A widely used password manager vendor confirmed attackers breached its development environment, accessing source code and internal technical documentation.
The company emphasized that customer vault data remains protected by zero-knowledge encryption, with master passwords never transmitted to its servers. No evidence suggests customer vaults were accessed or that malicious code entered the release pipeline.
The intrusion began with a phishing attack against a developer, whose session token was stolen and replayed to bypass multi-factor authentication. The vendor has since shortened session lifetimes and added device-binding controls.
Security experts broadly reaffirmed that password managers remain safer than the alternatives, while urging users to enable two-factor authentication and use long, unique master passwords.
