3 ms·
It is highly unlikely that the attacker was able to crack the encryption. It's also highly unlikely that Lastpass had an unencrypted copy of the vault. However
by andrejodc 4y ago
It is highly unlikely that the attacker was able to crack the encryption. It's also highly unlikely that Lastpass had an unencrypted copy of the vault. However we know that all URLs are not encrypted which allows to identify users who have accounts for particular services e. g. cryptocurrency websites. The attacker could mount targeted attacks only on these lastpass users to reduce the risk of raising red flags. For example the attacker can send very convincing phishing mails to target these individuals with 0-day exploits. But an alternative much more scarier scenario could happen if the attacker found a way to extract the lastpass master password by injecting malicious code into the lastpass extension of targeted users. The possibility of this scenario depends if there is a way for lastpass servers to inject code into the browser extension.