Desk live·
ForensicPost
Breaches/Concentration/File 22-0825

LastPass Developer Breach Took 14 Repositories Four Months Before the Vault Theft

One developer account, four days, fourteen source code repositories and the technical documentation of how LastPass protects its production backups. The company said no vaults were touched. It was true, and four months later it did not matter.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetLastPass
ActorUnattributed
S. Rosler11 min readConfidence: high3 sources reviewed

In August 2022 an unauthorised party reached portions of the LastPass development environment through a single compromised developer account. Reporting describes activity limited to a four-day window, an AWS GuardDuty alert on 11 August, and public disclosure on 25 August.

What was taken is reported as 14 source code repositories, technical documentation, and an encrypted copy of the key protecting production database backups in cloud storage — which the attacker was not in a position to decrypt. The company stated that no customer data and no encrypted vaults were accessed.

Severity Cannot Be Scored On The Day

Every statement the company made in August appears to have been accurate. No vaults, no customer data, a bounded four-day window, detection by an automated alert.

In December the same company disclosed that attackers had taken encrypted vault backups for the entire customer base, using information from this intrusion to get there — the file at 22-1222. The August incident was not a small incident that grew. It was reconnaissance whose value was realised later, and no scoring scheme this desk uses could have registered that at the time.

The Map Is The Asset

Source code and internal technical documentation describe where things are kept, how they are protected, which keys guard which stores and what the recovery paths are.

We filed stolen code as a diffuse, uncountable harm at 22-0322. This is the concrete version: the material was used. It also explains why the encrypted key mattered even though it could not be decrypted — knowing that a specific key protects a specific backup store tells an attacker exactly which human being to go after, which is what happened.

One Developer Account

The reported entry was a single compromised developer account in the development environment.

We keep arriving here — 22-1101, where a phished GitHub account reached 130 repositories; 22-0412, where a token cloned private code across dozens of organisations; 22-0524, where a synced browser password reached a corporate VPN. Development environments hold the description of production, and they are consistently governed as though they hold nothing.

How we reported this

Compiled from LastPass’s own disclosures and contemporaneous reporting, listed below. Some of this detail was published by the company later, in the course of describing the December incident, and is dated to that account rather than to August. The connection to the December compromise is as stated by the company and is filed separately at 22-1222. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. LastPass developer systems hacked to steal source codeBleepingComputer
  2. LastPass breach: Source code, proprietary tech info stolenHelp Net Security
  3. LastPass Says Source Code Stolen in Data BreachSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary