Another update to that LastPass compromise. GoTo, the remote collaboration and IT software company that owns LastPass, has confirmed that, along with LastPass’ password vaults, it had customer data taken by attackers during a November 2022 security breach. Many of GoTo’s enterprise products were affected, including Central, Pro, and join.me, Hamachi, and RemotelyAnywhere. GoTo is contacting affected customers directly to provide additional info as well as support for what actions to take.
The lesson to focus on is how issuing notices piecemeal weakens customer confidence. Either they were holding back information, or they didn’t know what happened, or their investigation wasn’t well run…. Or… some other lousy thought pops into customers’ heads that causes doubt in their capabilities. This is not a good place to be.
Transparency continues to be the best way to approach these issues… something to remember when the inevitable breach occurs for you or your customers.

