← Back to Gadget Pulse US

LastPass Users Are Just Now Finding Out What Got Leaked

Persona #3 · Vol: 0

If you've been coasting on the assumption that your password vault is a digital Fort Knox, this week served up a fresh reminder that Fort Knox has a gift shop and someone left the back door open.

LastPass is back in the news, and not because it finally fixed its autofill.

The company is confirming that a recent breach exposed customer data, and the internet is handling it with its usual calm, measured grace, which is to say people are screaming into the void while frantically changing every password they've ever created.

Here's the short version: attackers got into a third-party cloud storage bucket tied to LastPass's backup systems.

The company says encrypted vault data stayed locked down, but unencrypted stuff like names, email addresses, billing addresses, phone numbers, and some IP address data walked out the door.

That's the kind of information that doesn't open your bank account, but it does make you a prime target for phishing emails that look suspiciously legit.

Naturally, LastPass is telling everyone to rotate their master password, enable multifactor authentication, and generally stop reusing "Fluffy2019" across seventeen different accounts.

Users are responding with the enthusiasm of a person told to floss more often.

The r/LastPass subreddit is currently a support group, a rage room, and a tech support line all at once, which is honestly impressive multitasking.

Security folks are split on the panic level.

Some say the encrypted vaults are still basically safe unless you had a weak master password, in which case, good luck.

Others point out that this isn't LastPass's first rodeo, and at some point you have to wonder why the horse keeps bucking.

The company has been breached before, and each time it promises things will be different.

That's the corporate equivalent of "I've changed, baby, I swear." The real takeaway here isn't about LastPass specifically.

It's that every password manager is a single point of failure with a really nice user interface.

You're trusting one company to guard the keys to your entire digital life, and companies are made of servers, and servers are made of problems.

If you're not using a physical security key or some form of two-factor authentication that doesn't rely on a text message, you're basically leaving your front door unlocked and hoping the neighborhood watch is feeling motivated.

Change your master password if you haven't already.

Turn on MFA everywhere it's offered, even the annoying apps.

Stop using the same password for your email and your bank, because that's the digital equivalent of using the same key for your house and your car.

And maybe, just maybe, consider whether you want to keep all your eggs in one basket that keeps getting shaken.

The upside is that password managers are still way better than the alternative, which is you trying to remember forty-seven unique passwords and inevitably defaulting to your dog's name plus the year you graduated.

The downside is that trusting any single company with your digital life is a gamble, and the house doesn't always win. **Our take:** LastPass has now been breached enough times that sticking with it feels less like a security decision and more like a loyalty test.

If you're still using it, at minimum rotate everything and turn on MFA.

Final Thoughts

If you're not, this is a decent nudge to finally try that password manager you keep hearing about, preferably one with a better track record and a security key option.

Continue Reading