Data leak

LastPass 2015 Data Breach β€” Email Addresses, Password Reminders, Authentication Hashes

πŸ“… 2015-06-12 🏒 LastPass password manager user database
Primary Source β†—

Incident Details

On 12 June 2015, LastPass β€” one of the world’s most widely used password managers with tens of millions of users β€” discovered that its network had been compromised and that user data had been accessed. LastPass disclosed the breach on 15 June 2015 in a blog post. Compromised data included email addresses, password reminder hints, per-user server salts, and authentication hashes. Encrypted user vaults were not compromised because they are only stored client-side. LastPass immediately required all users to verify their email addresses before accessing their accounts and prompted users to change their master passwords (particularly for those with weak passwords). LastPass stated that user passwords remained safely encrypted, and that its encryption/hashing measures were sufficient that the vast majority of users should not be at risk if they had strong master passwords. This 2015 breach was followed by more severe subsequent incidents: the August 2022 breach (developer laptop and source code theft) and the December 2022 breach (vault backups and decryption keys stolen through a compromised DevOps engineer’s personal computer). The 2015 incident was the first major public breach of a major password manager and significantly damaged user confidence in password management products generally, highlighting the extreme sensitivity of data held by password managers.

Technical Details

Initial Attack Vector
Unknown attacker compromised LastPass's network and gained access to the LastPass database; specific intrusion vector was not disclosed; the attacker accessed user account email addresses, password reminders, server per-user salts, and authentication hashes
Vendor / Product
LastPass password manager user database

Timeline

  1. 2015-06-12 Breach occurred
  2. 2015-06-15 Publicly disclosed
  3. 2015-06-15 Customers notified