Re: LastPass Vault Breached via Employee's Home Computer

peter <[email protected]> Fri, 10 Mar 2023 14:30:56 +0100
Newsgroups alt.privacy.anon-server,alt.computer.security
Organization Tweak
Message-ID <[email protected]>
Hi Mike,

have you read anything about an login attempt generating a MFA approve 
prompt on the employees MFA device?





On 3/1/23 03:04, [email protected] wrote:
> https://pjmedia.com/news-and-politics/gregbyrnes/2023/02/28/lastpass-vault-breached-via-employees-home-computer-giving-keys-to-the-kingdom-to-hackers-n1674308
> 
> "Millions of LastPass users may be at risk after a major breach of the
> home computer of one of their top employees. This employee was only
> one of four people in the company with access to their corporate
> vault. The breach may have come through a home Plex media account,
> according to Ars Technica*, and appears to have been perpetrated by
> the same hackers who breached LastPass security on a smaller scale
> last August. At about the same time, Plex’s security was also
> breached."
> 
> *https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/
> 
> This is wjy I don't use password mangagers.  I keep my
> passwords/phrases in a PGP file on my comp.
> Yeah, I gotta copy paste after opening the PGP, but it is safer than
> using password "protector" dumbware like LastPass.
> 
> 
> 
>