Forum Moderators: open

Message Too Old, No Replies

LastPass: Unusual Attempted Login Activity

         

engine

5:05 pm on Dec 29, 2021 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



LastPass users were reporting attempted login activity, however, according to LastPass VP of Engineering, Gabor Angyal, no user accounts were compromised. The explanation on LastPass blog says,
Our initial findings led us to believe that these alerts were triggered in response to attempted “credential stuffing” activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained from third-party breaches related to other unaffiliated services. We quickly worked to investigate this activity and, at this time, have no indication that any LastPass accounts were compromised by an unauthorized third-party as a result of these credential stuffing attempts, nor have we found any indication that user’s LastPass credentials were harvested by malware, rogue browser extensions, or phishing campaigns.


[blog.lastpass.com...]