{
  "type": "bundle",
  "id": "bundle--c6bf2cfa-96bc-57df-843b-8c3643c0a796",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--872ec1f1-fa4e-597b-8250-32944ca6b39f",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:e9e064ce-0c28-5c11-9e57-de22c83449e1",
      "name": "LastPass",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--97bc3af5-fb9c-5781-8977-638c22fb6ea8",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:c100094d-cf70-548a-9b61-b67b3ba3c45d",
      "name": "LastPass security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--ac4f1342-8b76-5633-8a28-4550eec311db",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:3518a794-bf17-5110-9a05-de8112af36a6",
      "name": "LastPass security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--14b33b1a-18d7-5940-8a4b-6fe1e3fe02a9",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:6fb59080-1104-5070-b445-f3c1549dd769",
      "relationship_type": "affected-organization",
      "source_ref": "incident--97bc3af5-fb9c-5781-8977-638c22fb6ea8",
      "target_ref": "identity--872ec1f1-fa4e-597b-8250-32944ca6b39f",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "LastPass",
          "url": "https://blog.lastpass.com/posts/security-incident-update-recommended-actions",
          "external_id": "cit:8a771d68-c837-5f4d-b6b7-dc76134c5b7f",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:08e20047a8be27e5f721f7b76569024f6bce27d005897b9145cfc8e05b7d89e0"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--0baf8a43-a8f1-5fcf-8a14-1f4d8263f30e",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:968d1a7c-eacb-571b-93c1-266be7e65b09",
      "confidence": 85,
      "external_references": [
        {
          "source_name": "LastPass",
          "url": "https://blog.lastpass.com/posts/security-incident-update-recommended-actions",
          "external_id": "cit:043320df-4ca7-51f7-b5a0-0286a3b4d68d",
          "description": "Incident 1 Summary: A software engineer’s corporate laptop was compromised, allowing the unauthorized threat actor to gain access to a cloud-based development environment and steal source code, technical information, and certain LastPass internal system secrets.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:08e20047a8be27e5f721f7b76569024f6bce27d005897b9145cfc8e05b7d89e0"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Compromise of a DevOps engineer's home computer via keylogger, captured master password; two-stage intrusion (Aug dev environment, then Nov/Dec cloud storage)."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--386593bf-3949-59ab-84c1-591f16a6aaa2",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:7b1a07df-1dc6-54ed-9d18-50f83d87eb6a",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "LastPass",
          "url": "https://blog.lastpass.com/posts/security-incident-update-recommended-actions",
          "external_id": "cit:2c46e193-34f1-5ba5-a3fd-e7b4f07f14a7",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:08e20047a8be27e5f721f7b76569024f6bce27d005897b9145cfc8e05b7d89e0"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the lastpass security incident involving LastPass."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--e0835253-c8cd-541d-8136-9b944cdb835e",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:2cbbcedf-c78d-55db-b569-21dfc45df352",
      "confidence": 88,
      "external_references": [
        {
          "source_name": "LastPass",
          "url": "https://blog.lastpass.com/posts/security-incident-update-recommended-actions",
          "external_id": "cit:5e50b511-d073-5432-a590-75f7d2e7b3e1",
          "description": "All sensitive customer vault data, other than URLs, file paths to installed LastPass Windows or macOS software, and certain use cases involving email addresses, were encrypted using our Zero knowledge model and can only be decrypted with a unique encryption key derived from each user’s master password.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:08e20047a8be27e5f721f7b76569024f6bce27d005897b9145cfc8e05b7d89e0"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Encrypted password vaults for all customers stolen."
      }
    }
  ]
}
