vikrant69g blog

LastPass breach number three: the password manager that cannot secure passwords

LastPass notified users of another breach. This is the third major incident since 2022. At what point do we stop calling it a password manager and start calling it a credentials museum.

Stylised broken padlock with scattered password fragments on dark background

LastPass sent out breach notifications again. Third time since 2022. The pattern is familiar: unauthorised access to internal systems, customer vault data potentially exposed, immediate password reset recommendations, vague timeline. The company’s statement says attackers accessed encrypted vault data. Encryption is only as strong as the master password, and LastPass knows a non-trivial percentage of users pick weak ones. They cannot enforce strong master passwords without locking out paying customers who forget them. The business model creates the security hole. What surprised me is how many people in the HN thread are still using LastPass. The 2022 breach exposed encrypted vaults and unencrypted URLs, which is enough to map your digital life. The 2024 breach compromised internal credentials. Now this. The company has shown it cannot defend the castle, yet the moat remains full. The alternative is not convenient. 1Password, Bitwarden, and KeePassXC all require you to trust someone or host it yourself. Self-hosting means you are the weak link. Trusting a vendor means you hope their security is better than LastPass’s, which is a low bar but not a guarantee. I moved to Bitwarden after 2022. The vault export was painless. The import took ten minutes. The friction was psychological, not technical. Every password manager migration feels like admitting you picked wrong the first time. If you are still on LastPass after three breaches, the question is not whether to leave. It is what you are waiting for.


Source: LastPass notifies users of yet another data breach