On 27 February 2023 LastPass published an account connecting two incidents. The second began with the targeting of a senior DevOps engineer — one of a small number with access to decryption keys for vault backups — through their personal home computer.
Reporting of the account describes an unpatched vulnerability in media server software running on that machine, used to install a keylogger which captured the engineer’s master password after they authenticated with multi-factor authentication. Attackers then reached cloud storage holding encrypted customer vault backups and related data.
The Boundary Was Never Where The Diagram Said
This desk has filed a great many incidents where the route in was a supplier, a contractor or an outsourcer. This one is smaller and stranger: the route in was a piece of consumer software on a machine the company did not own, could not patch and had no visibility of.
Four people held the keys. That concentration is defensible security design — the fewer holders the better — right up to the point where it means compromising one specific person is sufficient.
Multi-Factor Was Present And Irrelevant
The engineer authenticated correctly. The keylogger recorded what was typed and the attacker used it. A second factor proves the person is present at login; it says nothing about whether the machine they are present on is trustworthy.
The corpus records the same limit at 23-0104, at 25-0813 where an attacker registered their own MFA device after phishing a one-time code, and at 23-0913 where a synced authenticator collapsed two factors into one.
Encrypted Backups Are A Time Problem
What was taken was encrypted, with the strength of that protection depending on each customer’s own master password. That makes the exposure a function of password quality and of how long an attacker is willing to wait.
It is the only file in this database where the desk cannot state whether the harm has happened yet. That is not a gap in reporting; it is the nature of stolen ciphertext.
Built on contemporaneous reporting of LastPass’s February 2023 account linking the two incidents, and on independent analysis of that account. The targeting of a DevOps engineer through a personal home computer, the unpatched media server software, the keylogger and the access to encrypted vault backups are as described in the company’s account and reported. This desk has not reviewed LastPass’s notifications to customers. No count of affected customers is asserted; the company did not publish one in a form this desk can carry. No CVE for the media server software is recorded here because the identification appears in reporting rather than in the company’s own statement. Graded high on the account as published. Corrections: corrections@forensicpost.com.