Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› GoTo Breach 2023: How Stolen Encrypted Backups and…
Breach analysis Incident: 30 Nov 2022

GoTo Breach 2023: How Stolen Encrypted Backups and Their Encryption Key Exposed Five Products

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Category: NHI
Attack route: Not disclosed Identities: Secret or password
On this page

On 23 January 2023, GoTo, the parent company of LastPass and maker of remote access and collaboration tools, told customers that an attacker had stolen encrypted backups for five of its products, Central, Pro, join.me, Hamachi and RemotelyAnywhere, and had also taken an encryption key for part of those backups. The intrusion was the one GoTo first disclosed on 30 November 2022, when it reported unusual activity in its development environment and in a third-party cloud storage service it shared with LastPass. The backups held account usernames, salted and hashed passwords, part of customers' multi-factor authentication (MFA) settings, and product and licensing data. GoTo reset passwords, reauthorised MFA and moved affected accounts to a new identity platform. It found no evidence that production systems were accessed, and in April 2023 said its investigation was complete. This is the same campaign as the LastPass breach of 2022, with a different victim.

Key takeaways

  • GoTo said on 23 January 2023 that a threat actor exfiltrated encrypted backups for Central, Pro, join.me, Hamachi and RemotelyAnywhere from a third-party cloud storage service.
  • GoTo also said it had "evidence that a threat actor exfiltrated an encryption key for a portion of the encrypted backups", so for some data the encryption may have offered no protection.
  • The backups held usernames, salted and hashed passwords, part of MFA settings and licensing data; BleepingComputer, citing GoTo's customer notice, added Central scripts, provisioning data and the last four digits of payment cards.
  • The cloud storage was shared with GoTo's affiliate LastPass, whose own 2022 breach involved the same environment. GoTo has not published how the attacker reached the storage or how many customers were affected.
  • The identity lesson: an encryption key stored where the encrypted data can be reached is just another secret waiting to be stolen, so keys need separate custody and separate access controls.

At a glance

OrganisationGoTo, for its Central, Pro, join.me, Hamachi and RemotelyAnywhere products; some Rescue and GoToMyPC customers' MFA settings
WhenIntrusion disclosed 30 November 2022; backup and key theft disclosed 23 January 2023; investigation closed 20 April 2023
AttackerUnnamed threat actor; GoTo has not attributed the attack. The same shared storage was involved in the LastPass incident
Entry pointGoTo's development environment and a third-party cloud storage service shared with LastPass; GoTo has not published the initial access method
Identities abusedAn encryption key for part of the backups; access to the shared cloud storage; backup copies of customer credentials and MFA settings
ImpactEncrypted customer backups for five products stolen with a key for part of them; password resets and MFA reauthorisation for affected users; no evidence of production access, according to GoTo
CategoryNHI. Incident class: confirmed NHI breach (encryption key and cloud-stored backups exfiltrated)

What happened

On 30 November 2022 GoTo's chief executive, Paddy Srinivasan, published a short notice. GoTo had engaged Mandiant and alerted law enforcement after finding problems: "Based on the investigation to date, we have detected unusual activity within our development environment and third-party cloud storage service." The notice added: "The third-party cloud storage service is currently shared by both GoTo and its affiliate, LastPass."

On 23 January 2023 GoTo updated the post with what the investigation had found. It said a threat actor had exfiltrated encrypted backups from the third-party cloud storage service related to Central, Pro, join.me, Hamachi and RemotelyAnywhere. "We also have evidence that a threat actor exfiltrated an encryption key for a portion of the encrypted backups," GoTo wrote. The data, which varied by product, could include account usernames, salted and hashed passwords, a portion of MFA settings, and some product settings and licensing information. Rescue and GoToMyPC encrypted databases were not taken, but the MFA settings of a small subset of their customers were affected.

BleepingComputer, which reviewed GoTo's notice to Central and Pro customers, reported that those backups also held deployment and provisioning information, One-to-Many scripts (Central only), and licensing and purchasing data such as contact details, billing addresses and the last four digits of credit card numbers. GoTo told customers "we salt and hash Central and Pro account passwords". BleepingComputer noted that GoTo had not said which encryption it used, and that if the backups were symmetrically encrypted the stolen key could decrypt them. GoTo says it does not store full card or bank details or collect dates of birth or Social Security numbers.

GoTo reset passwords for affected users and reauthorised MFA settings where needed, even though the passwords were salted and hashed, and moved affected accounts onto an enhanced identity management platform. It said there was no evidence of exfiltration from other products or from production systems. A final update on 20 April 2023 said the investigation was concluded, the threat actor's access had been removed, no compromise beyond the January disclosure had been found, and GoTo had reviewed encryption practices across its applications and backup infrastructure. GoTo has not published the number of affected customers or how the attacker first got in.

Timeline

DateEvent
30 November 2022GoTo discloses unusual activity in its development environment and a third-party cloud storage service shared with LastPass; Mandiant engaged and law enforcement alerted.
23 January 2023GoTo updates its notice: encrypted backups for five products and an encryption key for part of them were exfiltrated; affected customers are contacted.
24 January 2023BleepingComputer and Security Affairs report the update; BleepingComputer details the data types in the Central and Pro backups.
20 April 2023GoTo says the investigation is concluded, the threat actor's access is removed and no further compromise was found.

How it happened: the identity attack path

  1. Access to a shared environment. The attacker reached GoTo's development environment and a third-party cloud storage service used by both GoTo and LastPass. GoTo has not said how. Our LastPass page describes how, in that company's account of the campaign, stolen cloud access keys and decryption keys were central.
  2. Backups stored off production. Encrypted backups of customer data for five products sat in that cloud storage, outside the protections of the production systems.
  3. Key stored within reach. An encryption key for a portion of those backups was also reachable, and GoTo found evidence that it was exfiltrated.
  4. Exfiltration. The attacker copied the encrypted backups and the key out of the environment.
  5. Credential material exposed. The stolen data included usernames, hashed passwords and MFA settings, the material an attacker would need to attack customer accounts, which is why GoTo reset passwords and reauthorised MFA.

Impact

  • Confirmed by GoTo: encrypted backups for Central, Pro, join.me, Hamachi and RemotelyAnywhere were exfiltrated, along with an encryption key for part of them. MFA settings of a small subset of Rescue and GoToMyPC customers were affected.
  • Data at risk: usernames, salted and hashed passwords, MFA settings, product settings and licensing information; for Central and Pro, also provisioning data, scripts and partial billing details, according to BleepingComputer's review of GoTo's notice.
  • Not found: GoTo said it found no evidence of access to production systems or of compromise beyond what it disclosed in January 2023.
  • Unknown: the number of affected customers, the initial access method and whether any account was later attacked using the stolen data have not been published.

What this means for NHI governance

GoTo's disclosure is short, but the identity lesson is clear. Encryption protected the backups only as long as the key was kept apart from them. Once the attacker could reach both the storage and the key, the backups were as good as plaintext for that portion of the data. An encryption key is a non-human credential like any other: it needs an owner, access limited to the processes that use it, separate storage from what it protects, and rotation when its environment is touched.

The incident also shows how shared infrastructure spreads risk between companies. GoTo and LastPass shared one cloud storage service, so an attacker working through that environment could take data from both. The LastPass breach page covers the credential chain behind that campaign. Our Cryptographic Key Management Guide and Secrets Management Guide set out how to keep keys apart from the data they protect.

Recommendations

  • Store encryption keys apart from the data they protect. Keep backup keys in a key management service or hardware module with its own access policy, so that access to the storage never implies access to the key. See our Cryptographic Key Management Guide.
  • Rotate keys and reset credentials after any intrusion near them. GoTo reset passwords and reauthorised MFA; do the same for every key, token and secret the environment could reach. See the Leaked Credential Response Playbook.
  • Protect backups like production. Backups hold the same credentials and personal data as live systems. Apply the same access controls, monitoring and least privilege to backup storage and the identities that reach it. See our Cloud Workload Identity Guide.
  • Separate tenants in shared infrastructure. Where affiliates or business units share storage, give each its own accounts, keys and audit trail so one compromise does not expose both.
  • Limit who and what can reach developer environments. The intrusion began in a development environment. Use short-lived credentials and just-in-time access there too. See our JIT Access Guide.
  • Tell customers what was taken, plainly and early. GoTo's first notice gave little detail; customers need to know which data and which credentials to reset as soon as that is known.

Frequently asked questions

What did hackers steal from GoTo in 2023?

GoTo said in January 2023 that an attacker exfiltrated encrypted backups for Central, Pro, join.me, Hamachi and RemotelyAnywhere from a cloud storage service, plus an encryption key for part of those backups. The data could include usernames, salted and hashed passwords, MFA settings and licensing information.

Is the GoTo breach connected to the LastPass breach?

Yes. GoTo is LastPass's parent company, and GoTo said the third-party cloud storage service involved was shared by both GoTo and LastPass. GoTo's affected products and customers are different from LastPass's, which is why the two incidents have separate pages.

Were GoTo passwords exposed?

Salted and hashed passwords were in the stolen backups, not plaintext passwords, according to GoTo. Because an encryption key for some backups was also taken, GoTo reset passwords for affected users and reauthorised MFA settings as a precaution, and moved accounts to a new identity management platform.

LastPass breach 2022 · CircleCI breach 2023 · Cryptographic Key Management Guide · Secrets Management Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Encryption keys, backup credentials and cloud storage access keys are often the least governed secrets in an organisation. We help teams inventory them, separate keys from the data they protect and build rotation into incident response. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org