Dear valued customer,
In keeping with our commitment to transparency, we wanted to inform you of a security incident that our team is currently investigating.
We recently detected unusual activity within a third-party cloud storage service, which is currently shared by both LastPass and its affiliate, GoTo. We immediately launched an investigation, engaged Mandiant, a leading security firm, and alerted law enforcement.
We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information. Our customers’ passwords remain safely encrypted due to LastPass's Zero Knowledge architecture.
We are working diligently to understand the scope of the incident and identify what specific information has been accessed. As part of our efforts, we continue to deploy enhanced security measures and monitoring capabilities across our infrastructure to help detect and prevent further threat actor activity. In the meantime, we can confirm that LastPass products and services remain fully functional. As always, we recommend that you follow our best practices around the setup and configuration of LastPass, which can be found here.
As is our practice, we will continue to provide updates as we learn more. Please visit the LastPass blog for the latest information related to the incident: https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/.
We thank you for your patience while we work through our investigation.
Sincerely,
The Team at LastPass | 尊敬的客户。
本着我们对透明度的承诺,我们想告知您一个安全事件,我们的团队目前正在调查。
我们最近在第三方云存储服务中发现了不寻常的活动,目前LastPass和它的附属公司GoTo都在使用这项服务。我们立即展开了调查,聘请了领先的安全公司Mandiant,并通知了执法部门。
我们已经确定,一个未经授权的一方,利用2022年8月事件中获得的信息,能够获得我们客户信息的某些内容。由于LastPass的零知识架构,我们客户的密码仍然被安全加密。
我们正在努力了解该事件的范围,并确定哪些具体信息被访问。作为我们努力的一部分,我们继续在我们的基础设施中部署增强的安全措施和监控能力,以帮助检测和防止威胁者的进一步活动。同时,我们可以确认,LastPass的产品和服务仍然完全正常。一如既往,我们建议你遵循我们关于LastPass的设置和配置的最佳实践,可以在这里找到。
按照我们的惯例,我们将继续提供更多的更新。请访问LastPass博客,了解与该事件有关的最新信息:https://blog.lastpass.com/2022/1 ... -security-incident/。
我们感谢您在我们的调查过程中保持耐心。
真诚的。
LastPass的团队 |