LastPass Breach (2H22) – FAQ
Background & Summary LastPass released information on 22 December 2022 confirming that a threat actor had accessed backups of LastPass user vaults along with associated metadata likely connecting those vaults with customer identities. Technically this was a further update on previous partial disclosures, indicating that a breach in August 2022 was worse than they had initially thought (or let on). This is a bad headline for LastPass and its users, but the potential for an encrypted password vault to fall into the wrong hands is something that modern password managers are designed to be robust to. Information is still scant,
