https://www.theverge.com/2023/1/24/23569109/goto-hack-lastpass-breach-encrypted-backups-key Skip to main content The Verge logo.The Verge homepage * The Verge homepageThe Verge logo./ * Tech/ * Reviews/ * Science/ * Entertainment/ * MoreMenu The Verge logo. Menu * Security/ * Policy/ * Tech LastPass owner GoTo shares more bad news about November's security breach LastPass owner GoTo shares more bad news about November's security breach / The service formerly known as LogMeIn has confirmed attackers made off with customers' encrypted backups and the encryption key for a 'portion' of them. By Umar Shakir Jan 24, 2023, 9:05 PM UTC| Share this story * * * If you buy something from a Verge link, Vox Media may earn a commission. See our ethics statement. Art rendering of transparent laptop in front of a wall of surveilling eyes. Photo by Amelia Holowaty Krales / The Verge GoTo, the remote collaboration and IT software company that owns LastPass, has confirmed that, along with LastPass' password vaults, it had customer data taken by attackers during a November 2022 security breach (via TechCrunch). The company, which was formerly known as LogMeIn, is updating its blog post about the breach for the first time since November 30th, when GoTo confirmed "unusual activity" within its development environment and cloud storage service. Many of GoTo's enterprise products were affected, including Central, Pro, join.me, Hamachi, and RemotelyAnywhere. GoTo CEO Paddy Srinivasan writes that a hacker "exfiltrated encrypted backups from a third-party cloud storage service" and acquired the encryption key for a portion of them -- nearly two months ago. The information taken varies by product but "may include account usernames, salted and hashed passwords, a portion of Multi-Factor Authentication (MFA) settings, as well as some product settings and licensing information." Encrypted databases for the more well-known GoToMyPC remote computer software and Rescue were not taken by the attackers; however, "MFA settings of a small subset of their customers were impacted." GoTo is apparently contacting affected customers directly to provide additional info as well as support for what actions to take. Passwords for their accounts will be reset "out of an abundance of caution," and MFA will also be reauthorized. Srinivasan also wrote that affected accounts will be migrated to a different Identity Management Platform for additional security, one with "more robust authentication and login-based security options." Our first whiff of the breach was in August, when LastPass notified users that an unauthorized party compromised a developer account. Information taken during that attack was apparently used in November, when hackers were successful in obtaining customer vaults -- a fact that was only announced publicly late in the day on Thursday, December 22nd, when many people were preparing to take a holiday break. Related * Seven free alternatives to the LastPass password manager Cybersecurity experts tore apart LastPass' response to the leak, accusing the company of a lack of transparency about the severity of the situation and its failure to contain the breach. Now, Srinivasan is dealing with a heavy fallout that's only getting worse. But the CEO is noting to customers that GoTo doesn't store their full credit card and banking details and doesn't collect PII such as date of birth, address, and Social Security numbers. LastPass also played down a separate incident in 2021 where customers were barraged by constant unauthorized login attempts. Most Popular 1. Today I learned the Xbox can run Nintendo GameCube and Wii games ----------------------------------------------------------------- 2. Sony and Honda's EV goes where the Apple Car never did ----------------------------------------------------------------- 3. Amazon launches a $5 monthly subscription for unlimited prescription medications ----------------------------------------------------------------- 4. Elon Musk gets serious about 420 at securities fraud trial ----------------------------------------------------------------- 5. Apple MacBook Pro 16 (2023) review: the core count grows ----------------------------------------------------------------- Verge Deals / Sign up for Verge Deals to get deals on products we've tested sent to your inbox daily. Email (required)[ ]Sign up By submitting your email, you agree to our Terms and Privacy Notice. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply. From our sponsor Advertiser Content FromSponsor logo Sponsor thumbnail More from this stream Tuesday's top tech news: Lightyear's buzz fizzles * Microsoft Q2 2023: Windows, devices, and Xbox down as cloud holds strong Jan 24, 2023, 9:09 PM UTC * Google to shut down spam backdoor for political campaigns Jan 24, 2023, 8:45 PM UTC * Google is being sued by the US government and eight states over online advertising Jan 24, 2023, 8:38 PM UTC * Apple issues security update for the almost 10-year-old iPhone 5S Jan 24, 2023, 8:36 PM UTC See all 17 stories The Verge logo. * Terms of Use * Privacy Notice * Cookie Policy * Do Not Sell Or Share My Personal Info * Licensing FAQ * Accessibility * Platform Status * Contact * Tip Us * Community Guidelines * About * Ethics Statement The Verge is a vox media network * Advertise with us * Jobs @ Vox Media (c) 2023 Vox Media, LLC. All Rights Reserved