3 ms·
My recollection says twice. However, the number of times a company tells the media it has had a breach does not correspond to the number of times data has been
by Genbox 4y ago
My recollection says twice. However, the number of times a company tells the media it has had a breach does not correspond to the number of times data has been exfiltrated.
Notifying customers of a breach is a much more ethical approach than sitting on the information. In some countries it is even mandetory to report breaches to affected users, which I personally think is better than not doing it.
- drannex 4y agoAt a minimum of three times, https://en.wikipedia.org/wiki/LastPass#Security_issues https://en.wikipedia.org/wiki/LastPass#Security_issues
- Genbox 4y agoI interpret "hacked" as "compromised". Suspicious activity and vulnerability reports don't meet that criteria. In that case, only 2015 and 2022 would qualify. The activity in 2011 was never confirmed to be a breach. It was a overcautious response on LastPass's part after seeing an outlier in the logs. The investigating party gave a report saying they couldn't find anything, and the CEO later gave a statement saying they overreacted to an outliter out of an abundance of caution.