RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 22 December 2022 event · prepared 16 September 2026

LastPass's encrypted vault backups were stolen for offline attack

LastPass's own notices describe how a stolen backup put encrypted vaults beyond the company's ability to protect them further.

Visual for this record: LastPass's encrypted vault backups were stolen for offline attack
Visual published by informationage-production.s3.amazonaws.com, shown for identification of the record. Credit: informationage-production.s3.amazonaws.com · source page ↗ Rights: owner-review-pending.

What happened

LastPass disclosed in a security notice that an unauthorized party accessed its development environment in August 2022 and took source code and internal technical information. The company said that access was later used to compromise a senior DevOps engineer's personal computer through a vulnerable third-party media package, which let the intruder capture the engineer's master password with a keylogger after the engineer had already authenticated with multi-factor authentication, according to a supplemental technical account LastPass published. That master password unlocked a corporate vault holding decryption keys for cloud-storage backups, giving the intruder access to encrypted customer vault backups and to basic account data such as names, email addresses and billing information, spanning activity LastPass says ran from mid-August to late October 2022. LastPass disclosed the backup theft publicly on 22 December 2022 and published a further update with recommended customer actions on 1 March 2023.

Confidence and limits

Every fact here comes from LastPass's own published account; no government or independent forensic report has been opened for this article, so the timeline, the described attack chain and what was and was not accessed rest on the company's self-reporting alone. LastPass states master passwords are never known to, or stored by, the company, and that the vault backups themselves are encrypted, but this desk cannot independently verify the scope of what a determined attacker could ultimately recover from the stolen backups.

Why it mattered

Because the master password is the key that decrypts a stolen vault, and LastPass says it never held that password, the practical risk for most customers depends on how strong and how unique their own master password was and on the iteration count protecting it, factors outside the company's control after the backups were already copied. Unlike a typical breach where a company can reset credentials it controls, an offline copy of an encrypted vault can be attacked indefinitely, without triggering any lockout, rate limit or alert on LastPass's side, for as long as the attacker chooses to keep trying.

Defensive takeaway

If you or your organization used LastPass before this incident, treat every password stored in that vault as potentially exposed over time and prioritize rotating the highest-value credentials rather than assuming an unbroken master password made everything safe indefinitely.

  • Was your master password unique to LastPass, of meaningful length, and protected by a strong key-derivation iteration count?
  • Which credentials in an old vault would cause the most damage if recovered years from now, and have those been rotated regardless of this incident?
  • Does your organization's password-manager vendor selection process ask how customer key material is protected on the vendor's own employees' devices?

The incident is a reminder that a password manager concentrates risk as well as reducing it: it removes the burden of remembering many passwords but makes the single master credential, and whatever protects the people who administer the service, the entire perimeter.

Defensive takeaway

Treat any password stored in a LastPass vault from before this incident as potentially exposed over time, and prioritize rotating the highest-value credentials rather than assuming vault encryption alone made them safe indefinitely.

Every detail here comes from LastPass's own published notices and technical account; no independent forensic or regulatory report has been opened for this article, so the scope of what was ultimately accessed rests on the company's self-reporting.

Sources & reading trail

Notice of Recent Security Incident ↗

LastPass's account of the August 2022 development-environment access and the November 2022 cloud-storage backup theft.

company-primary · Source published: 22 December 2022 · Retrieved: 16 September 2026

Security Incident Update: Recommended Actions ↗

Details what was encrypted versus unencrypted in the stolen backups, confirms master passwords were never held by LastPass, and lists recommended customer actions.

company-primary · Source published: 1 March 2023 · Retrieved: 16 September 2026

Incident 2 – Additional details of the attack ↗

Describes how the DevOps engineer's home computer was targeted and how the captured master password led to the cloud-storage decryption keys.

company-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.