LastPass Discloses Third-Party Supplier Breach Exposing Customer Data
Password manager LastPass has disclosed a new data breach linked to a third-party supplier incident.
The breach exposed customer information including names, phone numbers, and other data. LastPass has not yet disclosed the full scope of the incident or the number of affected users.
The company has advised customers to take immediate steps to protect their accounts, though specific recommendations have not been detailed in the initial disclosure.
This incident follows a 2022 breach in which LastPass confirmed that threat actors accessed encrypted password vaults stored in the company's cloud infrastructure.
Users of LastPass services should monitor their accounts for suspicious activity, enable multi-factor authentication if not already active, and remain vigilant for phishing attempts that may leverage exposed personal information.