logo

What Did the LastPass Breach Reveal About Password Manager Security?

ID: 944f52a9-d454-5271-aaa2-5d7b557c9e8b

STIX ID: report--944f52a9-d454-5271-aaa2-5d7b557c9e8b

Feed Name: SecurityScorecard Blog

Threat Score
85/100

Date Published: 2025-09-17

Date Updated: 2026-04-29

...
...

This report reviews the LastPass 2022–2023 breach in which attackers executed a two-stage compromise—initially breaching developer accounts and source code, then leveraging a vulnerable third-party package to access a DevOps engineer’s machine and exfiltrate cloud backups, customer metadata, and encrypted vault data; it details what was exposed (encrypted credentials and unencrypted metadata), the supply-chain and human-failure factors that amplified risk, and prescribes lessons for stronger master passphrases, verified zero-knowledge architecture, secure DevOps, and vendor visibility.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.