LastPass revealed more information on a "coordinated second attack," where a threat actor accessed and stole data from the Amazon AWS cloud storage servers for over two months.
LastPass' parent company says intruders stole the company's encryption key for securing its customers' backed up data.
The password manager said an "unauthorized party" used information stolen from a breach of LastPass' systems in August.
LastPass says the attacker behind the August security breach had internal access to the company's systems for four days until they were detected and evicted.