Skip to main content
  1. Home
  2. Computing
  3. News

LastPass reveals how it got hacked — and it’s not good news

Add as a preferred source on Google

Last year was a particularly bad one for password manager LastPass, as a series of hacking incidents revealed some serious weaknesses in its supposedly rock-solid security. Now, we know exactly how those attacks went down — and the facts are pretty breathtaking.

It all began in August 2022, when LastPass revealed that a threat actor had stolen the app’s source code. In a second, subsequent attack, the hacker combined this data with information found in a separate data breach, then exploited a weakness in a remote-access app used by LastPass employees. That allowed them to install a keylogger onto the computer of a senior engineer at the company.

A depiction of a hacker breaking into a system via the use of code.
Getty Images

Once that keylogger was in place, the hackers could scoop up the engineer’s LastPass master password as it was entered, granting them access to the employee’s vault — and all the secrets contained within.

Recommended Videos

They used that access to export the contents of the vault. Nestled among the data were the decryption keys needed to unencrypt customer backups stored in LastPass’s cloud storage system.

That’s important because LastPass kept production backups and critical database backups in the cloud. A large amount of sensitive customer data was also stolen, although it appears the hackers were not able to decrypt it. A LastPass support page details exactly what was stolen.

Questionable transparency

Image used with permission by copyright holder

Luckily for LastPass users, it seems that customers’ most sensitive data — such as (most) email addresses and passwords — were encrypted using a zero-knowledge method. That means they were encrypted with a key derived from each user’s master password and unknown to LastPass. When the hackers stole LastPass data, they were unable to get these decryption keys because they were not stored anywhere by LastPass.

That said, plenty of important data was taken by the threat actors. That included backups of LastPass’s multi-factor authentication database, API secrets, customer metadata, configuration data, and more. As well as that, it seems numerous products apart from LastPass were also breached.

On a support page, LastPass said the way the second attack was carried out — by using genuine employee login details — made it difficult to detect. In the end, the company realized something was wrong when its AWS GuardDuty Alerts system warned it that someone was trying to use its Cloud Identity and Access Management roles to perform unauthorized activity.

A large monitor displaying a security hacking breach warning.
Stock Depot / Getty Images

LastPass has come in for plenty of criticism over its handling of the attacks in recent months, and that disapproval is unlikely to die down in light of the latest revelations. In fact, one security company went so far as to say that LastPass was not a trustworthy app and that users to switch to different password managers.

Right now, LastPass is apparently trying to hide its attack support pages from search engines by adding “<meta name=”robots” content=”noindex”>” code to the pages. That will only make it more difficult for users (and the wider world) to find out what happened and hardly seems to be done in the spirit of transparency and accountability. Nothing has been published on the company blog either.

If you’re a LastPass customer, it might be better to find an alternative app. Fortunately, there are plenty of other superb password managers out there that can reliably protect your important information.

Alex Blake
Alex Blake has been working with Digital Trends since 2019, where he spends most of his time writing about Mac computers…
Google’s new desktop mode makes one thing clear: Samsung DeX was onto something
Android 16 finally brings a real desktop mode to Pixel phones, but Google’s long-awaited move mostly proves Samsung spent years getting the hard parts right
File, Webpage, Person

I’ve been waiting for Android to take desktop mode seriously for years. Back in 2019, I bought a OnePlus 7 Pro and wasted an embarrassing amount of time trying to brute-force its half-baked desktop mode into something useful.

The idea made perfect sense to me even then. Phones were already absurdly powerful, and the thought of carrying one real computer in my pocket felt less like science fiction and more like delayed common sense.

Read more
Anthropic launches Claude design to simplify visual creation with AI
Finally, AI that designs your slides so you don’t have to
Claude

Anthropic has introduced a new AI-powered design tool called Claude Design, aimed at helping users create visual content such as prototypes, presentations, and marketing assets through simple conversational inputs. The product, developed under Anthropic Labs, is currently available in research preview for paid Claude subscribers and is being rolled out gradually.

Claude Design is powered by the company’s latest vision model, Claude Opus 4.7, and is positioned as a tool that bridges the gap between technical design expertise and everyday creative needs.

Read more
AI triggered a RAMmageddon so bad that Apple looks like the sensible choice
Laptop prices got so stupid in 2026, that Apple turned into the value king.
Student using MacBook Neo in classroom.

I really didn't want to believe it, but here we are. Apple is now looking like the sensible laptop brand. Not the cool underdog. Not the affordable alternative. Apple, in 2026. The reason is not that the company suddenly became generous, but rather the rest of the competition has suddenly become so deranged that a MacBook lineup starting at $599 feels weirdly grounded.

Apple's MacBook Neo starts at $599, while Microsoft's own 13-inch Surface Laptop now starts at $1,199 after this month's price hikes. This isn't a small gap that you can ignore. Meanwhile, Apple's MacBook Air with M5 starts at $1,099 with 16GB of memory and 512GB of storage, which looks like one of the few premium laptops still priced by human beings.

Read more