|
|
|
|
|
by overlordalex
1638 days ago
|
|
What is your opinion of the analysis from LastPass themselves?[0]
It seems to have been some internal alerting that went wrong, which does happen from time to time. > Our initial findings led us to believe that these alerts were triggered in response to attempted “credential stuffing” activity [...] We quickly worked to investigate this activity and, at this time, have no indication that any LastPass accounts were compromised by an unauthorized third-party as a result of these credential stuffing attempts, nor have we found any indication that user’s LastPass credentials were harvested by malware, rogue browser extensions, or phishing campaigns. > Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error. [0] https://blog.lastpass.com/2021/12/unusual-attempted-login-ac... |
|
It certainly isn’t reassuring that they keep talking about credential stuffing, even though it’s quite unlikely to be the culprit here.