We're getting some more detail from LastPass about their two breaches last year that were from the same attacker.
There's a lot to unpack here, but this detail about targeting a LastPass DevOps employee on their home computer is somewhat sobering:
"Due to the security controls protecting and securing the on-premises data center installations of LastPass production, the threat actor targeted one of the four DevOps engineers who had access to the decryption keys needed to access the cloud storage service."
"This was accomplished by targeting the DevOps engineer’s home computer and exploiting a vulnerable third-party media software package, which enabled remote code execution capability and allowed the threat actor to implant keylogger malware. The threat actor was able to capture the employee’s master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer’s LastPass corporate vault."'
https://support.lastpass.com/help/incident-2-additional-details-of-the-attack