In 2022, LastPass disclosed that attackers had copied encrypted customer vault backups from a cloud storage environment, along with some unencrypted metadata like website URLs. Here’s what that does and doesn’t mean for you.
What was taken
Encrypted vault backups — meaning your actual passwords were still protected by AES-256 encryption derived from your master password — plus some metadata that wasn’t encrypted, like the web addresses associated with saved logins.
What wasn’t taken
LastPass has stated master passwords themselves were not obtained directly, because of the zero-knowledge architecture — the company never has your plaintext master password to begin with.
Should you worry?
If your master password was weak or reused elsewhere, an attacker with enough computing time could eventually attempt to crack the encrypted backup. Security researchers generally recommend anyone still on LastPass rotate their master password, enable multi-factor authentication, and consider whether the incident changes their risk tolerance. Read our full LastPass review for how it scores today, or compare it directly in LastPass vs Dashlane.
Is switching worth it?
Several rivals — including our top-rated Bitwarden — have no disclosed breach history and score higher overall in our full rating.
