Cyber Security

CERT-In warns LastPass users in India of increased cyber attacks

Criminals are holding personal details and password vaults containing the sign-in credentials of millions of users.

The Indian Computer Emergency Response Team (CERT-In) issued a ‘high severity’ advisory, last evening for the Indian customers using LastPass.

Just before Christmas, LastPass, one of the leading password manager services had shared that the attackers stole customer vault data after breaching its cloud storage. In August this year its servers were hacked.

“It is reported that the threat actors obtained personal information belonging to its users that include their encrypted password vaults by leveraging data leaked. The data is encrypted, and the threat actor could possibly perform brute force attempt to guess the master password, or may carry out phishing, credential stuffing, or other brute force attacks against online accounts associated with your LastPass vault,” CERT-In wrote on its website.

Attackers broke into a third-party cloud storage service LastPass shares with affiliate company GoTo through which they gained access to certain elements of customers’ information.

While LastPass uses a minimum 12-character master password (with numbers, symbols, and capital letters), hackers can still make an attempt to get into the data using a brute force attack.

CERT-In also shared some of the best practices like changing password every 60-90 days on user-level accounts, using strong passwords with a combination of alphabets (both uppercase and lowercase), numerals and special characters. It also cautioned against the reuse of the master password on other websites.

What are brute force attacks?

The name “brute force” comes from attackers using excessively forceful attempts to gain access to user accounts.

A brute-force mechanism uses every possible combination for the password until one eventually figures it out. The hacker tries multiple usernames and passwords, often using a computer to test a wide range of combinations, until they find the correct login information.

Despite being an old cyber-attack method, brute force attacks are tried and tested and remain a popular tactic with hackers.

Ashwani Mishra

Recent Posts

ShellKode launches initiative to train 100,000 women developers in Gen AI

ShellKode, a globally distributed cloud-native company, has introduced "EmpowerHer" in collaboration with Amazon Web Services…

2 days ago

IBM expands globally to 92 countries via AWS marketplace, including India

IBM has announced the global expansion of its software portfolio, now available in 92 countries…

2 days ago

Building a culture that inspires innovation

In the global services landscape, India's role has evolved remarkably- establishing itself as a notable…

2 days ago

Elections & Economy: India’s financial symphony

As a common Indian citizen, I am compelled to delve into the profound relationship between…

2 days ago

Fostering leadership excellence: Empowering women to lead through inclusive culture

Fostering leadership excellence in today’s dynamic and interconnected world requires more than mere surface-level measures.…

2 days ago

Should traditional logistics players reassess their last-mile burden?

Logistics has always been a complex process of moving goods, such as warehousing and transportation,…

2 days ago