As reported by BleepingComputer (opens in new tab), LastPass has disclosed that it was targeted by a cyberattack two weeks ago after rumors of the attack began circulating online. The news outlet found out about the breach after speaking with insiders last week who said the company was “scrambling to contain the attack”. If you’re a LastPass customer, you may be wondering if your passwords and other sensitive data are still safe. Fortunately, customer passwords weren’t exposed as the hackers responsible only managed to steal the company’s source code along with proprietary technical information.

LastPass confirms it was hacked

In a new security advisory (opens in new tab) released on Thursday, LastPass CEO Karim Toubba explained that the company “detected some unusual activity within portions of the LastPass development environment” two weeks ago. The company immediately began an investigation and so far, no evidence has been found that any customer data or encrypted password vaults were accessed by the attacker behind the breach. The attacker was able to gain access to LastPass’ development environment by using a single compromised developer account. Once inside the company’s systems, they “took portions of source code and some proprietary LastPass technical information”, according to Toubba. Although all of LastPass’ products and services are operating normally, the company has deployed containment and mitigation measures. It’s also working with a cybersecurity and forensics firm to conduct an expanded investigation into the incident.

Why your passwords are still safe

In addition to being one of the best password managers, LastPass is also one of the largest and the company says its services are used by more than 33 million people and 100,000 businesses worldwide. Although your passwords are certainly safer when stored inside a password manager, there is always the chance that if a company like LastPass or 1Password is hacked, cybercriminals could gain access to your stored passwords. At the same time, the company doesn’t store nor does it have knowledge about your master password. This is because LastPass uses Zero Knowledge architecture which ensures it can never know or gain access to its customers’ master passwords. Likewise, none of the data stored inside customers’ encrypted vaults was compromised during the breach. Normally, after a data breach, companies recommend that users change their passwords but in this case, LastPass says that users don’t need to take any action at this time. The company also plans to keep users updated on the findings of its investigation once they become available.