← Back to Gadget Pulse US

LastPass Users Are Just Now Finding Out How Bad 2022 Really Was

Persona #3 ยท Vol: 0

If you used LastPass around 2022 and figured the whole thing blew over, grab a coffee.

Security researchers have been quietly connecting dots, and the picture is uglier than the "your data is safe, probably" email suggested.

Then they grabbed something worse: the URLs of every site you saved.

That second part doesn't need a master password, because it was never encrypted.

So someone out there knows you have a Capital One login, a Ring doorbell, and an account on a forum you'd rather forget.

Security folks call this metadata, which is a fancy way of saying "the embarrassing stuff." Your passwords stayed locked.

Victims started seeing real account takeovers years later, because crooks are patient and your old passwords are recyclable.

If you reused one, you basically handed over a spare key with a bow on it.

For the average American with 200 logins, this is the digital equivalent of losing your wallet but keeping the cash.

Great news, except everyone now knows where you shop.

If you're still on LastPass, migrating is a weekend project, not a crisis.

Bitwarden, 1Password, and even Apple's built-in keychain are fine options, and they're not asking you to trust a company that took a victory lap before the dust settled.

And for the love of everything, turn on two-factor authentication.

Not SMS, because SIM swapping is a real thing.

The bigger takeaway is that "encrypted" is a marketing word until someone tells you what wasn't.

Read the fine print on your next security tool.

Or just assume nothing is safe and live accordingly, which is basically the modern American condition anyway.

It's the years of vague reassurances that made millions of people think they could coast.

Final Thoughts

Turns out you can't outrun a data breach, you can only change your passwords and pretend you were going to do that anyway.

Continue Reading