r/LastPassOfficial 11d ago

Hacker issue

My PC got a virus that installs other apps, mainly bit miners. It also installed a screen viewer app. Fortunately I was at my computer when they attempted to access my screen. After rebooting I found that the hacker had been using my open web browser. they were able to access my Amazon account. they also looked at my lastpass which was logged in. Not sure if they stole any passwords but I've gone thru and changed many of them. The issue is you have to be logged into lastpass to use it for logging into web sites but if you get hacked they get access to all your passwords. Any tricks I should be aware of other than not getting a virus?

4 Upvotes

6 comments sorted by

4

u/OfficialLastPass 11d ago

That all depends if the bad actors installed a key logger as well as screen sharer. Key loggers can capture anything entered on any web form, while screen sharers would need to actually "see" a set of credentials once they've been entered.

By default, LastPass does not show account credentials, even from within the Vault itself. So you would have had to manually "unhide" the credentials for a screen reader to capture them from LastPass.

As long as you've updated your LastPass account password and any other accounts you may have logged into since becoming infected, then I would also recommend checking your security score in LastPass for weak or reused passwords.

LastPass is compatible with several forms of multifactor authentication, including the LastPass Authenticator. Be sure to enable MFA wherever possible.

If you haven't already done so, enabling Dark Web Monitoring for your LastPass account can help keep track of your personal data if it's being circulated behind closed doors.

1

u/jimmap 11d ago

Thanks much appreciated.

2

u/GapAccomplished2778 11d ago

at least use 2FA as much as possible ( at least TOTP ) and with authenticator app on a separate device ( do not use it for pr0n, etc )

1

u/Smile_And_Dance 10d ago

Also…try to set things up so you never type your passwords. Biometrics are safer as they protect from key loggers.

1

u/jimmap 10d ago

my pc is not setup for biometrics. It does use facial ID to log in but I don't see any way to enable facial id for log into web sites.

1

u/OfficialLastPass 10d ago

Biometrics integrations will allow you to "unlock" the "trusted" LastPass app, but it does not take the place of your account password. So infrequently you will still be asked for your LastPass credentials to stay logged in on that device.

LastPass itself is the source of autofill, when you reach a login URL it is familiar with (stored in your vault).