
A password manager is the one place where a breach of the vendor is supposed not to matter: the vault is encrypted with a key only you can derive. The LastPass breach of 2022 is the best real test of that promise so far. The encryption held. People still lost money, some of them years later.
It took two intrusions to get there. The first, on a developer's work laptop, looked contained. The second went through an engineer's home computer and a media server, and ended with a copy of customer vault backups in someone else's hands. This is how each step worked, and what a team that stores secrets (or signs users in) can take from it.

Incident 1: a developer laptop, four days
In August 2022 an attacker got into a software engineer's corporate laptop and, through it, the cloud development environment. LastPass disclosed it on 25 August: "portions of source code and some proprietary LastPass technical information" had been taken. A September update said the activity lasted four days and touched no customer data, because the development environment held none.
Both statements were true and neither was the end. What left the building was source code, technical documentation and some internal secrets, enough to learn how production backups were stored, what protected them and who held the keys. The UK regulator's later summary: the backup's decryption keys sat in the vaults of four senior employees.
Incident 2: the engineer's home PC
LastPass says the attacker pivoted the day the first incident ended, 12 August, and worked until 26 October 2022. The target was one of those four DevOps engineers, and the way in was not a company system at all.
A media server, 75 versions behind
LastPass described "a remote code execution vulnerability in a third-party media software package" on the engineer's personal computer. Plex later said the flaw was CVE-2020-5741, which let someone with the server owner's Plex account upload a file through the Camera Upload feature and have the server run it. Plex fixed it on 7 May 2020. Its statement: "the version that addressed this exploit was roughly 75 versions ago".
So a home machine ran software more than two years out of date, and the same machine was used to open a work vault.
A keylogger beats MFA
With code running on the PC, the attacker installed a keylogger and waited. In LastPass's words they captured "the employee's master password as it was entered, after the employee authenticated with MFA". The UK Information Commissioner adds two details:
• MFA was bypassed with a trusted device cookie: the PC had been marked as trusted, so whoever controlled the PC inherited that trust.
• The engineer's personal and business vaults were linked under a single master password. One captured password opened both.
MFA proves a person is present at sign-in. It does nothing about software that is already on the device watching them type. We covered the same limit from another side in session cookie theft after MFA.
The keys were in a note
The attacker exported the engineer's vault entries and shared folders. Among them, LastPass said, were "encrypted secure notes with access and decryption keys needed to access the AWS S3 LastPass production backups, other cloud-based storage resources, and some related critical database backups".
From there it was a download with valid credentials, which is why it ran for weeks. LastPass said the legitimate keys made attacker activity hard to tell from normal work. What finally raised the alarm was AWS GuardDuty, when the attacker tried to use cloud IAM roles for something those roles didn't normally do.
What was taken
LastPass told customers in stages: on 30 November that "certain elements" of customer information had been reached, and on 22 December 2022 the full picture.
• Readable: company and user names, billing addresses, email addresses, phone numbers, the IP addresses customers used, and the website URL of every vault entry.
• Encrypted: website usernames and passwords, secure notes and form-fill data, under AES-256 with a key derived from each user's master password, which LastPass never had.
What the encryption did, and what it didn't
The design worked as designed. No one has shown the attackers decrypting vaults in bulk, and the regulator found no evidence of it. But a stolen vault can be attacked forever, offline, with no rate limit and no lockout. Three things then decide how long each vault lasts.
1. URLs in the clear told the attacker where to dig
With unencrypted URLs, nobody has to attack every vault. They sort by who has entries for crypto exchanges, bank admin pages or a company's cloud console, and spend their hardware on those. Researcher Wladimir Palant noted LastPass had been told to encrypt this metadata years earlier. The URLs are also ready-made material for phishing: the attacker knows your email address and every service you use.
2. Iteration counts were frozen at sign-up
The vault key comes from the master password through PBKDF2, a function run many times over so that each guess costs an attacker real time. LastPass's December notice cited 100,100 rounds, its default since 2018. Older accounts were never moved up:
• accounts from around 2013 commonly had 5,000;
• some older ones had 500, and a few users reported 1;
• LastPass's default today is 600,000.
Palant measured about 88,000 guesses a second on one RTX 4090 at 100,100 rounds. The cost per guess scales with the round count, so the same card manages roughly 1.7 million guesses a second at 5,000 rounds and billions at 1. That is our arithmetic from his figure, not a benchmark, but the ratio is the point: an old account was twenty times cheaper to attack than a new one, with the same password.
3. The master password itself
The notice said guessing a master password would take "millions of years" with default settings. That holds for a long random one. The 12-character minimum dated from 2018 and wasn't enforced on older accounts, and people choose passwords people can remember. One victim interviewed by Brian Krebs had an eight-character master password on a ten-year-old account.
The long tail
• September 2023: researchers Taylor Monahan and Nick Bax tie more than 150 cryptocurrency thefts, over $35 million, to one common factor: the victims had kept wallet seed phrases in LastPass.
• March 2025: US prosecutors, in a forfeiture complaint, say the Secret Service and FBI concluded the same attackers used a password from a victim's vault in a $150 million theft on 30 January 2024. LastPass's reply: it has seen no "conclusive evidence that connects any crypto thefts to our incident".
• Late 2025: the UK Information Commissioner fines LastPass UK £1.2 million over up to 1.6 million UK users, citing senior staff reaching business vaults from unmanaged personal devices.
• 2026: a US court gives initial approval to a class settlement of up to $24.5 million, most of it set aside for cryptocurrency losses.
Encryption turned a breach into a slow one. It didn't turn it into nothing.
Controls that break each step
Privileged access only from managed devices
• The handful of people who can reach production keys do it from company-managed, patched machines, never a family PC that also runs a media server.
• Don't allow "trust this device" for those accounts, and keep work and personal vaults under different passwords.
• Use hardware security keys for them. A keylogger can copy what is typed; it can't copy a key that signs each sign-in.
Don't keep the backup keys where one login reaches them
• Decryption keys for backups belong in a KMS or HSM with its own access policy and its own log, not in a note in a personal vault.
• Short-lived cloud credentials instead of long-lived access keys: a stolen key that expires in an hour is a much smaller gift.
• After any breach of a development environment, rotate every secret that environment could see, and assume the attacker now knows your architecture.
Notice the download
• Alert on bulk reads from backup buckets and on access from networks you've never seen. This one was caught only when the attacker stepped outside what a role normally did; plain downloads with valid keys went unnoticed for weeks.
• Give backup storage its own account and its own, very short, list of who can read it.
If you store user secrets
• Encrypt the metadata too. URLs, titles and tags tell an attacker which records are worth the effort.
• Raise key-derivation cost for existing accounts at their next sign-in, not just for new ones. A default that only applies to new users leaves your oldest customers weakest.
• Tell users plainly and early. Four notices over four months, each wider than the last, cost LastPass more trust than the first intrusion did.
If you use a password manager
• Still use one. Reused passwords are a far more common way to lose an account, as in 23andMe.
• Long, random master password; check the key-derivation setting on any account you opened years ago.
• Don't keep wallet seed phrases or recovery codes for your most valuable accounts in the same vault.
• Turn on MFA at each site, so a cracked vault entry alone isn't enough.
The lesson
Every password a site stores is something it can lose, and the cost lands on its users years later. LastPass had to hold secrets; that is the product. Most sites don't. If yours only needs to know who is signing in, the safest stored password is none: let people prove an email address or use the Google or Apple account they already protect, and rate-limit attempts with osec Login Protection. Related reading: Okta 2023, another vendor breach that began in a personal browser profile.
osec Auth adds passwordless sign-in to your site: email code, Google and Apple, with no OAuth setup on your side. No password database to breach, no hashes to crack offline.
Add passwordless sign-inSources: LastPass: Notice of security incident (updates of 25 Aug, 15 Sep, 30 Nov and 22 Dec 2022); SecurityWeek: LastPass says DevOps engineer's home computer hacked (LastPass's incident 2 details); SC Media: Employee's hacked home PC allowed threat actor access to LastPass corporate vault (GuardDuty alerts); The Hacker News: Engineer's failure to update Plex software (CVE-2020-5741, Plex's statement); Wladimir Palant: LastPass has been breached, what now?; Krebs on Security: Experts fear crooks are cracking keys stolen in LastPass breach; Krebs on Security: Feds link $150M cyberheist to 2022 LastPass hacks; UK Information Commissioner's Office: Password manager provider fined; Bloomberg Law: LastPass gets initial nod for $24.5 million data breach deal.