password-security-guideINFO

Is LastPass Safe in 2026? After the Breaches - Honest Verdict

Is LastPass safe after its 2022 vault breach and the June 2026 supply-chain incident? An honest 2026 look at what happened, how the encryption held (and where it didn't), what was and wasn't exposed, and whether to stay or switch to an audited alternative like NordPass or Bitwarden.

By Eric Gerard · Editor · PwdFortress6 min readPhoto via Unsplash

"Is LastPass safe?" is a fair question to ask in 2026, because the honest answer is shaped by a real event: the 2022 breach. LastPass still works and has hardened since, but its trust took a serious hit and many users migrated. This guide explains what actually happened, where the encryption held and where it didn't, and whether to stay or switch - factually, without hype.

If LastPass's track record worries you, compare it directly in Bitwarden vs LastPass.

The short answer

  • LastPass encrypts your vault and supports 2FA - it is not "broken" today.
  • But in 2022, attackers stole encrypted vault backups + customer metadata.
  • Master passwords were not stolen, so a strong, unique master password kept vaults safe - weak ones could be brute-forced offline from the stolen copies.
  • In June 2026, a supply-chain breach (via a third-party CRM) exposed customer contact data - but not vaults or encrypted passwords.
  • Trust was damaged; many users reasonably switched.

So "safe" depends heavily on your master password strength and whether you acted after the breaches.

Rows of servers in a data center
Rows of servers in a data center

What happened in 2022 (factually)

Attackers accessed LastPass systems and exfiltrated backups of customer vault data and account metadata (including saved URLs). The secret fields in vaults were encrypted with your master password, which LastPass does not store - so the encryption was not directly defeated. The genuine danger: anyone holding a stolen vault copy can attempt offline brute-force, which is feasible against a weak or reused master password. Hence the post-breach advice: change the master password and rotate stored credentials.

What happened in June 2026 (a different kind of breach)

In June 2026, LastPass confirmed a fresh data breach - but it's important to be precise about what it was, because it is not a repeat of 2022. This time the entry point was a supply-chain attack: around June 12, attackers compromised a third-party tool, Klue, and used stolen access keys to reach the Salesforce CRM accounts connected to it - including LastPass's. (LastPass wasn't the only Klue customer affected; BeyondTrust was caught in the same incident.)

What the attackers took was CRM and support data: customer names, phone numbers, email addresses, physical addresses, and support case records. According to LastPass, password vaults, products and core infrastructure were not affected, and encrypted passwords remained secure. An extortion crew calling itself Icarus claimed responsibility and threatened to leak the data unless paid.

So how worried should you be? Differently than in 2022. There is no indication your vault was exposed this time - the realistic risk is targeted phishing: someone who has your name, email, phone and the fact that you're a LastPass customer can craft a very convincing "LastPass security alert." Treat any unexpected LastPass message with suspicion, never click a login link from an email, and go to the site directly. The bigger-picture point is the pattern: by LastPass's own history this is roughly the eighth time customer data has been exposed since 2011 - and that track record, more than any single incident, is what the "is LastPass safe" question is really about. Sources: TechCrunch and TechRadar.

Did it expose your passwords?

Not directly if your master password was strong and unique. But because attackers hold offline copies indefinitely, weak master passwords remained at risk over time, and unencrypted metadata (like URLs) was exposed. If you were affected, treat high-value stored passwords (email, banking, crypto) as potentially at risk and rotate them - see what to do after a data breach for the full response.

Why a stolen vault is dangerous: offline brute-force

When attackers hold a copy of your encrypted vault, there's no server to rate-limit or lock them out - they can guess your master password offline, as fast as their hardware allows, for as long as they like. Two things decide whether that succeeds:

  • Master-password strength. A short or reused password falls quickly to a wordlist or brute-force run; a long, random passphrase is effectively out of reach.
  • Key-derivation iterations (PBKDF2). A password manager stretches your master password through many hashing rounds so each guess is costly. Older LastPass accounts were configured with far fewer iterations than current recommendations, which weakens offline resistance. If you stayed, open the security settings and raise the iteration count to the current default, then change the master password so it's re-encrypted at the stronger setting.

This is why the post-breach advice isn't paranoia: a stolen vault plus a weak master password is a slow-motion compromise.

Stay or switch?

This is a trust and risk-tolerance decision, not a claim that LastPass is unusable today.

A safer setup, whichever you choose

  • A strong, unique master password (a passphrase) - see what is a passphrase.
  • 2FA on the vault: authenticator app or hardware key - see best authenticator apps.
  • Unique passwords per site, generated by the manager, so one breach never cascades.

Audited zero-knowledge options - NordPass, Bitwarden, 1Password, Proton Pass - all fit this model.

If you used LastPass: your checklist

Whether you stay or leave, do these now - a stolen 2022 vault copy still exists somewhere:

  1. Change your master password to a long, unique passphrase (this re-encrypts the vault).
  2. Raise the PBKDF2 iteration count to the current default in security settings.
  3. Turn on 2FA for the vault - an authenticator app or hardware key.
  4. Rotate high-value credentials first - email, banking, crypto, then anything reused.
  5. If switching: export your vault, import into an audited zero-knowledge manager, then delete the LastPass vault and account.

Work top-down by value; you don't have to rotate everything at once, but do the critical accounts today.

The bottom line

LastPass in 2026 is usable but trust-damaged: it encrypts vaults and supports 2FA, yet the 2022 theft of encrypted vault backups means safety hinges on a strong master password and on having rotated credentials since. Staying is defensible with a strong master password and 2FA; switching to an audited, zero-knowledge manager with a clean record is the choice many made and is entirely reasonable. Either way, a long master passphrase plus 2FA is non-negotiable.

Editorial assessment based on the publicly documented 2022 LastPass breach (encrypted vault backups and metadata exfiltrated; master passwords not stored) and the standard zero-knowledge model of alternatives. We state the facts of the incident plainly without exaggeration. Commercial links carry the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.

Frequently asked questions

Is LastPass safe to use in 2026?

It is functional and has hardened since, but its trust was seriously damaged by the 2022 breach, and many users migrated away. The honest position: LastPass encrypts your vault and supports 2FA, but in 2022 attackers stole encrypted vault backups plus customer metadata. Master passwords were not in the stolen data, so a strong, unique master password kept vaults safe - but weak master passwords could be brute-forced offline from the stolen copies. If you stayed, you should already have a very strong master password and have rotated critical credentials. Many people reasonably choose an alternative with no comparable incident.

What exactly happened in the LastPass breach?

In 2022, attackers accessed LastPass systems and exfiltrated, among other things, backups of customer vault data and account metadata (such as URLs). Vault secret fields were encrypted with the user's master password, which LastPass does not store - so the encryption itself was not 'broken'. The real risk: anyone with a stolen vault copy could attempt offline brute-force against it, which is feasible if the master password was weak or reused. That is why post-breach guidance was to change the master password and rotate stored credentials.

Did the breach expose my passwords?

Not directly, if your master password was strong and unique. The stolen vault fields were encrypted, and the master password (the key) was not in the breach. But because attackers held offline copies, weak master passwords were vulnerable to brute-force over time, and unencrypted metadata like saved URLs was exposed. The safe assumption for anyone affected: treat critical stored passwords as potentially at risk and rotate them, especially high-value accounts (email, banking, crypto).

What happened in the June 2026 LastPass breach?

This one was different from 2022. In June 2026, LastPass confirmed that customer data was stolen through a supply-chain attack: attackers compromised a third-party tool (Klue) and used stolen keys to reach connected Salesforce CRM accounts, including LastPass's. The exposed data was contact and support information - names, phone numbers, email addresses, physical addresses and support case records. Crucially, LastPass stated that password vaults, products and core infrastructure were not affected, and encrypted passwords remained secure. An extortion group calling itself Icarus claimed the breach. So this was a CRM/contact-data exposure (which raises your risk of targeted phishing), not a vault compromise like 2022 - but it is the eighth time LastPass customer data has been exposed since 2011, which is itself the trust problem.

Should I switch away from LastPass?

It is a reasonable choice, and many did. If you stay, ensure a long, unique master password, 2FA, and that you have rotated important credentials since 2022. If you switch, audited zero-knowledge managers with no comparable breach - NordPass, Bitwarden, 1Password, Proton Pass - are strong options. The decision is about restored trust and your risk tolerance, not whether LastPass is 'broken' today; it is usable, but the bar for a credential vault is high.

What is a safer alternative to LastPass?

Audited, zero-knowledge password managers with clean track records: NordPass (XChaCha20, independent audits), Bitwarden (open-source, audited), 1Password (long security record), and Proton Pass (Swiss, end-to-end encrypted). All generate and store unique passwords per site behind one master secret. Pair any of them with strong 2FA, ideally an authenticator app or hardware key, and you are in good shape.