LastPass has been hacked again
The company’s announcement
The password storage service, LastPass , has been hacked once again in just a few months.
LastPass says it is investigating a security incident after an ” unauthorized party ” breached its systems on Wednesday and gained access to some customer information. This information was taken from the cloud of a third-party service shared by LastPass and parent company GoTo .
LastPass CEO Karim Toubba said :
We recently spotted a common activity in a cloud service currently shared by both LastPass and its subsidiary, GoTo. We immediately launched an investigation, hired Mandiant, a leading security firm, and notified the authorities.
We have determined that an unauthorized party used information obtained from the first incident in August and was able to access some of our customer information. Our customers’ passwords stay securely encrypted thanks to LastPass’ Zero Knowledge architecture.

The company is working diligently to understand the damage that has been done and has confirmed that its services continue to operate as normal. As always, the company recommends following its best practices for setting up and configuring LastPass, which can be found here.
LastPass was also hacked last August.

