CASE DOSSIER investigation

LastPass DevOps Engineer Home Breach & Vault Exfiltration

Docket: Incident Retrospective 2022-2023 Court: U.S. District Court for the District of Massachusetts Opened: 2022-08-25 Sector: Identity & Cloud Software

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$35.0 million
Re-architecting cloud infrastructure, customer attrition, and multi-state litigation.
Techniques
3
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in U.S. District Court for the District of Massachusetts.
  • Primary Target Sector: Identity & Cloud Software.
  • Documented Financial Loss: $35.0 million.
  • 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Adversaries compromised a senior DevOps engineer home computer by exploiting a remote code execution vulnerability in Plex Media Server, implanted keyloggers to capture master vault credentials, and exfiltrated encrypted customer password vaults from AWS S3 storage.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Infiltration of a senior DevOps engineer home computer via exploitation of a vulnerable third-party media software package (Plex Media Server), enabling keylogger installation and master password theft.

Operational & Financial Fallout

Threat actors exfiltrated production database backups and encrypted customer password vault blobs containing website URLs, usernames, and encrypted passwords for millions of LastPass users, forcing global password reset alerts.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Infiltration of a senior DevOps engineer home computer via exploitation of a vulnerable third-party media software package (Plex Media Server), enabling keylogger installation and master password theft.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Infiltration Workstation Compromise & Source Exfiltration
MITRE ATT&CK T1190 →

Attackers breached an engineer corporate laptop in an initial August 2022 incident, stealing developer documentation and technical artifacts.

Artifacts & Tooling: Compromised developer identity Source repository clone
2
Home Infiltration Home Network Exploitation via Vulnerable Media Server
MITRE ATT&CK T1566 →

Attackers exploited an unpatched Plex Media Server (CVE-2020-5741) on a DevOps engineer home network, deploying a keylogger.

Artifacts & Tooling: CVE-2020-5741 exploit Keylogger payload
3
Credential Capture Master Password & 2FA Bypass
MITRE ATT&CK T1056.001 →

The keylogger captured the engineer master password as they authenticated to access the company corporate password vault.

Artifacts & Tooling: Keylogger log dump Master vault decryption
4
Cloud Access Access to AWS Production Backup Storage
MITRE ATT&CK T1530 →

Armed with master credentials and AWS access keys from the engineer home workstation, attackers accessed cloud storage (AWS S3) buckets.

Artifacts & Tooling: AWS IAM access keys S3 bucket enumeration
5
Exfiltration Bulk Cloud Vault Exfiltration
MITRE ATT&CK T1567.002 →

Attackers copied encrypted customer vault backups and proprietary database backups to attacker-controlled cloud storage.

Artifacts & Tooling: S3 sync command Encrypted vault backup blobs
Real-World Blast Radius & Operational Fallout

Threat actors exfiltrated production database backups and encrypted customer password vault blobs containing website URLs, usernames, and encrypted passwords for millions of LastPass users, forcing global password reset alerts.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Restrict production cloud environment access to company-issued, managed hardware with strict conditional access and MDM enforcement.
✓ Require hardware token MFA for decrypting administrative vaults and obtaining cloud infrastructure credentials.
✓ Implement separate cloud roles and short-lived credentials for developer and infrastructure automation.
✓ Continuously monitor cloud storage buckets for unusual bulk egress traffic patterns.

Procedural & Incident Timeline

2022-08-25 incident

LastPass detects unauthorized development environment access; investigation begins.

2022-11-30 discovery

Investigators discover secondary access to encrypted AWS S3 production backups containing customer vaults.

2022-12-22 disclosure

LastPass publishes customer notice confirming encrypted customer vault data was stolen.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Threat actors exploited a vulnerable third-party media software package (Plex CVE-2022-40348) installed on a DevOps engineer home computer to gain remote execution." LastPass Support Incident Notice 2023 reviewed
T1056.001 Keylogging
Credential Access
"A persistent keylogger was installed on the engineer personal system, capturing the master password as it was entered after hardware token MFA authentication." LastPass Security Posture Retrospective reviewed
T1567.002
"Using captured AWS access keys and decryption tokens, the actors directly queried AWS S3 buckets to exfiltrate database backups containing customer vault blobs." CISA Advisory on Cloud Storage Credential Theft reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, LastPass DevOps Engineer Home Breach & Vault Exfiltration, No. Incident Retrospective 2022-2023 (U.S. District Court for the District of Massachusetts 2022), https://cybercaselibrary.com/cases/lastpass-devops-cloud-vault-breach/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/lastpass-devops-cloud-vault-breach" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>