LastPass is being sued following major cyberattack

LastPass
(Image credit: LastPass)

LastPass has been threatened with legal action following a months-long data breach that began in August 2022 and led to the leak of potentially millions of users' private information.

A statement by the password manager CEO Karim Toubba at that time claimed a lack of evidence that any customer data was at risk, though a leading cybersecurity and forensics firm was deployed. 

A December 2022 notice announced that “an unknown threat actor accessed a cloud-based storage environment leveraging information obtained from the incident”.

LastPass August 2022 leak

According to the class action complaint filed in a Massachusetts court, names, usernames, billing addresses, email addresses, telephone numbers, and even the IP addresses used to access the service were all made available to wrongdoers. 

The final straw in the hat could have been the leak of customers’ vault data, which includes all manner of information ranging from website usernames and passwords to other secure notes and form data.

According to the lawsuit, “LastPass understood and appreciated the value of this Information yet chose to ignore it by failing to invest in adequate data security measures”.

The case’s plaintiff claims to have invested $53,000 in Bitcoin since July 2022, which was later “stolen” several months later, leading to police and FBI reports. 

More recently, Toubba took to the company’s blog to announce that “some source code and technical information were stolen from [LastPass’s] development environment”, leading to an attack on an employee’s account that saw credentials and keys being stolen. The company has since that it is “decommissioning that environment in its entirety and rebuilding a new environment from scratch.”

While the case plaintiff has demanded a jury trial with regards to the leak and their subsequent losses, it remains to be seen what (if any) action shall be taken against LastPass.

TOPICS
Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Man screaming at computer with TechRadar data privacy week logo next to it.
I almost lost my entire online identity – until one tool made all the difference
Data Breach
US state sues T-Mobile over 2021 data breach which leaked data of millions
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock
Man using iMessage on an iPhone
Apple will finally enable encrypted RCS messages between iOS and Android, and it's about time
Google Messages update
Google Messages could soon follow WhatsApp with an upgrade that makes it much easier to join group chats