Skip to main content
Netherlands News in English

Main navigation

  • Top stories
  • Health
  • Crime
  • Politics
  • Business
  • Tech
  • Culture
  • Sports
  • Weird
  • 1-1-2
Image
LastPass
LastPass - Credit: sharafmaksumov / DepositPhotos - License: DepositPhotos
Crime
LastPass
password manager
hack
follow the money
Friday, 10 February 2023 - 20:05

Share this article:

Millions of passwords stolen from LastPass earlier than company disclosed: Report

A hacker stole a file from password manager LastPass that contained the passwords of 30 million users and 85,000 companies. LastPass reported on December 22 that the hacker gained access to sensitive information, but the theft happened months earlier, Follow the Money (FTM) reported.

The hacker copied a database from LastPass. “This is potentially one of the most valuable stolen databases of all time: users - and there are millions of them - have often stored dozens of passwords,” FTM said.

The password manager hasn’t been very forthcoming with information about the hack, despite reporting on it four times. In August, CEO Karim Toubba said a hacker gained access to the company’s development space through an employee’s account. According to Toubba, the hacker’s activities were “limited,” and LastPass customers didn’t have to worry or take any action.

In mid-September, LastPass said that an internal investigation revealed the hacker had access to its system for four days but didn’t do anything serious. End-November, the company reported that the cyberattack was somewhat serious after all - the hacker had accessed “certain elements of client information.” But LastPass insisted that there was no reason to worry.

And then, on December 22, three days before Christmas, LastPass announced that the hacker stole password vaults and copied company names, usernames, billing addresses, email addresses, phone numbers, and IP addresses.

Still, LastPass insisted that there was no major cause for concern. As long as customers had a good master password, their passwords were safe, the company said. Cracking a 12-character password would take millions of years using “generally available technology,” LastPass said.

Ethical hacker Ricky Gevers was flabbergasted by the LastPass communications about this hack. “It seems to say: everything is safe, don’t worry,” Gevers told FTM. “That’s what I believed, as did many other people. But if you look closer, it says something else.” If the hacker cracked your master password, they had access to all the passwords you saved with the password manager.

The hacker didn’t need a private key, which customers are supposed to keep on their own devices. And unlike what many users thought, their personal password vault was not a fully encrypted folder but a text document with a few encrypted fields, according to FTM.

FTM also pointed out that by still claiming that the passwords are safe if people used a good master password, LastPass is shifting the responsibility to its users. All is well as long as YOU made sure your master password was secure. If the hacker got hold of your passwords, you should have had a better master password, is the message.

According to the investigative journalists at FTM, services designed to make devices safer are remarkably often unsafe, usually because they prioritize convenience over security. Consumers forget that their data is extremely valuable. There’s a reason that “if it’s free, you are the product” has become a cliche.

And password managers are wonderful tools for profiling users, Bart Jacobs, professor of privacy and identity at Radboud University, said to FTM. “The information about who logs in to which website and when is worth money,” Jacobs said. And that is precisely the information that is unencrypted in the LastPass vault. “

LastPass now seems willing to provide further information about the hack to users, but only in a physical meeting, and if the invitees sign a nondisclosure agreement beforehand, FTM reports based on an email sent to a Dutch IT manager.

More like this

Image
A Dutch police badge lying on a desk with a police officer typing on a computer in the background
Police warned about security hole used by Russian hackers in major theft of police data
Image
Odido's headquarters building in The Hague. Undated
Odido only noticed theft of 6.2 million people’s data when hackers informed them
Image
Bored students in a lecture hall
Company behind Canvas makes deal with hackers; Says stolen data was destroyed
Image
Vrije Universiteit Amsterdam
Hackers again access universities' Canvas app, threatening to publish student data
Make NL Times your top Google source

Follow us:

Latest stories

  • Archeologists find over 3,000 historical objects in Drenthe stream valley
  • Dutch-led proposal urges phased EU benefits and longer transitions for new members
  • Cabinet explores allowing pepper spray for women in high-risk situations
  • Dutch foundation starts mass claim against Snapchat over “addictive design”
  • AI helps organizations be more efficient, but not necessarily more productive: TNO

Top stories

  • Lightning strike halts train services between Amsterdam, Schiphol and Utrecht
  • Netherlands 17th on Global Peace Index in an increasingly unsafe world
  • Falling tree kills driver, hail destroys campsite in Noord-Brabant; More storms today
  • Dutch home prices won't rise further this year: Rabobank
  • New national siren system to be developed as Netherlands keeps air raid alerts

© 2012-2026, NL Times, All rights reserved.

Footer menu

  • Change Privacy Settings
  • Privacy Policy
  • Contact
  • Partner Content