LastPass DevOps Engineer Home Breach & Vault Exfiltration
Key Facts
- Legal Status: INVESTIGATION in U.S. District Court for the District of Massachusetts.
- Primary Target Sector: Identity & Cloud Software.
- Documented Financial Loss: $35.0 million.
- 3 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Infiltration of a senior DevOps engineer home computer via exploitation of a vulnerable third-party media software package (Plex Media Server), enabling keylogger installation and master password theft.
Operational & Financial Fallout
Threat actors exfiltrated production database backups and encrypted customer password vault blobs containing website URLs, usernames, and encrypted passwords for millions of LastPass users, forcing global password reset alerts.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Infiltration of a senior DevOps engineer home computer via exploitation of a vulnerable third-party media software package (Plex Media Server), enabling keylogger installation and master password theft.
Adversary Kill Chain Flow
5 Documented PhasesAttackers breached an engineer corporate laptop in an initial August 2022 incident, stealing developer documentation and technical artifacts.
Attackers exploited an unpatched Plex Media Server (CVE-2020-5741) on a DevOps engineer home network, deploying a keylogger.
The keylogger captured the engineer master password as they authenticated to access the company corporate password vault.
Armed with master credentials and AWS access keys from the engineer home workstation, attackers accessed cloud storage (AWS S3) buckets.
Attackers copied encrypted customer vault backups and proprietary database backups to attacker-controlled cloud storage.
Threat actors exfiltrated production database backups and encrypted customer password vault blobs containing website URLs, usernames, and encrypted passwords for millions of LastPass users, forcing global password reset alerts.
Procedural & Incident Timeline
LastPass detects unauthorized development environment access; investigation begins.
Investigators discover secondary access to encrypted AWS S3 production backups containing customer vaults.
LastPass publishes customer notice confirming encrypted customer vault data was stolen.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Threat actors exploited a vulnerable third-party media software package (Plex CVE-2022-40348) installed on a DevOps engineer home computer to gain remote execution." | LastPass Support Incident Notice 2023 | reviewed |
| T1056.001 | Keylogging Credential Access | "A persistent keylogger was installed on the engineer personal system, capturing the master password as it was entered after hardware token MFA authentication." | LastPass Security Posture Retrospective | reviewed |
| T1567.002 | "Using captured AWS access keys and decryption tokens, the actors directly queried AWS S3 buckets to exfiltrate database backups containing customer vault blobs." | CISA Advisory on Cloud Storage Credential Theft | reviewed |