LastPass
Incident posture
Timeline
Summary
In a major data breach at a leading password management provider, threat actors stole encrypted backups of approximately 30 million customer password vaults, exposing more than 25 million users to long-term risk. The attackers first compromised a developer's account to steal internal source code and proprietary technical information, then leveraged credentials obtained during that initial intrusion, combined with a vulnerability in a third-party media software package, to launch a coordinated second attack. By deploying keylogger malware on a senior DevOps engineer's home computer, the threat actor captured the employee's master password and gained access to corporate vaults containing the decryption keys needed to access AWS S3 cloud storage. Once retrieved, the stolen encrypted backups—protected by various AWS encryption methods—were exfiltrated. The incident enabled a multi-year campaign of cryptocurrency theft, with blockchain analysts tracing around $35 million in stolen digital assets to Russian cybercriminals who brute-forced vaults secured by weak or unchanged master passwords.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In August 2022, LastPass disclosed that an unauthorized party had gained access to its development environment through a single compromised developer account. The intrusion, detected after "unusual activity" was observed in the development area of the company's network, resulted in the theft of portions of source code and proprietary technical information. CEO Karim Toubba stated that the incident had been contained, that outside cybersecurity experts had been engaged, and that there was no evidence at that stage of any access to customer data or encrypted password vaults. Because LastPass does not retain copies of users' master passphrases, the company maintained that vault contents remained secure. The breach occurred approximately two weeks before the public disclosure on August 25, 2022, and affected a password manager serving more than 25 million individual users and 80,000 business customers at that time. The initial assessment characterized the incident as limited to internal development resources and not impacting production systems.
A subsequent investigation, supported by Mandiant, revealed that the threat actor had pivoted from the first incident, which concluded on August 12, 2022, into a coordinated second attack spanning August 12, 2022 to October 26, 2022. The actor leveraged information stolen during the first incident, information available from a third-party data breach, and a vulnerability in a third-party media software package. Tactics, techniques, and procedures observed in the second incident differed from those of the first, and the connection between the two was not initially apparent. The actor used valid credentials stolen from a senior DevOps engineer to access a shared cloud-storage environment, making it difficult to distinguish malicious activity from legitimate operations. AWS GuardDuty eventually alerted LastPass to anomalous behavior when the actor attempted to use Cloud Identity and Access Management (IAM) roles for unauthorized activity. The actor had implanted keylogger malware on the DevOps engineer's home computer via the vulnerable media software, capturing the employee's master password after MFA authentication, which granted access to the corporate LastPass vault. From there, the actor exported entries and shared folders containing encrypted secure notes with access and decryption keys needed to reach AWS S3 LastPass production backups and other cloud-based storage resources. These S3 buckets were protected with AWS S3-SSE encryption, AWS S3-KMS encryption, or AWS S3-KMS encryption with customer-provided keys (SSE-C), and required both AWS Access Keys and LastPass-generated decryption keys for access. The second incident exposed backups containing LastPass customer vault data for approximately 30 million users, creating what blockchain analytics firm TRM Labs later described as a "long-tail risk" for more than 25 million users.
In response to the second incident, LastPass carried out extensive containment, eradication, and recovery activities with Mandiant's assistance. The company forensically imaged corporate and personal devices, assisted the affected DevOps engineer with hardening their home network and personal resources, and upgraded the employee to Microsoft's conditional access PIN-matching multifactor authentication via the Microsoft Authenticator application. Critical and high-privilege credentials known to be available to the actor were rotated, with remaining lower-priority items subsequently rotated as well. Certificates obtained by the actor were revoked and re-issued. Within the AWS environment, LastPass analyzed S3 cloud-based storage resources and applied additional hardening measures, including tighter logging and alerting, deactivated prior development IAM users, prevention of long-lived development IAM users, rotated production service IAM user keys with tighter IP restrictions, deletion of obsolete service IAM users, enforcement of IAM resource tagging with periodic reporting, and rotation and deletion of SAML certificates. The company also revised its 24x7 threat detection and response coverage, enabling additional managed and automated services, and developed custom analytics to detect ongoing abuse of AWS resources.
The long-term consequences of the breach emerged over the following years as stolen vault backups were exploited for cryptocurrency theft. TRM Labs traced multiple waves of theft attributing the activity to Russian cybercriminals, noting that vaults protected by weak master passwords could be decrypted offline, creating a multi-year attack window. The firm traced $28 million stolen from 2024 to early 2025 and an additional $7 million taken in September 2025, totaling approximately $35 million, though this was characterized as likely only a fraction of the full amount. Stolen funds from the earlier phase were routed through the now-defunct Cryptomixer.io and off-ramped via Cryptex, a Russia-based exchange sanctioned by OFAC in 2024. In the September 2025 wave, approximately $7 million was traced through Wasabi Wallet, with withdrawals flowing to Audi6, another Russian exchange associated with cybercriminal activity. Funds were converted to fiat currency and withdrawn via exchanges as recently as October 2025. Despite the actors' use of CoinJoin to obfuscate transactions, TRM Labs applied proprietary demixing techniques to match deposits to a specific withdrawal cluster, with blockchain fingerprints and post-mixing intelligence consistently pointing to Russia-based operational control. The "slow-drip wallet draining" over the three years following the breach was enabled by brute-forcing of vaults belonging to users who had not changed their master passwords. In December 2025, the UK's Information Commissioner Office fined LastPass £1.2 million ($1.6 million) for security failings that led to the breach, which impacted an estimated 1.6 million UK users, noting that master passwords were stored locally on customer devices, a factor that limited the potential for threat actors to decrypt customer credentials.
Sources
Sources available to members: 4 sources.