LASTPASS▊
- OPERATION
- Password manager — "we protect your passwords"
- HABITAT
- ~30 million customer vaults
- EVENT
- CASCADING BREACH — Aug–Oct 2022, three months undetected FACT
- FALLOUT
- Feds link a $150M+ cyberheist to the stolen vaults (2025) ATTRIBUTED
- DISPOSITION
- UK ICO penalty Nov 2025; $24.5M class-action settlement Feb 2026 ADJUDICATED
Two weeks ago, we detected some unusual activity within portions of the LastPass development environment. After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults.
Karim Toubba, CEO, LastPass — the original August 25, 2022 breach notice, on the LastPass blog. The December 22, 2022 update to the same post disclosed that the attacker had copied a backup of customer vault data.
Observe the vault-keeper: an organism whose entire survival proposition is that it does not leak, filmed at the precise moment it leaked — slowly, for three months, through a hole in a keeper's home entertainment system.
The password manager is a concentration play. You surrender every credential you own to one vault on the promise that the vault is the one thing on the internet that will never open to the wrong hand. That promise is the entire product. There is no partial credit.
What the archive records here is not that LastPass was unlucky. It is that the crown jewels — the decryption keys — sat behind an engineer's personal Plex server, and that the harm did not end when the breach did. Vaults do not expire. Neither, apparently, does the theft. Every claim carries its receipt; the defense gets equal time.
the drama timeline
ACT I — "CONTAINED"
The first disclosure is calm, precise, and true in every word it chooses — which is a different thing from complete.
-
AUG 25 2022
Stage one: source code, and a reassurance
A developer's corporate laptop is compromised; the attacker takes 14 source-code repositories, technical docs, and an encrypted key protecting cloud backups. LastPass discloses it, says it is contained, and says no customer data was accessed. Accurate — and, because stage two is already underway, incomplete.
ACT II — THE PLEX SERVER
The predator does not attack the vault. It attacks the one keeper watching a movie at home.
-
AUG–OCT 2022
Three months inside, through a home media server
Using stage-one material, the attacker pivots to a senior DevOps engineer — one of only four people with the decryption keys — and exploits a known Plex vulnerability on his personal home computer to plant a keylogger. From Aug 12 to Oct 26 the attacker reads LastPass cloud storage, exfiltrating backups that contain the customer vaults, until AWS GuardDuty alerts finally surface it.
The keys to thirty million vaults were, functionally, one patch behind on a hobby server. The chain is only as strong as its most relaxed evening.
-
DEC 2022
The full scope: ~30M vaults
LastPass discloses the attacker took backups containing ~30M customer vaults — encrypted usernames/passwords/notes and unencrypted URLs, billing addresses, emails, and IP addresses. Older vaults used fewer PBKDF2 iterations and are more exposed to offline brute-force.
ACT III — THE THEFT THAT DOESN'T STOP
A stolen vault is not a spill to be mopped. It is a seed that germinates for years.
-
SEP 2023
The vaults start paying out — to someone else
Krebs on Security reports experts have traced roughly $35M in cryptocurrency theft to decrypted LastPass vaults — the offline cracking the December disclosure warned about, now producing losses.
-
2025–2026
$150M, an ICO penalty, and a settlement
By 2025 the U.S. Secret Service and TRM Labs attribute a $150M cyberheist to the same breach, laundering through mixers and OFAC-sanctioned exchanges. In Nov 2025 the UK ICO issues a £1,228,283 penalty; in Feb 2026 LastPass settles a class action for $24.5M, $16M of it earmarked for crypto losses.
Three years after the breach was "contained," it is still writing checks. The attribution is the government's; the settlements are the record's.
both sides, on the record
The one product promise, broken. A password manager's sole job is not leaking the vault; ~30M vaults left the building [1] [3].
The keys sat behind a hobby server. Decryption-key access ran through an engineer's personal Plex install, unpatched against a known bug [2].
The harm compounds. Feds and TRM trace $150M+ in theft to the stolen vaults — years later [4] [5].
The vaults were encrypted. Stolen fields remained under the customer's master password; LastPass's guidance turned on iteration counts and master-password strength, and strong modern vaults are materially harder to crack [3].
It disclosed and detailed. LastPass published incident updates and recommended-action guidance, and detection ultimately came from its own AWS GuardDuty tooling [1] [3].
Crypto attribution is investigators', not adjudicated against LastPass. The $150M figure is the Secret Service's / TRM's on-chain attribution to thefts enabled by the breach, not a court finding of LastPass liability for that sum [4].
YOU DECIDE
Scoped to the claims. The breach and its ~30M-vault scope are LastPass's own disclosures. The Plex-server pivot is documented. The $150M is investigators' attribution; the ICO penalty and the $24.5M settlement are on the record.
Weigh the costly signal: the concentration play only works if the vault is the one thing that never opens. For three months in 2022, the record says, it was ajar — and the draft is still blowing through.
The archive does not judge. It notes that a vault, once copied, is patient.
evidence locker
PRIMARY RECORD
PRESS & INVESTIGATIVE
The standard. The breach and its scope are sourced to LastPass's own disclosures. The Plex-server pivot is sourced to BleepingComputer and LastPass's update. The $150M crypto-theft figure is stated as the U.S. Secret Service's and TRM Labs' on-chain attribution — theft enabled by the breach, not a court finding of LastPass liability for that amount. The ICO penalty and $24.5M settlement are stated as adjudicated. The defense is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.