LastPass Discloses Password Vault Breach Details

3 minute read

Published:

LastPass disclosed on December 22, 2022 that an August 2022 security incident — in which an attacker had compromised a developer’s workstation and exfiltrated source code, technical documentation, and internal secrets — had been used as the first stage of a second, larger breach. In the second incident (September through October 2022), the attacker used credentials and keys stolen from a LastPass DevOps engineer’s home computer (compromised through a vulnerable third-party media player with an unpatched remote code execution vulnerability) to access LastPass’s cloud backup storage on Amazon S3. The attacker exfiltrated backups of LastPass customer vault data along with encryption keys and other infrastructure data. The disclosure came four months after the initial August 2022 breach notification, which had incorrectly characterized the damage as limited to source code and had not mentioned that customer vault data was at risk. The delayed and initially incomplete disclosure was widely criticized by security researchers and customers.

The vault backups that were stolen had a mixed encryption posture. Sensitive fields within each vault entry — stored website passwords, credit card numbers, and secure notes — were encrypted using AES-256-CBC with a key derived from the user’s master password using PBKDF2-SHA256. Unencrypted in the vault backups were: website URLs (the domain names for each stored credential), site names and categories, LastPass username/email address, billing address, company name, telephone number, IP addresses of login sessions, and device information. The URL data was particularly significant: it revealed the list of every website for which a user had stored a password, enabling attackers to prioritize high-value targets (cryptocurrency exchanges, financial institutions, corporate VPNs, email providers) for offline master password cracking. The PBKDF2 iteration count — which determines how computationally expensive each password guess is — was 100,100 for accounts that had logged in recently (LastPass’s 2022 default), but some older accounts had been created when the default was 5,000 or even 1 iterations and had never been updated, making their vaults dramatically easier to crack offline. NIST SP 800-132 recommends 310,000+ iterations of PBKDF2-SHA256 for password storage; 1-5,000 iterations allowed GPU-based cracking at millions of guesses per second.

Because the attackers possessed copies of the vault ciphertext, they could conduct offline brute-force and dictionary attacks without being subject to LastPass’s server-side rate limiting or lockout mechanisms. The security of each user’s vault depended entirely on the strength of their master password and the PBKDF2 iteration count. Security researchers at Wladimir Palant (a browser extension security expert) and others published detailed analyses of the encryption flaws within weeks of the disclosure, estimating that vaults with low iteration counts and master passwords below 12 characters were practically crackable on commodity GPU hardware within days to weeks. In 2023, multiple security researchers documented a pattern of cryptocurrency thefts targeting LastPass users: victims who self-identified as having stored cryptocurrency wallet seed phrases in LastPass reported thefts totaling tens of millions of dollars that correlated with the LastPass breach timeline and infrastructure. Blockchain analysis company MetaMask and independent researchers attributed over $35 million in cryptocurrency theft by early 2023 to LastPass vault cracking. For password manager users, the breach reinforced several engineering recommendations: master passwords should be randomly generated and 16+ characters; PBKDF2 iteration counts should be maximized and accounts updated after any service-side default change; credentials for high-value accounts (financial, email, work VPN) should be assumed compromised after any password manager breach and changed immediately; and seed phrases for cryptocurrency wallets should never be stored in cloud-based password managers regardless of claimed encryption strength.