As you may have recently heard, LastPass (a popular password management software used by millions and recommended by KiteTech) was the recent target of a data breach involving customer data. This news release contains more information about what happened.
Virtually all businesses these days have some digital footprint, so any of them, especially those who deal directly with sensitive personal data, could potentially be targeted for data compromise. That said, KiteTech takes very seriously the trust our customers put in us and the importance of your personal data, and we want to make sure you are fully informed about what happened and what you should do about it.
What happened?
A threat actor was able to copy a backup of customer vault data from the encrypted storage container which is stored in a proprietary binary format that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields such as website usernames and passwords, secure notes, and form-filled data. These encrypted fields remain secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user’s master password. The master password is never known to LastPass and is not stored or maintained by LastPass. The encryption and decryption of data is performed only on the local LastPass client.
Out of an abundance of caution, LastPass is still requiring all users to reset their master passwords.
LastPass has provided the following instructions for resetting your master password:
“To reset your master password, please visit https://lastpass.com/ and click on “I forgot my password”. You will be guided through the process of resetting your master password, which will require you to verify your account using either your email address or a recovery one-time password.”
What should you do about it?
- The first thing we recommend is that you immediately change your Master Password in LastPass. While the Master Passwords were not compromised, all LastPass encryption is derived from the Master Password. Changing the Master Password will “re-key” the Password Vault with new encryption.
- Equally important, make sure that Multi-Factor Authentication (MFA) is enabled on your LastPass account. We recommend that you enable MFA on all of your accounts anyway, but if you do not have MFA enabled on your LastPass account you are at extreme risk for your passwords being compromised.
- We also recommend you change the passwords of each account you have stored in LastPass. Again, it appears that passwords were not fully compromised in unencrypted form, but it is prudent to be abundantly cautious and change your passwords (after you have changed your Master Password). LastPass is advising that the likelihood of the threat actor decrypting this data is slim, but we do think it is in your best interest. We understand this can be a time-consuming task. We would recommend prioritizing any credentials that protect financial data (banks, insurance, etc). For accounts that do not protect sensitive data, you may choose to change those as you access them during the normal course of use.
- Lastly, be on the lookout for phishing attempts related to this compromise. With LastPass not storing the Master Password, the only source of that password is you. It is important to remember that LastPass will never call, email, text, or send you a link requesting your Master Password.
Conclusion
While data breaches are always a worrisome subject in the realm of cyber security, the steps listed above will help you remain secure. By using a strong, unique master password and utilizing multi-factor authentication, you are doing your part in staying protected.
As always, if you have any questions or further concerns, KiteTech is here to help. If you’re already a current client, feel free to reach out to your account manager for further discussion. If you’re not currently working with Kite Technology and would like to learn more about how our Managed IT and Security Services can help you operate more effectively and secure your business, please contact us to schedule a conversation. We’re here to help!
Dillon Fornaro
Security Engineer
Kite Technology Group

By default, Outlook has several Categories already created, named for the colors associated with them. If these work for you, then great! But Outlook allows you to go deeper and customize the Categories. To do so, click on the “All Categories…” menu option.
On the screen that follows, you can click any Category you want, rename it, assign it a different color, and even assign a Shortcut Key, which allows you to quickly set a message to that Category by using the keyboard shortcut you choose from the list. You’ll also notice that you can create brand new categories from this same screen.
When you set a Category on an email, you’ll notice it appears at the top of the email directly under the Subject line.



There are additional options you can access if you choose a Custom flag. As you see here, you can choose a Start date, Due date, and even set a Reminder at a certain date and time. These are all intended to help you keep a timeline and not miss any obligations.



Again, you’ll notice options here for the first two topics discussed in this article: Categorized and Flagged. You can use this to quickly find messages with a particular Category or Flag applied, and you can also combine these criteria together for a more specific search. Maybe you want to find messages with a specific Category that you have Flagged for follow-up, like this message.
When you run searches, your criteria are saved and able to be recalled later, so you can click the “Recent Searches” button and choose a set of criteria you’ve used recently. This can be useful if need to do the same searches frequently. 


I use Quick Steps to quickly move emails to certain folders in my mailbox, so the only ones that appear for me in this screenshot are basic Move actions. To add a new Quick Step, you can click the New button, where you’ll see a list of preset options to get you started, or you can choose Custom to start from scratch.







To enable rule lines, go to the View tab on the Ribbon, and click Rule Lines. If you click the dropdown arrow, you will see other options, like wide-spaced and grid lines.



















