← GoTo

2022 Cloud storage breach — encrypted backups stolen

2022 Unknown records affected Share on X

Data compromised

Account usernames, salted/hashed passwords, MFA settings, product settings, licensing info

Technical writeup

GoTo (formerly LogMeIn) disclosed unauthorized activity in third-party cloud storage shared with subsidiary LastPass. Attackers exfiltrated encrypted customer backups from Central, Pro, join.me, Hamachi, and RemotelyAnywhere. An encryption key for a portion of backups was also stolen. MFA settings for Rescue and GoToMyPC compromised. Attack leveraged data from LastPass August 2022 breach.

Root cause

Third-party cloud compromise; linked to LastPass breach.

References