Password managers are one of the most useful tools for protecting yourself on the internet: they keep all your passwords in a single encrypted place so you don’t have to remember each one. But what happens when the security company itself suffers an attack? LastPass, one of the most popular password managers in the world with more than 33 million users, has notified its customers that hackers have stolen their personal data. It was not a direct attack on LastPass, but on Klue, an external company that does market research for them. The cybercriminals got into Klue’s systems and took names, phone numbers, email addresses and the history of customer service conversations. What is worrying is not just the data leak, but LastPass’s track record. In 2022 they already suffered a massive theft in which the attackers took their users’ password vaults. Although they were encrypted, many of those passwords ended up being deciphered because their owners had used weak master passwords, which led to cryptocurrency thefts and other problems. This new breach, which occurred through Klue, shows that security depends not only on one company, but on the entire chain of providers that surround it. The lesson for the average user: choose your password manager well, use a truly secure master password, and always enable two-step verification. — Marta, for intermittent intelligence.
LastPass is in the news again: customer data stolen through an external provider






