LastPass A.I CyberSecurity Scoring
LastPass
Company Information
Website:https://www.lastpass.com/
Employees number:713
Number of followers:42,443
NAICS:541514
Industry Type:Computer and Network Security
Homepage:lastpass.com
LastPass Risk Score (AI oriented)
Between 0 and 549
LastPassComputer and Network Security
Updated:
15/07/2026
15/07/2026
100/1000
Critical
C
LastPass Global Score (TPRM)
xxxx
LastPassComputer and Network Security
Score locked

LastPassCritical
Current Score
100C (CRITICAL)
01000
18 incidents
-168 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
100
JULY 2026
100
JUNE 2026
100
Breach
25 Jun 2026 • LastPass
Klue: Klue Hit by Double Extortion as Second Hacker Group Emerges
Klue Faces Unprecedented Dual Extortion Attack After Data Breach
100
CRITICAL0
KLU1782428022
Klue Faces Unprecedented Dual Extortion Attack After Data Breach
Vancouver-based market intelligence platform Klue has disclosed a rare and escalating cybersecurity crisis, involving two criminal groups with conflicting extortion demands following a data breach. The incident, first reported by TechCrunch, marks an unusual case of competing threats targeting the same victim highlighting evolving tactics in cyber extortion.
The breach initially involved a hacking group that stole sensitive customer data, including proprietary market research, competitive analysis, and strategic planning materials used by enterprise clients to track rivals. In a surprising turn, the original attackers later claimed they were deleting the stolen files, though Klue’s customers were warned not to assume the threat had passed. Before any relief could set in, a second criminal group emerged, demanding ransom for the same compromised data.
The situation leaves Klue’s enterprise clients including sales and marketing teams at major corporations in limbo, uncertain whether their highly sensitive business intelligence has been destroyed, leaked, or is now in the hands of multiple threat actors. The competitive intelligence sector handles particularly valuable data, such as go-to-market strategies and product roadmaps, which could cause significant damage if exposed.
Security researchers note that while secondary markets for stolen data are not new, the simultaneous, opposing claims from two criminal groups are highly unusual. The first group’s alleged data deletion could be a face-saving exit or genuine reversal, while the second group’s demands suggest they either independently accessed Klue’s systems or acquired the data from the original attackers.
Klue has not disclosed technical details of the breach, the scope of compromised data, or the number of affected customers. The incident underscores the cascading risks of B2B SaaS breaches, where third-party vendors handling critical business intelligence become high-value targets. It also arrives amid growing enterprise concerns over vendor security postures, following high-profile breaches at platforms like Okta and LastPass.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
100
Breach
24 Jun 2026 • LastPass
LastPass: Looking for a New Password Manager After the LastPass Data Breach? Here's the Best Way to Switch
LastPass Breach Prompts Password Manager Migration Concerns
100
CRITICAL0
LAS1782311873
LastPass Breach Prompts Password Manager Migration Concerns
LastPass recently revealed that subscriber data may have been compromised due to a breach at a third-party service provider, raising security concerns among users. For those considering a switch, transitioning to a new password manager requires careful planning to ensure a seamless transfer of credentials.
Before migrating, users should evaluate alternative password managers for key features such as secure credential storage, password generation, auto-fill capabilities for web and mobile apps, multi-factor authentication (MFA), digital legacy options, and additional security tools like VPNs. Many services offer free trials, allowing users to test functionality before committing.
Two primary methods exist for transferring passwords:
1. Export and Import – Users can export their existing passwords and form-filling data into a file (often a CSV or service-specific format) and import it into the new manager. However, CSV files may not retain all stored data, such as addresses or payment details, and some managers have limited import compatibility.
2. Dual-Manager Transition – Since most password managers can run simultaneously, users can install a new service while keeping the old one active. The new manager will capture login credentials as they are used, though this method may miss infrequently accessed passwords.
The breach highlights the importance of secure password management and the growing adoption of passkeys a passwordless authentication method supported by leading password managers and platforms like Apple and Google. Users seeking alternatives can explore options tailored for personal or business use, prioritizing security, usability, and feature depth.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
100
Breach
11 Jun 2026 • LastPass
Klue and LastPass: LastPass customer info leaked again after third-party data breach
LastPass Warns Users of Third-Party Breach Exposing Personal Data
100
CRITICAL0
LASKLU1782319113
LastPass Warns Users of Third-Party Breach Exposing Personal Data
LastPass has notified customers that their personal information was compromised in a June 11 breach of Klue, a third-party market intelligence firm. The stolen data includes names, phone numbers, email and physical addresses, as well as support case and sales-related records. While LastPass emphasized that its own systems and customer vaults remain unaffected, the incident has raised concerns about downstream risks.
The cybercrime group Icarus has claimed responsibility for the attack and is reportedly contacting users with threats to leak their data. Multiple cybersecurity firms using Klue have also experienced data exposure, increasing the potential for phishing and social engineering attacks targeting affected individuals.
The breach adds to LastPass’s troubled security history, particularly its 2022 incidents, which resulted in significant financial losses. Ripple co-founder Chris Larsen lost $150 million in crypto after his private keys were exposed in the 2022 breach. Cybersecurity researcher ZachXBT later linked the incident to additional thefts, including $5.4 million from over 40 addresses in 2024 and $4.4 million from 25 victims in 2023. Two individuals tied to the "AudiA6" crypto-laundering operation were also found to have processed stolen funds from LastPass users.
Last year, the UK’s Information Commissioner’s Office fined LastPass £1.2 million for the 2022 breach, citing inadequate security measures that allowed unauthorized access to its backup database, impacting 1.6 million UK users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
100
APRIL 2026
100
Cyber Attack
14 Apr 2026 • LastPass
LastPass and Google: Omnistealer uses the blockchain to steal everything it can
Omnistealer: Malware Exploiting Blockchain for Undeletable Command-and-Control
100
CRITICAL0
LASGOO1776169942
Omnistealer: How Malware Exploits Blockchain for Undeletable Command-and-Control
A newly identified info-stealer, Omnistealer, is leveraging public blockchains like TRON, Aptos, and Binance Smart Chain to host its malicious infrastructure making it nearly impossible to remove. Unlike traditional malware that relies on platforms like GitHub or Google Drive (which can be taken down), Omnistealer embeds encrypted commands, malware fragments, and staging code within blockchain transactions. Since blockchains are append-only and immutable, these malicious snippets remain permanently accessible, creating a censorship-resistant command-and-control (C2) network that evades takedown efforts.
Once deployed, Omnistealer acts as a comprehensive data harvester, targeting:
- Over 10 password managers, including LastPass and cloud-synced tools.
- Major browsers (Chrome, Firefox) to extract saved logins and session data.
- Cloud storage credentials, such as Google Drive.
- More than 60 crypto wallets, including MetaMask and Coinbase Wallet.
The attack chain typically begins with social engineering: victims receive fake job offers via LinkedIn or Upwork, luring them into downloading and executing code from a seemingly legitimate GitHub repository. This code then fetches the final payload by reading encrypted data from blockchain transactions.
Researchers estimate that 300,000 credentials have already been compromised, affecting sectors ranging from financial compliance and defense suppliers to U.S. government entities. The malware’s persistence rooted in blockchain’s decentralized nature poses a significant challenge for defenders, as traditional remediation methods (e.g., domain takedowns) are ineffective against immutable ledger entries.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
100
Breach
10 Mar 2026 • LastPass
Salesforce, Snowflake, Okta, Sony, LastPass and AMD: Salesforce Customer Data Breach Linked to ShinyHunters
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft
100
CRITICAL0
SALLASAMDSNOSONOKT1773153462
ShinyHunters Exploits Salesforce Experience Cloud Misconfigurations in Large-Scale Data Theft
The hacking group ShinyHunters has claimed responsibility for stealing data from approximately 100 major companies by exploiting misconfigurations in Salesforce’s Experience Cloud platform. According to reports, the group accessed information from around 400 websites and organizations, including high-profile targets like Snowflake, Okta, LastPass, Sony, AMD, and Salesforce itself.
Salesforce confirmed that a "known threat actor group" is actively scanning public-facing Experience Cloud sites portals used for customer, partner, and employee interactions due to overly permissive guest user configurations. The company clarified that the issue stems from customer-defined guest user profiles, not a vulnerability in Salesforce’s core platform.
### How the Attack Works
Experience Cloud sites can be configured to allow guest users (unauthenticated visitors) to view public pages and submit forms. However, if these guest profiles are granted excessive permissions, attackers can query and extract CRM data that was never intended to be public.
ShinyHunters reportedly used a modified version of AuraInspector, an open-source tool originally designed by Mandiant to detect misconfigurations in Salesforce’s Aura endpoints. The altered tool enables mass scanning of public-facing sites, extracting data when guest permissions are too broad.
### ShinyHunters’ Track Record
Active since 2019, ShinyHunters has been linked to numerous high-profile breaches, often employing "pay or leak" tactics demanding ransoms to prevent data exposure. Recent incidents include the 2024 Snowflake breach, as well as attacks on universities and consumer platforms, leveraging phishing, social engineering, and SaaS misconfigurations.
### The Broader Risk of Misconfiguration
This incident highlights a persistent cybersecurity challenge: misconfiguration remains a leading attack vector. While SaaS platforms like Salesforce offer robust security controls, human error in permission settings can expose sensitive data. Experience Cloud’s flexibility designed for public-facing portals becomes a liability when guest user profiles are improperly configured, allowing unauthorized access to CRM records.
### Salesforce’s Response & Mitigation Steps
Salesforce has urged customers to:
- Audit guest user permissions across all Experience Cloud sites.
- Set default external access to "private" to block unauthenticated queries.
- Disable guest access to public APIs and remove API-enabled permissions from guest profiles.
- Monitor logs for unusual activity, such as large-scale scanning attempts.
The incident underscores the need for ongoing security reviews rather than one-time configurations, as cloud environments evolve and threat actors refine their tactics. With regulatory scrutiny and reputational risks escalating, enterprises must treat access control and governance as continuous priorities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
100
JANUARY 2026
100
Cyber Attack
19 Jan 2026 • LastPass
LastPass and Amazon Web Services: LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords
Critical Phishing Campaign Targets LastPass Users in Sophisticated Attack
100
CRITICAL0
LASAMA1769009064
Critical Phishing Campaign Targets LastPass Users in Sophisticated Attack
A high-severity phishing campaign targeting LastPass users began on January 19, 2026, with attackers impersonating the company’s support team to steal master passwords. The fraudulent emails falsely claim an urgent need for vault backups within 24 hours, leveraging social engineering to exploit user trust.
LastPass has confirmed that it never requests master passwords or demands immediate vault backups via email, emphasizing that legitimate communications avoid unsolicited urgent actions. The campaign was strategically launched over a U.S. holiday weekend, a tactic designed to capitalize on reduced security staffing and slower incident response times commonly exploited by threat actors to evade detection.
The phishing infrastructure relies on two key components: an initial redirect hosted on compromised AWS S3 buckets and a spoofed domain mimicking LastPass’s legitimate services. LastPass is actively working with third-party partners to dismantle the malicious infrastructure and urges users to delete any suspicious emails and report them to [email protected] for further analysis.
Organizations are advised to bolster email security controls to block messages from identified sender addresses and reinforce phishing awareness, particularly regarding urgent language and credential requests. The incident underscores the persistent risk of credential harvesting campaigns targeting password manager users.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
100
Vulnerability
01 Jan 2026 • LastPass
LastPass, Bitwarden and Dashlane: 25 Flaws Found in Cloud Password Managers Allow Unauthorized Access and Data Manipulation
Critical Vulnerabilities Exposed in Major Cloud Password Managers
100
CRITICAL0
DASLASBIT1771317146
Critical Vulnerabilities Exposed in Major Cloud Password Managers
Researchers from ETH Zurich’s Applied Cryptography Group have uncovered 25 severe security flaws in popular cloud-based password managers, including Bitwarden, LastPass, and Dashlane, which collectively serve around 60 million users worldwide. The findings challenge the long-held assumption of "zero-knowledge encryption" a security model where data remains encrypted even if servers are compromised.
Led by Professor Kenneth Paterson, the team simulated a malicious server threat model, testing how browser extensions responded when servers were compromised. The results revealed client-side vulnerabilities that could allow attackers with server access to view, modify, or delete stored passwords, logins, and sensitive data. Bitwarden was found to have 12 vulnerabilities, LastPass 7, and Dashlane 6, with some flaws enabling full organization vault compromises or unauthorized access via sync manipulation.
Key issues stem from outdated cryptographic practices and user-friendly features like password recovery and sharing, which introduce complexity and expand the attack surface. Doctoral student Matteo Scarlata noted that many vendors rely on 1990s-era encryption to avoid disrupting users or causing downtime, undermining the security guarantees of zero-knowledge architectures.
The vulnerabilities, assigned CVE IDs with CVSS scores ranging from 7.5 to 8.5, include:
- Bitwarden: Unauthorized vault access, integrity violations in shared credentials, and full organization vault compromise.
- LastPass: Password recovery bypass and credential modification attacks.
- Dashlane: Legacy crypto decryption leaks.
The researchers followed responsible disclosure, giving vendors 90 days to address the flaws. While patches are now being rolled out, the findings highlight a critical weakness: even encrypted data can be manipulated if servers are compromised. The incident underscores the need for regular external audits, transparent security practices, and migration to modern cryptographic standards rather than relying on incremental fixes.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
152
Breach
25 Dec 2025 • LastPass
LastPass: LastPass Settlement Reaches Up to $24 Million After Data Breach
LastPass Data Breach and Settlement
100
CRITICAL-52
LAS1766649509
LastPass Settles Lawsuit for Up to $24 Million Following Data Breach
LastPass, a widely used password manager, has agreed to a settlement of up to $24 million after a lawsuit stemming from a 2022 data breach. The agreement includes $8.2 million for data-protection claims and up to $16.25 million to reimburse users for cryptocurrency losses linked to the incident.
### The Breach and Its Impact
In the attack, hackers accessed sensitive user data, though stored passwords remained encrypted. However, some customers reported unauthorized access to crypto wallets connected to their LastPass accounts, leading to financial losses. The breach raised concerns about the security of password managers, which users rely on to protect digital assets and personal information.
The lawsuit alleged that LastPass failed to adequately safeguard user data, exposing customers to privacy risks and financial harm.
### Settlement Details
Eligible users will be notified about how to submit claims. Payouts will vary based on verified losses:
- $8.2 million allocated for data-protection claims.
- Up to $16.25 million for crypto loss reimbursements.
### Broader Implications
The settlement underscores the real-world consequences of data breaches, even for trusted security tools. While password managers enhance convenience, this incident highlights their vulnerabilities and the need for robust security measures.
For LastPass, the case has prompted security improvements, including stronger encryption, enhanced safeguards, and more transparent user updates. The company has pledged to prevent future breaches, though the incident serves as a reminder that no service is immune to cyber threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
142
OCTOBER 2025
277
Breach
15 Oct 2025 • LastPass
LastPass UK Limited: Recent ICO Data Breach Enforcement Emphasizes the Importance of a Robust Breach Response
UK ICO Imposes £15 Million in GDPR Fines on Capita and LastPass for Cybersecurity Failures
124
CRITICAL-153
LAS1770195780
UK ICO Imposes £15 Million in GDPR Fines on Capita and LastPass for Cybersecurity Failures
In late 2025, the UK Information Commissioner’s Office (ICO) levied a combined £15 million in GDPR fines against Capita plc and Capita Pension Solutions Limited (fined £14 million on 15 October 2025) and LastPass UK Limited (fined £1.2 million on 20 November 2025) for data breaches resulting from cyberattacks.
The ICO’s decisions highlight critical enforcement trends, including its strict expectations for proactive cybersecurity measures. In Capita’s case, the regulator determined that inadequate penetration testing, understaffed security operations, and weak administrator access controls created avoidable vulnerabilities exploited by attackers. Despite acknowledging the costs of robust security, the ICO rejected resource constraints as justification for lapses, particularly for organizations handling high-risk data.
The rulings also emphasize the NCSC’s cybersecurity guidance as a benchmark for "appropriate" GDPR compliance. Internal documents such as Capita’s penetration test reports were cited as evidence of security weaknesses, underscoring the legal risks of unprotected internal assessments. Companies are advised to consider privilege protections for sensitive security findings to limit exposure.
The ICO set a high bar for mitigating factors. LastPass’s cooperation, though deemed "good," was not considered exceptional, while Capita’s 14-hour GDPR notification (well ahead of the 72-hour deadline) failed to reduce its penalty. The regulator expects continuous, engaged responses rather than one-time compliance efforts.
Notably, LastPass’s fine was calculated based on its holding company’s global revenue, not just its own turnover, aligning with EU precedent. This approach could significantly impact private equity and investment firms, as fines may extend to broader corporate groups.
The cases signal the ICO’s uncompromising stance on data protection, with enforcement actions targeting both technical oversights and structural accountability.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Cyber Attack
15 Oct 2025 • LastPass
LastPass
Ongoing Phishing Campaign Targeting LastPass, Bitwarden, and 1Password Users with Fake Security Alerts
124
HIGH-153
LAS3302433101625
An ongoing phishing campaign targeted LastPass users via fake emails claiming the company was hacked, urging them to download a malicious desktop version of the password manager. The attack exploited social engineering tactics, impersonating LastPass with urgency-driven messages from domains like ‘hello@lastpasspulse[.]blog’. The downloaded binary installed Syncro, a legitimate remote monitoring tool repurposed to deploy ScreenConnect, granting attackers persistent remote access. While LastPass confirmed no breach occurred, the campaign aimed to steal vault credentials by tricking users into installing malware disguised as a security update. The threat actors leveraged reduced holiday staffing (Columbus Day weekend) to delay detection. Cloudflare later blocked the phishing landing pages, but the attack demonstrated sophisticated use of legitimate tools (Syncro/ScreenConnect) to bypass defenses, disable security agents (Emsisoft, Webroot, Bitdefender), and exfiltrate sensitive data from compromised endpoints.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
573
Ransomware
03 Oct 2025 • LastPass
Salesforce
Scattered Lapsus$ Hunters Ransomware Attack on Salesforce Customer Data via Salesloft Drift Integration
274
CRITICAL-299
SAL5592855100325
The ransomware group ShinyHunters (Scattered Lapsus$ Hunters) breached Salesforce by exploiting stolen OAuth tokens from Salesloft Drift’s AI chatbot integration, compromising 1.5 billion records across 760 companies (including Cisco, Disney, and Marriott). The leaked data includes PII (names, DOBs, passports, employment histories), shipping details, chat transcripts, flight records, and car ownership data—validated by cybersecurity researchers. Attackers first infiltrated Salesloft’s GitHub repository, extracting private source code and OAuth tokens, then laterally moved to Google Workspace, Microsoft 365, and Okta platforms of victims. The group demanded separate ransoms from Salesforce and listed 39 high-profile victims on a darkweb leak site, pressuring them to pay under threat of full data exposure. The attack leveraged social engineering (vishing, phishing, IT impersonation) to trick employees into granting access, highlighting vulnerabilities in third-party supply-chain integrations and weak 2FA/OAuth security controls.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
573
JUNE 2025
559
Breach
12 Jun 2025 • LastPass
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
495
CRITICAL-64
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential
In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations.
### What Happened?
On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress.
Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed.
### How the Attack Unfolded
The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain.
### Key Victims & Impact
While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span:
- Password management (LastPass)
- Privileged access (BeyondTrust)
- Endpoint security (Tanium, Jamf)
- Threat intelligence (Recorded Future)
- Bug bounty coordination (HackerOne)
- Application security (Snyk)
Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure.
### Broader Context: A Year of Supply Chain Attacks
The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses.
### Regulatory & Industry Reactions
- Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene.
- Security vendors on the victim list face heightened procurement questions from enterprise buyers.
- Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications.
### Lessons from the Breach
The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires:
- Automated expiration for pilot credentials.
- Minimum-scoped OAuth grants (avoiding broad CRM access).
- Recurring token audits to identify stale integrations.
As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2025
601
Breach
01 Jan 2025 • LastPass
LastPass and Apple: New AI Scams Are Targeting You, LastPass Was Breached Again, and an Urgent Warning for Apple Owners
LastPass Security Incident Involving Third-Party Tool
536
CRITICAL-65
LASAPP1782793516
Cybersecurity Roundup: LastPass Breach, AI Scams, and Emerging Threats
This week in cybersecurity brought a mix of high-profile breaches, AI-driven fraud, and evolving threats targeting personal data.
LastPass Suffers Another Breach
LastPass disclosed a security incident involving a third-party tool, resulting in the theft of customer contact information and physical addresses. While passwords and vault data remained secure, the breach marks another setback for the password manager, which has faced repeated security challenges. The incident underscores the risks of relying on third-party services in critical security infrastructure.
AI-Powered Scams Cost Americans Nearly $900 Million in 2025
The FBI’s 2025 Internet Crime Report revealed that AI-enabled scams drained nearly $900 million from U.S. victims last year, with older adults disproportionately targeted. AI tools have made it easier for scammers to craft convincing phishing emails, fraudulent ads, and fake websites, amplifying the scale and sophistication of attacks. The FBI warned that without intervention from AI developers, these threats will continue to escalate.
Dark Web Markets Automate Stolen Credential Sales
Security researchers at Flare uncovered a growing "malware-as-a-service" model on dark web forums, where hackers now offer targeted credential searches for specific individuals or platforms. Instead of selling bulk data, cybercriminals now provide curated results complete with customer reviews making it easier for attackers to launch spear-phishing campaigns or identity theft. AI-driven automation has streamlined the process, turning stolen data into a more accessible commodity.
Apple Devices Face "Unpatchable" Security Flaw
Older iPhones, iPads, Apple TVs, and Studio Displays are affected by an "unpatchable" vulnerability that requires physical access to exploit. While the risk is limited, the flaw highlights the challenges of securing aging hardware, as researchers recommend upgrading to newer devices as the only viable solution.
Anthropic Considers ID Verification for Claude Users
AI firm Anthropic is exploring government ID verification for users flagged for fraudulent activity, citing compliance with age-verification laws and internal fraud prevention. The move, outlined in an updated privacy policy, raises concerns about data security, given the rising number of breaches involving stolen IDs. The company’s shift comes amid regulatory pressure and efforts to improve relations with government agencies.
VPNs and Streaming: A Cat-and-Mouse Game
A deeper look at VPN usage for bypassing geo-restrictions revealed that streaming services frequently block VPN traffic, with success varying by provider. While VPNs remain a key security tool, their effectiveness for accessing restricted content fluctuates as platforms refine detection methods.
From password managers to AI-driven fraud, this week’s developments highlight the persistent and evolving nature of cyber threats.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2022
650
Breach
01 Aug 2022 • LastPass
LastPass
LastPass Data Breach
586
CRITICAL-64
LAS25527822
An unauthorized party gained the access to a cloud-based password security site, LastPass suffered a data security breach that resulted in the theft of certain source codes and technical information.
They targeted its development environment. No customer data or encrypted passwords were accessed.
Amidst investigated the incident and they engaged the services of a leading cybersecurity and forensics firm and they implemented additional countermeasures.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2022
585
Cyber Attack
16 Jun 2022 • LastPass
LastPass
Phishing Campaign Targeting LastPass Users via Fake Legacy Inheritance Process
524
CRITICAL-61
LAS1192211102425
LastPass is warning customers about an ongoing phishing campaign by the financially motivated threat group CryptoChameleon (UNC5356), targeting its users since mid-October. The attack involves fraudulent emails impersonating LastPass’s legacy inheritance process, claiming a family member requested access to the victim’s password vault via a fake death certificate. Users are tricked into clicking a malicious link redirecting them to a spoofed login page (lastpassrecovery[.]com), where they are prompted to enter their master password. In some cases, attackers also posed as LastPass support staff via phone calls to manipulate victims further.The campaign has evolved to include passkey-focused phishing domains (e.g., mypasskey[.]info), indicating attempts to steal modern authentication credentials. This follows LastPass’s 2022 breach, where encrypted vault backups were stolen, leading to subsequent cryptocurrency thefts totaling $4.4 million. The latest attack exploits psychological manipulation and technical deception to compromise user accounts, potentially granting attackers access to sensitive credentials stored in LastPass vaults.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2022
701
Breach
01 Jan 2022 • LastPass
LastPass: LastPass Gets Initial Nod for $24.5 Million Data Breach Deal
LastPass 2022 Data Breach Settlement
565
CRITICAL-136
LAS1770196017
LastPass Reaches $24.5 Million Settlement Over 2022 Data Breach
LastPass, a leading password-security provider, has received preliminary approval from a U.S. federal court to settle a proposed class-action lawsuit stemming from a 2022 data breach. The breach exposed the personal information of millions of users and led to the theft of cryptocurrency from affected accounts.
Under the terms of the settlement, LastPass will establish an $8.2 million fund to compensate class members for losses incurred due to the breach. An additional $16.3 million will be allocated for further victim compensation, bringing the total settlement to nearly $24.5 million. The agreement was filed in the U.S. District Court for the District of Massachusetts.
The breach, which occurred in 2022, compromised sensitive user data, including encrypted password vaults, and was linked to subsequent financial fraud targeting cryptocurrency holdings. The settlement aims to resolve claims from impacted individuals while avoiding prolonged litigation.
The case underscores the growing financial and reputational risks companies face following major cybersecurity incidents, particularly those involving sensitive financial or personal data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2020
739
Breach
16 Jun 2020 • LastPass
LastPass
LastPass Data Security Breach
675
CRITICAL-64
LAS214211222
LastPass again suffered from a data security breach after an unauthorized party gained the access to a cloud-based password security site.
Although the third-party cloud provider wasn't identified, Amazon Web Services mentioned the company's migration of a billion customer records to its cloud in a blog post from 2020.
No customer data or encrypted passwords were accessed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2015
756
Breach
01 Jul 2015 • LastPass
LastPass
LastPass Data Security Breach
696
CRITICAL-60
LAS1151522
A cloud-based password security site, LastPass suffered a data security breach that compromised the account email addresses, password reminders, server per user salts, and authentication hashes.
LastPass recommended its users to update their weak master passwords as a preventive step.
LastPass servers were even over-loaded and many people were displayed the message: "Oops! Our servers are a bit overloaded right now. Please try your password change again shortly, we will catch up soon."
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for LastPass ??
What was LastPass's A.I Rankiteo Cyber Score in July 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in June 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in May 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in April 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in March 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in February 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in January 2026 ??
What was LastPass's A.I Rankiteo Cyber Score in December 2025 ??
What was LastPass's A.I Rankiteo Cyber Score in November 2025 ??
What was LastPass's A.I Rankiteo Cyber Score in October 2025 ??
What was LastPass's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on LastPass's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with LastPass ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view LastPass's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?