LastPass 2022 Incident: Password Manager Lessons
LastPass disclosed in 2022 that an attacker accessed its development environment and stole source code and technical information. Subsequent investigation found that information from the first event contributed to access to a cloud backup environment and exfiltration of encrypted and unencrypted data.
For customers, the incident raised two separate questions: what the provider protected cryptographically, and what each user must do to make an offline attack against encrypted vault data difficult.
Encrypted data still carried long-term risk
Encryption can limit exposure, but its practical strength depends on implementation and the user's master password. Unencrypted account metadata can also support targeted phishing and prioritization.
Organizations using a password manager needed to distinguish provider-required actions from broader precautionary rotation. Changing every secret without a plan can create outages while leaving high-risk credentials active too long.
Use password managers as part of a wider control system
Require strong, unique master passwords and MFA, protect recovery paths, monitor new devices and exports, and remove former users promptly. Prioritize rotation for privileged, externally reachable, reused, old, or weak secrets and for credentials associated with affected URLs.
Keep break-glass access and rotation ownership documented. Review API keys, SSH keys, certificates, service accounts, and recovery codes as well as human passwords.
- Encryption does not remove the need for strong master secrets.
- Metadata can improve attacker targeting.
- Secret rotation needs risk-based order and ownership.
- Provider incidents belong in identity response plans.
Put the lesson into practice
- Review the provider's current incident guidance.
- Enforce strong master passwords and MFA.
- Inventory privileged and machine secrets stored in vaults.
- Rotate highest-risk credentials first.
- Monitor for phishing, exports, and unusual new devices.
Related Outfaze guidance
- Managed multi-factor authentication
- Cloud security monitoring
- Managed detection and response
- Compliance as a Service
- Digital forensics and incident response
