If you used LastPass to store your passwords, you already know the company got hacked.
What you may not realize is how long the fallout has dragged on—and what a new wave of reporting reveals about who's actually at risk.
It's the slow, ugly aftermath of one, and it's still reshaping how millions of Americans think about digital security.
Back in 2022, attackers broke into LastPass and walked off with encrypted customer vaults.
At the time, the company downplayed the danger, insisting that strong master passwords would keep everything safe.
That reassurance is now looking shaky, because attackers didn't just grab data and disappear.
They took it home and started grinding away at it.
The uncomfortable truth is that encryption is only as strong as the password protecting it.
If your master password was short, reused, or something you'd find in a dictionary, it may not hold up against modern cracking rigs.
Security researchers have repeatedly warned that weaker vaults are the ones most likely to fall first.
The people who thought they were fine are exactly the people who should be double-checking.
For starters, stop treating any single password manager as a vault you can set and forget.
Change your master password if you haven't already, and make it long—think a passphrase, not a clever word with a number tacked on.
Then go through your most important accounts, starting with email and banking, and rotate those passwords too.
We hand these apps the keys to our entire digital lives, then assume the company behind them will be flawless forever.
Breaches happen, and when they do, the vendor's first instinct is often damage control, not total honesty.
Treat every "your data is safe" email with a healthy dose of skepticism.
The whole point of a password manager is to make you more secure, and for most people it still does.
The alternative—reusing the same lame password everywhere—is objectively worse.
But the LastPass saga is a reminder that convenience and security are always pulling against each other, and you have to stay awake to which one is winning.
If you're still using LastPass, you don't necessarily need to flee in a panic.
But you should assume your vault could eventually be exposed and plan accordingly.
That means unique passwords everywhere, two-factor authentication switched on wherever it's offered, and a habit of reviewing your accounts before someone else does it for you.
The deeper pattern here is that we keep outsourcing our safety to companies that treat security as a feature, not a promise.
Until that changes, the smartest move is to assume you're one breach away from a bad week—and act like it. **Our take:** The real scandal isn't that LastPass got hacked.
It's how confidently everyone was told not to worry.
Final Thoughts
Stay skeptical, rotate your passwords, and never let a single app become the only thing standing between you and disaster.