LastPass Provides Action Items in Response to Breach

Publish Date

Type

Cyber Alert

Topics
  • Cybersecurity

LastPass recently released an update providing additional context into the August 2022 security incident. The update serves to assure customers and business administrators of what LastPass will do differently in the future to avoid similar incidents and notifies federated users that the unknown threat actor exfiltrated the K2 split knowledge component from the LastPass MFA/Federation Database. LastPass also provides further recommended action items for general customers and business administrators.

The takeaways from the update involve ten key topic areas and subsequent action items to promptly take to stay secure.

The topic areas include:

  1. Master password length and complexity
  2. Iteration counts for master passwords
  3. Super admin best practices
  4. MFA shared secrets
  5. SIEM Splunk integration
  6. Exposure due to unencrypted data
  7. Deprecation of Password apps (Push Sites to Users)
  8. Reset SCIM, Enterprise API, SAML keys
  9. Federated customer considerations
  10. Additional considerations

Key LastPass recommendations for business administrators

  1. Review master password policies and enforce stronger master passwords
  2. Review security reports related to master passwords
  3. Reset shared secrets for non-federated customers
  4. Update Splunk instance token
  5. Review vault item password policies

Our recommendations for LastPass users

  1. Immediately update your LastPass master password
  2. Consider changing your passwords for sites stored within LastPass
  3. Stay alert for phishing attacks as hackers now have sensitive user information that could be used in a future attack
  4. Watch for further updates regarding this incident and what to do on LastPass’ website

LastPass has closed this investigation, so businesses should ensure that employees are aware of any data that may have been compromised and promptly act upon the action items provided by LastPass.

How we help

We can help your firm establish and test your cybersecurity program to ensure that it exceeds industry standards. Our team can:

  • Develop and review written policies and procedures that meet your firm’s regulatory requirements and the latest industry standards
  • Assess your policies and procedures to confirm they accurately reflect the cybersecurity procedures currently in practice at your firm
  • Test your systems to identify network vulnerabilities and provide remediation recommendations

For questions about this alert, or to find out how we can help you meet your regulatory cybersecurity obligations, please reach out to your ACA Aponix consultant, or contact us below.

Contact Us