Attackers copied a backup of LastPass customer-vault data in 2022, including personal information and website URLs. Sensitive passwords and other vault fields were encrypted; the UK Information Commissioner’s Office (ICO) later said it found no evidence that attackers decrypted encrypted passwords. The stolen encrypted vaults still create risk, particularly for people whose master passwords were weak or reused.
How the LastPass breach unfolded
LastPass disclosed the theft on 22 December 2022. The attack built on an earlier incident in August 2022, when an intruder accessed source code and technical information. LastPass said information from that incident was then used to reach a cloud-storage environment and copy a backup of customer-vault data. In a March 2023 update, the company said its investigation found no threat-actor activity after 26 October 2022.
The ICO’s later account described a chain of compromises behind the attack. The attacker first compromised an employee’s corporate laptop and development access, then targeted a senior employee’s personal laptop. A keylogger captured that employee’s master password; the attacker bypassed multi-factor authentication using a trusted-device cookie and reached AWS storage and decryption keys kept in a business vault.
What information was taken?
The copied backup included personal information and a copy of the vault database. LastPass said some information was exceptions to the encryption applied to sensitive vault fields.
#1 Best Overall
- ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
- ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
- ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
- ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
- ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
| Data in the backup | What LastPass said about it |
|---|---|
| Names, email addresses and phone numbers | Customer information was included in the stolen backup. |
| Stored website URLs, Windows or macOS software file paths, and certain email-address use cases | These were exceptions to the encryption applied to sensitive vault fields. |
| Website usernames and passwords, secure notes, and form-filled data | These sensitive vault fields were encrypted. |
LastPass did not describe all customer information as encrypted. In particular, exposed URLs and personal metadata can reveal which services someone uses and may help an attacker tailor a phishing attempt.
Were LastPass passwords decrypted?
The ICO reported in 2025 that it found no evidence attackers were able to decrypt encrypted passwords and credentials. That is not the same as saying the stolen vaults were harmless or that every item in them was encrypted.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
LastPass said sensitive vault fields used 256-bit AES encryption, with a unique key derived from each user’s master password under its zero-knowledge design. Because the stolen backup contained encrypted vaults, an attacker could attempt to guess a master password offline, without repeatedly logging in to the victim’s account. This is a risk inference from the stolen encrypted data and the key-derivation design—not a finding that the ICO observed successful decryption. A weak or reused master password makes that risk more concerning.
A copy of a vault backup is distinct from live access to a LastPass account. The ICO’s finding does not establish that attackers could open every stolen vault, and it does not establish that a strong master password was cracked.
Rank #3
- Requires 3 "AAA" batteries (included)
- Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs
What should a LastPass user do?
If you used LastPass around the time of the incident, focus first on the master password and on accounts whose details would be especially damaging if exposed. These are precautionary steps based on the kinds of data taken and the offline-guessing risk; they do not imply that a particular account was decrypted.
- Replace a weak or reused master password. Choose a long, unique password or passphrase that you have not used on another service. A new password cannot recall a stolen backup, but it protects your current account and reduces the chance that an old password guess also works elsewhere.
- Change reused passwords on other services. Prioritize email, financial, work and other high-impact accounts if their passwords matched or resembled passwords stored in the vault.
- Use multi-factor authentication where available. It adds a barrier to account access if a password is exposed, though the incident shows that trusted-device mechanisms also need strong protection.
- Watch for targeted messages and unexpected account activity. The exposed URLs and personal details may make a convincing impersonation easier. Do not follow login links in unsolicited messages; go directly to the service’s known website or app.
What did the ICO fine LastPass for?
On 11 December 2025, the UK ICO announced a fine after concluding that the 2022 breach compromised personal information belonging to up to 1.6 million UK users. The formal enforcement record lists a penalty of £1,228,283, issued on 20 November 2025, for infringements of UK GDPR Articles 5(1)(f) and 32(1)(f). The ICO’s conclusion was that LastPass lacked sufficiently robust technical and organisational measures to protect the information.
Rank #4
Information Commissioner John Edwards said: “Password managers are a safe and effective tool for businesses and the public to manage their numerous login details and we continue to encourage their use.” The enforcement action concerns LastPass UK Ltd and the protection of UK users’ personal information; it is not a finding that all vault passwords were readable to the attackers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this breach means when assessing a password manager
The incident illustrates why security depends on more than whether vault contents are encrypted. When comparing password managers, useful questions include:
Recommended Free Tools
Best Value
- FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
- SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
- DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
- DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
- Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
- Are vault contents and URLs encrypted on the user’s device, or can the service access them?
- How are encryption keys derived, and does protection rely only on a master password?
- How are employee and administrator accounts, multi-factor authentication, and trusted devices protected?
- Are personal and business vaults separated, and how are cloud-backup keys stored?
- How clearly does the provider disclose incidents, and what do independent regulatory or audit findings establish?
The LastPass case supports asking these questions; it does not by itself establish comparative security scores for other providers.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

