Desk live·
ForensicPost
Cloud/Identity/File 23-0227

LastPass Says a Keylogger on an Engineer’s Home Computer Reached Its Vault Backups

One of four engineers with vault decryption access ran a media server at home with a known unpatched flaw. A keylogger captured the master password after multi-factor authentication, and the corporate boundary turned out to run through a domestic living room.

Constructed geometry · not a chart of case data
TargetLastPass
ActorUnattributed
D. Kennedy12 min readConfidence: high2 sources reviewed

On 27 February 2023 LastPass published an account connecting two incidents. The second began with the targeting of a senior DevOps engineer — one of a small number with access to decryption keys for vault backups — through their personal home computer.

Reporting of the account describes an unpatched vulnerability in media server software running on that machine, used to install a keylogger which captured the engineer’s master password after they authenticated with multi-factor authentication. Attackers then reached cloud storage holding encrypted customer vault backups and related data.

The Boundary Was Never Where The Diagram Said

This desk has filed a great many incidents where the route in was a supplier, a contractor or an outsourcer. This one is smaller and stranger: the route in was a piece of consumer software on a machine the company did not own, could not patch and had no visibility of.

Four people held the keys. That concentration is defensible security design — the fewer holders the better — right up to the point where it means compromising one specific person is sufficient.

Multi-Factor Was Present And Irrelevant

The engineer authenticated correctly. The keylogger recorded what was typed and the attacker used it. A second factor proves the person is present at login; it says nothing about whether the machine they are present on is trustworthy.

The corpus records the same limit at 23-0104, at 25-0813 where an attacker registered their own MFA device after phishing a one-time code, and at 23-0913 where a synced authenticator collapsed two factors into one.

Encrypted Backups Are A Time Problem

What was taken was encrypted, with the strength of that protection depending on each customer’s own master password. That makes the exposure a function of password quality and of how long an attacker is willing to wait.

It is the only file in this database where the desk cannot state whether the harm has happened yet. That is not a gap in reporting; it is the nature of stolen ciphertext.

How we reported this

Built on contemporaneous reporting of LastPass’s February 2023 account linking the two incidents, and on independent analysis of that account. The targeting of a DevOps engineer through a personal home computer, the unpatched media server software, the keylogger and the access to encrypted vault backups are as described in the company’s account and reported. This desk has not reviewed LastPass’s notifications to customers. No count of affected customers is asserted; the company did not publish one in a form this desk can carry. No CVE for the media server software is recorded here because the identification appears in reporting rather than in the company’s own statement. Graded high on the account as published. Corrections: corrections@forensicpost.com.

Sources
  1. LastPass Hack: Engineer’s Failure to Update Plex Software Led to Massive Data BreachThe Hacker News
  2. LastPass breach timeline: How a monthslong cyberattack unraveledCybersecurity Dive
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary