I use LastPass to manage my passwords for the websites I frequent, and I have it configured to only fill passwords locally on my machine, which means that the password manager doesn't sync online.
A few weeks ago, on June 1, I received a notification email from HitBTC.com that a user from an unrecognized IP address has logged into my account:
Users, BEWARE! If you are on HitBTC.com, make sure to change your current passwords on any other sites you may be a member of if you use the same password.
I'm just curious as to why there was no official statement or email from the HitBTC.com team regarding this security compromise...
HitBTC here. We are extremely sorry to hear that you have encountered this unpleasant experience. Observing your account on a trading platform being intruded is the worst. But it's easy to protect from this.
Allow us to explain this a little bit. In case you don't have 2-step verification enabled on your account, the potential intruders require only your password to start using your account. And they are trying really hard to steal people's passwords, using a whole bunch of methods. Luckily, standard security measures are here to help, and they will do the job perfectly. To stay secure, you would need to make your password strong, change it on a regular basis, scan your computer for malicious software. And, of course, it's vital to enable 2-step verification. And that's it, total security is at your service.
We also provide you with a whole set of safety tools, including 2-step verification for withdrawals or entering the "Settings" section; e-mail verification for withdrawals; e-mail security notifications (which you've witnessed doing their job).
It's important to understand that it's not possible to steal someone's passwords and other personal data from us.
Nobody ever did and nobody ever will.