Online password management platform LastPass disclosed that an unauthorized party gained access to a third-party cloud storage service that LastPass uses to store archived backups of its production data. According to a LastPass investigation, an unknown attacker gained access to a cloud-based storage environment using information previously obtained by LastPas in an incident disclosed in August 2022, and some source code and technical information was stolen from the development environment and used to for attacking another employee to obtain credentials and keys used to access and decrypt certain storage in a cloud-based storage service. LastPass determined that once the cloud storage access keys and dual storage container decryption keys were obtained, the attackers copied information from backups containing basic customer account information and related metadata, including company name, end user name, billing address, Email addresses, phone numbers and IP addresses used by customers to access LastPass services. LastPass says that since 2018, it has required a master password of at least 12 characters, which greatly reduces the ability to brute force guess passwords. If a user's master password does not follow the above defaults, LastPass recommends that users consider minimizing risk by changing stored website passwords. the