LastPass
| Primary URL | Location | Industry | lastpass[.]com |
Country
United States of America
|
Technology
|
|---|
Profile
LastPass is a provider of password management solutions that enables individuals, families and organisations to store, generate and autofill login credentials and other sensitive information within an encrypted vault. The service is delivered through browser extensions, desktop applications and mobile apps, allowing users to access their vault across multiple platforms while maintaining synchronization. By offering features such as secure sharing, multi‑factor authentication and emergency access, LastPass serves a broad market that includes personal consumers seeking convenience, households looking to manage shared accounts and enterprises requiring centralized credential governance and compliance support. The company emphasizes a Zero Knowledge architecture, meaning that only the user possesses the master password capable of decrypting stored data, and it employs AES‑256 encryption combined with unique per‑user salts and iterative hashing to protect master passwords and vault contents. These technical controls are presented as core to its value proposition, aiming to ensure that even if the underlying storage is compromised, the actual credentials remain unreadable without the user’s secret.
Throughout its operational history LastPass has disclosed several security incidents that have shaped its security posture and response practices. In June 2026 a breach at a technology partner named Klue exposed customer support case records and personal details such as names, phone numbers, email addresses and physical addresses, although the company confirmed that its own infrastructure, including password vaults, remained uncompromised and no passwords or payment card data were accessed. In November 2022 attackers leveraged information from an earlier incident to infiltrate a shared third‑party cloud storage service, accessing certain customer data while reiterating that encrypted passwords stayed secure due to the Zero Knowledge model; this followed a prior intrusion into its developer environment that resulted in stolen source code and prompted the engagement of Mandiant and law‑enforcement notification. A separate November 2022 incident involved a threat actor compromising a DevOps engineer’s personal device via keylogger malware to capture a master password, which allowed exfiltration of decryption keys for cloud storage containing customer metadata and encrypted vault data, though sensitive fields stayed protected by AES‑256 encryption under the Zero Knowledge approach. Earlier, in June 2015, unauthorized network access led to the exposure of email addresses, password reminders, server salts and authentication hashes, but the encrypted vault data remained inaccessible, leading the firm to highlight its encryption practices and to introduce enhanced login verification for unrecognized devices. These events collectively illustrate LastPass’s focus on cryptographic safeguards, its reliance on third‑party relationships and its established procedures for incident investigation, stakeholder notification and remediation. The company’s headquarters is located in the United States of America.
