LastPass and Apple: New AI Scams Are Targeting You, LastPass Was Breached Again, and an Urgent Warning for Apple Owners

LastPass and Apple: New AI Scams Are Targeting You, LastPass Was Breached Again, and an Urgent Warning for Apple Owners

Cybersecurity Roundup: LastPass Breach, AI Scams, and Emerging Threats

This week in cybersecurity brought a mix of high-profile breaches, AI-driven fraud, and evolving threats targeting personal data.

LastPass Suffers Another Breach
LastPass disclosed a security incident involving a third-party tool, resulting in the theft of customer contact information and physical addresses. While passwords and vault data remained secure, the breach marks another setback for the password manager, which has faced repeated security challenges. The incident underscores the risks of relying on third-party services in critical security infrastructure.

AI-Powered Scams Cost Americans Nearly $900 Million in 2025
The FBI’s 2025 Internet Crime Report revealed that AI-enabled scams drained nearly $900 million from U.S. victims last year, with older adults disproportionately targeted. AI tools have made it easier for scammers to craft convincing phishing emails, fraudulent ads, and fake websites, amplifying the scale and sophistication of attacks. The FBI warned that without intervention from AI developers, these threats will continue to escalate.

Dark Web Markets Automate Stolen Credential Sales
Security researchers at Flare uncovered a growing "malware-as-a-service" model on dark web forums, where hackers now offer targeted credential searches for specific individuals or platforms. Instead of selling bulk data, cybercriminals now provide curated results complete with customer reviews making it easier for attackers to launch spear-phishing campaigns or identity theft. AI-driven automation has streamlined the process, turning stolen data into a more accessible commodity.

Apple Devices Face "Unpatchable" Security Flaw
Older iPhones, iPads, Apple TVs, and Studio Displays are affected by an "unpatchable" vulnerability that requires physical access to exploit. While the risk is limited, the flaw highlights the challenges of securing aging hardware, as researchers recommend upgrading to newer devices as the only viable solution.

Anthropic Considers ID Verification for Claude Users
AI firm Anthropic is exploring government ID verification for users flagged for fraudulent activity, citing compliance with age-verification laws and internal fraud prevention. The move, outlined in an updated privacy policy, raises concerns about data security, given the rising number of breaches involving stolen IDs. The company’s shift comes amid regulatory pressure and efforts to improve relations with government agencies.

VPNs and Streaming: A Cat-and-Mouse Game
A deeper look at VPN usage for bypassing geo-restrictions revealed that streaming services frequently block VPN traffic, with success varying by provider. While VPNs remain a key security tool, their effectiveness for accessing restricted content fluctuates as platforms refine detection methods.

From password managers to AI-driven fraud, this week’s developments highlight the persistent and evolving nature of cyber threats.

Source: https://me.pcmag.com/en/security/37573/new-ai-scams-are-targeting-you-lastpass-was-breached-again-and-an-urgent-warning-for-apple-owners

LastPass cybersecurity rating report: https://www.rankiteo.com/company/lastpass

Apple cybersecurity rating report: https://www.rankiteo.com/company/apple

"id": "LASAPP1782793516",
"linkid": "lastpass, apple",
"type": "Breach",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Customers',
                        'industry': 'Cybersecurity',
                        'name': 'LastPass',
                        'type': 'Password Manager Service'}],
 'attack_vector': 'Third-party tool compromise',
 'customer_advisories': 'Public disclosure of breach',
 'data_breach': {'data_encryption': 'Passwords and vault data remained '
                                    'encrypted',
                 'data_exfiltration': 'Yes',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Moderate',
                 'type_of_data_compromised': 'Contact information, physical '
                                             'addresses'},
 'description': 'LastPass disclosed a security incident involving a '
                'third-party tool, resulting in the theft of customer contact '
                'information and physical addresses. While passwords and vault '
                'data remained secure, the breach marks another setback for '
                'the password manager, which has faced repeated security '
                'challenges.',
 'impact': {'brand_reputation_impact': 'Significant',
            'data_compromised': 'Customer contact information and physical '
                                'addresses',
            'identity_theft_risk': 'Increased'},
 'lessons_learned': 'Risks of relying on third-party services in critical '
                    'security infrastructure',
 'post_incident_analysis': {'root_causes': 'Third-party tool compromise'},
 'recommendations': 'Review and strengthen third-party security protocols',
 'references': [{'source': 'Cybersecurity Roundup'}],
 'response': {'communication_strategy': 'Public disclosure'},
 'title': 'LastPass Security Incident Involving Third-Party Tool',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.