LASTPASS

OPERATION
Password manager — "we protect your passwords"
HABITAT
~30 million customer vaults
EVENT
CASCADING BREACH — Aug–Oct 2022, three months undetected FACT
FALLOUT
Feds link a $150M+ cyberheist to the stolen vaults (2025) ATTRIBUTED
DISPOSITION
UK ICO penalty Nov 2025; $24.5M class-action settlement Feb 2026 ADJUDICATED
Two weeks ago, we detected some unusual activity within portions of the LastPass development environment. After initiating an immediate investigation, we have seen no evidence that this incident involved any access to customer data or encrypted password vaults.

Karim Toubba, CEO, LastPass — the original August 25, 2022 breach notice, on the LastPass blog. The December 22, 2022 update to the same post disclosed that the attacker had copied a backup of customer vault data.

Observe the vault-keeper: an organism whose entire survival proposition is that it does not leak, filmed at the precise moment it leaked — slowly, for three months, through a hole in a keeper's home entertainment system.

The password manager is a concentration play. You surrender every credential you own to one vault on the promise that the vault is the one thing on the internet that will never open to the wrong hand. That promise is the entire product. There is no partial credit.

What the archive records here is not that LastPass was unlucky. It is that the crown jewels — the decryption keys — sat behind an engineer's personal Plex server, and that the harm did not end when the breach did. Vaults do not expire. Neither, apparently, does the theft. Every claim carries its receipt; the defense gets equal time.

the drama timeline

ACT I — "CONTAINED"

The first disclosure is calm, precise, and true in every word it chooses — which is a different thing from complete.

  1. AUG 25 2022

    Stage one: source code, and a reassurance

    A developer's corporate laptop is compromised; the attacker takes 14 source-code repositories, technical docs, and an encrypted key protecting cloud backups. LastPass discloses it, says it is contained, and says no customer data was accessed. Accurate — and, because stage two is already underway, incomplete.

ACT II — THE PLEX SERVER

The predator does not attack the vault. It attacks the one keeper watching a movie at home.

  1. AUG–OCT 2022

    Three months inside, through a home media server

    Using stage-one material, the attacker pivots to a senior DevOps engineer — one of only four people with the decryption keys — and exploits a known Plex vulnerability on his personal home computer to plant a keylogger. From Aug 12 to Oct 26 the attacker reads LastPass cloud storage, exfiltrating backups that contain the customer vaults, until AWS GuardDuty alerts finally surface it.

    The keys to thirty million vaults were, functionally, one patch behind on a hobby server. The chain is only as strong as its most relaxed evening.

  2. DEC 2022

    The full scope: ~30M vaults

    LastPass discloses the attacker took backups containing ~30M customer vaults — encrypted usernames/passwords/notes and unencrypted URLs, billing addresses, emails, and IP addresses. Older vaults used fewer PBKDF2 iterations and are more exposed to offline brute-force.

ACT III — THE THEFT THAT DOESN'T STOP

A stolen vault is not a spill to be mopped. It is a seed that germinates for years.

  1. SEP 2023

    The vaults start paying out — to someone else

    Krebs on Security reports experts have traced roughly $35M in cryptocurrency theft to decrypted LastPass vaults — the offline cracking the December disclosure warned about, now producing losses.

  2. 2025–2026

    $150M, an ICO penalty, and a settlement

    By 2025 the U.S. Secret Service and TRM Labs attribute a $150M cyberheist to the same breach, laundering through mixers and OFAC-sanctioned exchanges. In Nov 2025 the UK ICO issues a £1,228,283 penalty; in Feb 2026 LastPass settles a class action for $24.5M, $16M of it earmarked for crypto losses.

    Three years after the breach was "contained," it is still writing checks. The attribution is the government's; the settlements are the record's.

both sides, on the record

The one product promise, broken. A password manager's sole job is not leaking the vault; ~30M vaults left the building [1] [3].

The keys sat behind a hobby server. Decryption-key access ran through an engineer's personal Plex install, unpatched against a known bug [2].

The harm compounds. Feds and TRM trace $150M+ in theft to the stolen vaults — years later [4] [5].

The vaults were encrypted. Stolen fields remained under the customer's master password; LastPass's guidance turned on iteration counts and master-password strength, and strong modern vaults are materially harder to crack [3].

It disclosed and detailed. LastPass published incident updates and recommended-action guidance, and detection ultimately came from its own AWS GuardDuty tooling [1] [3].

Crypto attribution is investigators', not adjudicated against LastPass. The $150M figure is the Secret Service's / TRM's on-chain attribution to thefts enabled by the breach, not a court finding of LastPass liability for that sum [4].

YOU DECIDE

Scoped to the claims. The breach and its ~30M-vault scope are LastPass's own disclosures. The Plex-server pivot is documented. The $150M is investigators' attribution; the ICO penalty and the $24.5M settlement are on the record.

Weigh the costly signal: the concentration play only works if the vault is the one thing that never opens. For three months in 2022, the record says, it was ajar — and the draft is still blowing through.

The archive does not judge. It notes that a vault, once copied, is patient.

evidence locker

PRIMARY RECORD

  1. LastPass — Notice of Recent Security Incident (Dec 2022) FACT — the company's own disclosure. blog.lastpass.com/posts/notice-of-recent-security-incident
  2. LastPass — Security Incident Update & Recommended Actions (Mar 2023) FACT blog.lastpass.com/posts/security-incident-update-recommended-actions

PRESS & INVESTIGATIVE

  1. BleepingComputer — "DevOps engineer hacked to steal password vault data" ATTRIBUTED bleepingcomputer.com/…/lastpass-devops-engineer-hacked/
  2. Krebs on Security — "Feds Link $150M Cyberheist to 2022 LastPass Hacks" (Mar 2025) ATTRIBUTED krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/
  3. TRM Labs — on-chain tracing of the stolen-vault crypto ATTRIBUTED trmlabs.com/…/trm-traces-stolen-crypto-from-2022-lastpass-breach
  4. Cybersecurity Dive — the monthslong-attack timeline ATTRIBUTED cybersecuritydive.com/news/lastpass-cyberattack-timeline/
  5. Wikipedia — "LastPass 2022 data breach" (aggregated, footnoted) REFERENCE en.wikipedia.org/wiki/LastPass_2022_data_breach
The standard. The breach and its scope are sourced to LastPass's own disclosures. The Plex-server pivot is sourced to BleepingComputer and LastPass's update. The $150M crypto-theft figure is stated as the U.S. Secret Service's and TRM Labs' on-chain attribution — theft enabled by the breach, not a court finding of LastPass liability for that amount. The ICO penalty and $24.5M settlement are stated as adjudicated. The defense is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.