted in Asia time. No injuries were reported.

Iran launched an attack on two U.S. bases in Jordan on Monday in retaliation for America’s strike on its Larak Island. U.S. forces targeted two Iranian rocket launchers on Larak Island on Sunday, reportedly killing three, claiming that Tehran intended to fire rockets carrying sea mines into the Strait of Hormuz.

The small island, situated in the Strait of Hormuz, has been a critical military and shipping control point for Iranian forces, enabling them to maintain tight control over vessel traffic through one of the world’s most vital maritime routes.

The tit-for-tat hostilities marked the first time in over a month that the U.S. and Iran have exchanged strikes.

While neither side appears to be seeking a return to full-scale war, both have signaled readiness to respond to further attacks. “We are going to hit them hard,” President Donald Trump told Fox News on Monday, stating that “there will be a response” to Iran’s attacks on U.S. military bases in the region.

Analysts largely view the U.S. attack on Larak Island as an attempt to break a deadlock rather than a shift in strategy. “By targeting the launchers rather than broader Iranian military infrastructure, the U.S. seems to be punishing a specific behavior rather than, at least for now, expanding its war aims,” said Ali Vaez, deputy program director at International Crisis Group.

“It is enforcing the blockade,” said Jason Brodsky, policy director of United Against Nuclear Iran, adding that the Trump administration’s goal is to further degrade Tehran’s ability to mine the Strait of Hormuz, while focusing on economic coercive measures as the midterm elections approach.

Washington has intensified pressure to squeeze Iran’s already weakened economy with “secondary sanctions” that penalize nations and businesses buying Iranian crude. U.S. Treasury Secretary Scott Bessent said Monday, on the sidelines of the Group of 20 finance ministers’ gathering, that Iran was “lashing out kinetically” because the new sanctions were taking a toll on its economy.

Speaking from the Oval Office on Monday, Trump reportedly said that Iran’s financial systems, armed forces, and governing body have largely degraded. “It doesn’t mean we won’t smack them to see what happens,” the president said.

The war, now entering its seventh month, has disrupted global energy supplies and sent shockwaves through global financial markets. International oil benchmark Brent surged past $90 a barrel amid renewed hostilities and last traded at $91.08 on Tuesday. U.S. West Texas Intermediate futures added less than 1% to $86.65 per barrel.

“This is fundamentally an endurance contest,” said Brodsky, as Trump has demonstrated an “unpredictability” that should concern the Iranians, and Tehran may lash out more aggressively militarily as economic pressure mounts.

Continue Reading

Trending

Copyright © Verum World Media