← Back to Gadget Pulse US

LastPass Users Are Just Now Finding Out What Got Leaked

Persona #3 ยท Vol: 0

Remember when LastPass swore up and down that your master password was safe after that 2022 breach?

A fresh wave of reporting and user complaints is dragging the whole mess back into the spotlight, and the vibes are, to use the technical term, extremely bad.

Here's the short version for anyone who wisely deleted the app and moved on with their life.

Back in August 2022, attackers lifted source code.

Then in November, they came back for the actual vault data.

LastPass eventually admitted that customer vaults were taken, encrypted, and that some users with weak master passwords were at "elevated risk." That phrase has been doing a lot of heavy lifting ever since.

The part that's aging like milk in a hot car is the timeline.

LastPass initially suggested the master password itself was never compromised, which led a whole lot of people to shrug and keep their 12-character "Fluffy2021!" password right where it was.

Security researchers have spent the last couple years politely explaining that encrypted vaults sitting in a criminal's hard drive are not a "we'll deal with it later" situation.

Now the internet is doing what the internet does: discovering old news, treating it as brand new, and lighting the comments section on fire.

Reddit threads are full of people realizing they reused that master password on six other sites.

Others are finding out their auto-fill was quietly working against them the whole time.

And a truly cursed number of folks are learning that their "secure notes" โ€” the ones with passport numbers and crypto seed phrases โ€” were in those vaults too.

To be fair to physics, AES-256 encryption is not a joke.

If your master password was genuinely long and unique, you're probably fine.

The problem is that "probably fine" is doing an Olympic-level gymnastics routine when the alternative is a stranger with your Netflix, your bank, and your email all in one zip file.

So what do you actually do, besides posting "well well well" in a forum?

Change your LastPass master password if you're still there, and change it everywhere you reused it.

Turn on two-factor authentication on your email first, because that's the keys to the kingdom.

If you've already migrated to Bitwarden, 1Password, or just a spiral notebook duct-taped under your desk, congratulations, you win a gold star and a mild sense of superiority.

The bigger takeaway is that this is less a LastPass story and more a "how do you store 300 passwords in your head" story.

That's why password managers exist, and that's also why putting all your eggs in one encrypted basket is a bet you're making whether you think about it or not. **Our take:** Password managers are still dramatically better than reusing "Summer2019" on every site, but "trust us, it's encrypted" stops being comforting when the vaults are already gone.

Final Thoughts

If you're still on LastPass out of pure inertia, that's not loyalty โ€” that's a subscription to anxiety.

Continue Reading