{
  "id": "case-lastpass-vault",
  "slug": "lastpass-devops-cloud-vault-breach",
  "title": "LastPass DevOps Engineer Home Breach & Vault Exfiltration",
  "summary": "Adversaries compromised a senior DevOps engineer home computer by exploiting a remote code execution vulnerability in Plex Media Server, implanted keyloggers to capture master vault credentials, and exfiltrated encrypted customer password vaults from AWS S3 storage.",
  "case_number": "Incident Retrospective 2022-2023",
  "court": "U.S. District Court for the District of Massachusetts",
  "district": "D. Mass.",
  "country": "United States",
  "opened_at": "2022-08-25",
  "status": "investigation",
  "victim_sector": "Identity & Cloud Software",
  "victim_country": "United States",
  "loss_amount_usd": 35000000,
  "loss_amount_note": "Re-architecting cloud infrastructure, customer attrition, and multi-state litigation.",
  "first_seen_at": "2022-08-01T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "unc3944",
  "defendant_slugs": [],
  "cves": [
    "CVE-2022-40348"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Threat actors exploited a vulnerable third-party media software package (Plex CVE-2022-40348) installed on a DevOps engineer home computer to gain remote execution.",
      "evidence_locator": "LastPass Support Incident Notice 2023",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "LastPass Incident Update",
      "source_url": "https://blog.lastpass.com",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1056.001",
      "evidence_excerpt": "A persistent keylogger was installed on the engineer personal system, capturing the master password as it was entered after hardware token MFA authentication.",
      "evidence_locator": "LastPass Security Posture Retrospective",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "LastPass Security Blog",
      "source_url": "https://blog.lastpass.com",
      "technique_name": "Keylogging",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1567.002",
      "evidence_excerpt": "Using captured AWS access keys and decryption tokens, the actors directly queried AWS S3 buckets to exfiltrate database backups containing customer vault blobs.",
      "evidence_locator": "CISA Advisory on Cloud Storage Credential Theft",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Guidance",
      "source_url": "https://www.cisa.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2022-08-25",
      "description": "LastPass detects unauthorized development environment access; investigation begins."
    },
    {
      "event_type": "discovery",
      "event_date": "2022-11-30",
      "description": "Investigators discover secondary access to encrypted AWS S3 production backups containing customer vaults."
    },
    {
      "event_type": "disclosure",
      "event_date": "2022-12-22",
      "description": "LastPass publishes customer notice confirming encrypted customer vault data was stolen."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Infiltration of a senior DevOps engineer home computer via exploitation of a vulnerable third-party media software package (Plex Media Server), enabling keylogger installation and master password theft.",
    "blast_radius": "Threat actors exfiltrated production database backups and encrypted customer password vault blobs containing website URLs, usernames, and encrypted passwords for millions of LastPass users, forcing global password reset alerts.",
    "kill_chain": [
      {
        "phase": "Initial Infiltration",
        "title": "Workstation Compromise & Source Exfiltration",
        "description": "Attackers breached an engineer corporate laptop in an initial August 2022 incident, stealing developer documentation and technical artifacts.",
        "technical_artifacts": [
          "Compromised developer identity",
          "Source repository clone"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Home Infiltration",
        "title": "Home Network Exploitation via Vulnerable Media Server",
        "description": "Attackers exploited an unpatched Plex Media Server (CVE-2020-5741) on a DevOps engineer home network, deploying a keylogger.",
        "technical_artifacts": [
          "CVE-2020-5741 exploit",
          "Keylogger payload"
        ],
        "mitre_technique_id": "T1566"
      },
      {
        "phase": "Credential Capture",
        "title": "Master Password & 2FA Bypass",
        "description": "The keylogger captured the engineer master password as they authenticated to access the company corporate password vault.",
        "technical_artifacts": [
          "Keylogger log dump",
          "Master vault decryption"
        ],
        "mitre_technique_id": "T1056.001"
      },
      {
        "phase": "Cloud Access",
        "title": "Access to AWS Production Backup Storage",
        "description": "Armed with master credentials and AWS access keys from the engineer home workstation, attackers accessed cloud storage (AWS S3) buckets.",
        "technical_artifacts": [
          "AWS IAM access keys",
          "S3 bucket enumeration"
        ],
        "mitre_technique_id": "T1530"
      },
      {
        "phase": "Exfiltration",
        "title": "Bulk Cloud Vault Exfiltration",
        "description": "Attackers copied encrypted customer vault backups and proprietary database backups to attacker-controlled cloud storage.",
        "technical_artifacts": [
          "S3 sync command",
          "Encrypted vault backup blobs"
        ],
        "mitre_technique_id": "T1567.002"
      }
    ],
    "defensive_takeaways": [
      "Restrict production cloud environment access to company-issued, managed hardware with strict conditional access and MDM enforcement.",
      "Require hardware token MFA for decrypting administrative vaults and obtaining cloud infrastructure credentials.",
      "Implement separate cloud roles and short-lived credentials for developer and infrastructure automation.",
      "Continuously monitor cloud storage buckets for unusual bulk egress traffic patterns."
    ]
  }
}