LastPass customers are still finding out years later.
In late 2022, attackers walked off with encrypted copies of millions of user vaults.
The company said the data was safe because it was locked.
Then people started reporting drained crypto wallets, compromised email accounts, and logins that suddenly failed.
The math on "safe" turned out to be a lot shakier than advertised.
Here's what nobody wants to admit: this isn't one company's screwup.
A password manager is a single locked box holding every key you own.
That's the whole selling point and the whole problem.
When the box gets opened, everything inside is exposed at once, and you can't reissue your face or your childhood pet's name.
Attackers got in through a vulnerable third-party media app, then used that foothold to reach a senior engineer's machine.
From there, they grabbed source code and, eventually, vaults.
Just patience and one unpatched piece of software nobody was watching.
The company's response was slow, vague, and defensive.
Customers learned more from security researchers on Twitter than from official emails.
By the time clear guidance arrived, many people had already spent weeks not knowing whether their master password was the only thing standing between a stranger and their bank account.
So what actually happens when your vault leaks?
If your master password was weak or reused, it's over quickly.
If it was strong, attackers don't give up.
They run it against leaked password lists, try variations, and wait.
A cracked password from 2019 still opens the same door in 2025.
The uncomfortable truth is that most of us handed over our entire digital lives because a website told us it was the responsible thing to do.
And it is more responsible than using "Summer2024!" on twelve sites.
But "better than terrible" isn't the same as "safe," and the industry has spent a decade blurring that line.
If you're still using a cloud-synced manager, the practical moves are unglamorous.
Turn on two-factor authentication with an app or a hardware key, not SMS.
Change your master password if it's older than the last breach disclosure.
Audit what's actually in your vault and delete the accounts you forgot existed.
And accept that your email inbox is the real master key—if someone gets in there, they can reset everything else.
Local and open-source options exist, but they demand more from you.
There's no customer support line and no company to blame.
That trade-off is real, and pretending otherwise is how we ended up here.
We were told to centralize our secrets with companies that get breached, downplay it, and move on.
Every few years the cycle repeats with a new logo.
Meanwhile, the cost lands on ordinary people who just wanted to stop reusing the same password.
The password manager was supposed to be the fix for a broken system.
Instead it became the biggest single target in it.
Final Thoughts
Until companies treat a breach like the emergency it is—and until we stop treating convenience as a security feature—your vault is only as strong as the worst day of the company holding it.