If you've been feeling a little too smug about using a password manager, this week has been a gentle reminder that even the digital vaults have vault doors, and sometimes those doors are held shut with a sticky note.
The short version: LastPass confirmed that a breach first disclosed back in August went deeper than anyone wanted to admit.
An attacker walked off with customer vault data — encrypted passwords, sure, but also unencrypted stuff like website URLs, company names, and the kind of billing addresses that make for excellent phishing bait.
For the three people who still trust a free VPN, here's the recap.
The company originally said the August incident was contained.
Then a second breach dropped in November.
Then, right around the holidays, they admitted the bad guys had actually grabbed backups of customer vaults.
Nothing says "Happy New Year" like a hacker with your Netflix login and your mother's maiden name.
Now, to be fair — and I can't believe I'm defending LastPass — the actual password fields are still encrypted with your master password.
If your master password was a 40-character monstrosity you memorized at 3 a.m., you're probably fine.
If it was "Fluffy2023!" because you have a golden retriever and a sense of optimism, well, we need to talk.
Encrypted blobs are useless to a thief, but knowing which sites you use is a gold mine.
They know you have an account on a site you'd rather your spouse didn't know about.
That's not a data breach, that's a personal dossier with a bow on top.
Security researchers have been screaming about this for months, mostly at each other on Twitter, which is the modern equivalent of a smoke alarm.
The advice is the same as always: change your master password, enable two-factor authentication everywhere, and consider migrating to a competitor like 1Password or Bitwarden.
Also, maybe stop reusing the same password for your email and your dog's Instagram.
The uncomfortable truth nobody wants to say out loud is that password managers are still better than the alternative.
The alternative is keeping everything in a spiral notebook labeled "Passwords" or using "password123" for your 401(k) portal.
At least with a manager, one breach doesn't automatically mean every account falls like dominoes — assuming you actually rotated your credentials instead of just reading about the breach and feeling bad for five minutes.
What's genuinely infuriating is the communication.
Customers got drip-fed bad news over months, each update slightly worse than the last.
That's not transparency, that's a slow-motion trust fall where nobody caught you.
If a company wants to hold the keys to your digital life, it should probably tell you the moment someone else grabs a copy. **The takeaway:** Ditch the "it won't happen to me" mindset, because it already did.
Spend twenty minutes changing your important passwords and turning on 2FA.
Final Thoughts
Your future self will thank you, probably right after you finish resetting your email for the fourth time this year.