Identity, IAM Technologies, Threat Management, Threat Intelligence, Breach

Crypto theft still powered by 2022 LastPass breach

LastPass website under a magnifying glass. LastPass is a freemium password manager that stores encrypted passwords online.

Threat actors have been able to continuously conduct cryptocurrency heists using encrypted vault backups pilfered in a cyberattack against LastPass three years ago, Security Affairs reports.

Insecure master passwords have been leveraged to decrypt the backups of almost 30 million vaults stolen in 2022 and facilitate wallet draining activities until 2024 to 2025, according to an analysis from TRM Labs. Attackers then funneled the pilfered funds to Cryptex, Audi6, and other Russian cryptocurrency exchanges, indicating their potential association with Russia-based operators.

"While definitive attribution of the original intrusion cannot yet be confirmed, these signals, combined with TRM's ability to demix activity at scale, highlight both the central role of Russian cybercrime infrastructure in monetizing large-scale hacks and the diminishing effectiveness of mixing as a reliable means of obfuscation," said researchers.

Such findings come after LastPass was ordered by the UK's Information Commissioner's Office to pay a $1.6 million penalty over negligence related to the 2022 breach.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds