Back to the archive

The encyclopedia · Software & IT · Operational decision · 2022

LastPass was hacked twice in 2022 — the second breach exposed password vaults

LastPass was breached in August and November 2022. The second breach exposed encrypted password vaults. Users were told to change all passwords.

LastPass · GoTo · 2022-11

What happened

In August 2022, LastPass, one of the most popular password managers, disclosed that hackers had accessed its internal systems and stolen source code. The company initially assured users that no customer data had been compromised.

In November 2022, LastPass disclosed a second, more serious breach: the hackers had used information from the first breach to access a third-party cloud storage service and steal encrypted customer password vaults. The vaults contained users' encrypted passwords, website URLs and other sensitive data.

The breach was particularly damaging because LastPass's entire value proposition was security: users trusted the service to protect their most sensitive credentials. The company was criticized for its initial downplaying of the first breach, its slow disclosure of the second, and its failure to protect the cloud storage backup. The case illustrated how a security company's breach is more damaging than any other company's breach, because the product is the trust.

Why it happened

  • The first breach (August 2022) exposed source code and was initially downplayed.
  • The second breach (November 2022) exposed encrypted customer password vaults.
  • LastPass's value proposition was security; the breach undermined the core product.
  • The company was criticized for slow disclosure and inadequate protection of backups.
What it costencrypted vaults exposed; user trust destroyed; brand damagecostly

The lesson

A security company's breach is a contradiction. LastPass sold trust, and the hackers stole it. When your product is security, transparency after a breach is the product.

Aftermath

LastPass was criticized by security researchers and lost users to competitors (1Password, Bitwarden). The company overhauled its security infrastructure. The case prompted a broader discussion about password manager security and the risks of centralized credential storage.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →