The email landed in inboxes like a bad dream that refused to end.
LastPass confirmed that a breach first disclosed in 2022 went further than many customers understood, with attackers walking off with encrypted vault data and, in some cases, the URLs of the sites you log into.
If you reused your master password anywhere, even once, years ago, this is the week it comes back to bite you.
Security experts have spent a decade telling Americans to use a password manager, to stop recycling the same login across banking, email, and shopping accounts.
They picked LastPass, synced their lives into it, and now sit in the uncomfortable position of being punished for following the advice.
Trust, once broken in the security business, does not quietly repair itself.
Attackers took encrypted vaults, which sounds safe until you remember that a vault is only as strong as the master password guarding it.
Weak, short, or reused master passwords can be cracked offline with enough time and computing power.
And because the stolen data included website addresses, criminals know exactly which targets are worth the effort.
Your bank login is a juicier prize than your pizza app password.
First, if you're still on LastPass, move your vault somewhere else.
Bitwarden, 1Password, and even Apple's and Google's built-in managers are reasonable alternatives.
Second, change the passwords for your most important accounts, starting with email, because whoever controls your email controls everything linked to it.
Third, turn on two-factor authentication everywhere it's offered, ideally with an app or hardware key rather than text messages.
Then there's the habit nobody wants to hear about.
A password manager makes unique passwords painless, but only if you actually let it generate them.
The people hit hardest in this saga aren't careless users.
They're ordinary Americans who trusted a brand and got a masterclass in why the security industry's favorite slogan, "trust us," was never a real answer.
We've handed our digital lives to a handful of companies, and when one of them stumbles, the fallout lands on households, not boardrooms.
Class action settlements pay lawyers and mail out checks worth less than a decent dinner.
The executives who oversaw the failure move on to other jobs.
You're left rotating passwords on a Tuesday night while a stranger somewhere scrolls through a list of every site you've ever cared about.
This is the quiet cost of convenience culture.
We outsourced memory to an app, and the app failed.
The lesson isn't that password managers are bad.
It's that any single point of failure in your digital life is a gamble, and most of us never bothered to ask what happened if the house lost.
Our take: the breach is a reminder that security is personal responsibility dressed up as a product, and no subscription fee buys you immunity.
If you haven't audited your passwords since 2022, tonight is the night.
Final Thoughts
The inconvenience of changing a dozen logins is nothing compared to the alternative.