LastPass Hackers Breach Company's Password Vault. Is Your Data At Risk? Further investigation into the first LastPass hacking incident, which occurred in 2022, revealed that the hackers obtained access to corporate files.

By Madeline Garfinkle Edited by Jessica Thomas

Opinions expressed by Entrepreneur contributors are their own.

The password manager LastPass has announced new details about a hacking incident that occurred in August 2022.

At the time, LastPass said that although an "authorized party" gained entry to its system, no evidence was found that the hackers obtained user data. Now, evidence has emerged that the hackers appear to have gained access to an employee's home computer and infiltrated a "shared cloud-storage environment," which "initially made it difficult for investigators to differentiate between threat actor activity and ongoing legitimate activity."

Related: Apple to Roll Out First of Its Kind Technology to Protect Users from Hackers, Spyware

The hackers gained access to the employee's computer by installing a keylogger into the software to obtain the employee's password for the LastPass corporate vault. Once they were in the vault, they exported entries and shared folders that contained decryption keys needed to unlock cloud-based Amazon S3 buckets with customer vault backups.

LastPass announced key initiatives it is taking to address the "ongoing containment, eradication and recovery activities related to the second incident," including "hardening to security" of employees' resources and home networks.

Related: Hackers Steal $620 Million in Massive Gaming Crypto Heist

With so much of life requiring passwords for day-to-day functions — from email to apps — LastPass was founded to help individuals navigate all their passwords in one secure place.

Is your data at risk?

GoTo, LastPass' parent company, announced in January that it will inform individuals if their data has been breached and provide "actionable steps" to ensure greater security for their accounts.

Although it's still unclear how many users were affected by the hack, Kiplinger suggests it's better to be safe than sorry and take action immediately by changing important passwords, using websites like HaveIBeenPwned.com or even switching password managers.

Madeline Garfinkle

News Writer

Madeline Garfinkle is a News Writer at Entrepreneur.com. She is a graduate from Syracuse University, and received an MFA from Columbia University. 

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Leadership

7 Telltale Signs of a Weak Leader

Whether a bully or a people pleaser who can't tell hard truths, poor leadership takes many forms.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for entrepreneurs to pursue in 2025.

Business News

'Everyone Can Profit From It': What Is DeepSeek? China's 'Cheap' to Make AI Chatbot Climbs to the Top of Apple, Google U.S. App Stores

DeepSeek researchers claim it was developed for less than $6 million, a contrast to the $100 million it takes U.S. tech startups to create AI.

Business News

Elon Musk's DOGE Is Hiring People Eager to 'Work Long Hours' to Eliminate 'Waste, Fraud and Abuse' in the Government. Here's How to Apply.

The Department of Government Efficiency is hiring U.S. citizens to help cut spending and headcounts in the federal government.

Business News

'I Love Doing Product Reviews': Bill Gates Stepped Down from Microsoft in 2020, But Admits He Still Spends 15% of His Time Working at the Company

In a new interview with the Wall Street Journal, Gates also said he is still close with Microsoft's CEO Satya Nadella.

Leadership

Strong Leaders Thrive in Complexity — Here Are 5 Leadership Level-Ups for 2025

Leadership isn't static. It's a journey of continual learning and evolution. Here are some lessons for leaders this year.