Security

Is LastPass Still Safe After the 2022 Breach?

Updated: June 2026 · By KeyVaultUSA Editorial Team · 11 min read

Our Current Recommendation

We do not recommend LastPass for new users in 2025. If you currently use LastPass, we recommend switching to Bitwarden or 1Password. Here's why.

What Exactly Happened in the LastPass 2022 Breach

In August 2022, attackers gained access to LastPass's development environment. This was initially disclosed as a relatively minor incident. Then, in December 2022, LastPass revealed the full picture was far worse.

The attacker used information from the August breach to target a LastPass DevOps engineer. Through this employee's home computer, they accessed a cloud storage environment containing encrypted customer vault backups. The attacker stole:

  • Encrypted vault data (passwords, usernames, notes)
  • Unencrypted metadata: website URLs you have stored, your LastPass username, billing address, and IP addresses
  • Multi-factor authentication settings
⚠️
The Unencrypted URL Problem

Even though your passwords were encrypted, the website URLs were NOT encrypted. Attackers now know which sites you have accounts on — including banks, email providers, and sensitive accounts. This enables targeted phishing attacks.

Are You Still at Risk in 2025?

This depends on how strong your master password was at the time of the breach.

LastPass uses PBKDF2 with 100,100 iterations (now increased, but the stolen vaults used the old count for many older accounts). If your master password was weak or common, there's a real possibility attackers have already cracked it and have access to your stored passwords.

If your master password was long and truly random (16+ characters with mixed types), you are likely still safe — but the risk is not zero, and it grows over time as computing power improves.

Our Verdict: Should You Switch?

Yes, we recommend switching. Not because LastPass is definitively cracked, but because:

  • The breach revealed serious security culture problems at LastPass
  • Better alternatives exist at the same or lower price point
  • The peace of mind alone is worth switching
  • Bitwarden is free and arguably more trustworthy (open source)

Best LastPass Alternatives

Best Overall Switch

1Password

Easiest migration path from LastPass. Import your LastPass export file in minutes.

Switch to 1Password →
Best Free Switch

Bitwarden

Open source, free forever. Direct LastPass import. Zero cost to switch.

Switch to Bitwarden →

Related Articles You May Like

🔄
Reviews Best LastPass Alternatives 2025
⚖️
Comparison LastPass vs Bitwarden
🔒
Security Are Password Managers Safe?
🚨
Security What to Do After a Data Breach
🌑
Security Dark Web Monitoring Explained
🔄
How-To How to Switch Password Managers