On Wednesday, password manager LastPass announced that it had experienced its second data breach in the span of three months.
CEO Karim Toubba announced that the company hack picked up unusual activity within a third-party cloud storage service, shared between LastPass and affiliate GoTo. An investigation was immediately launched into the incident by security firm Mandiant, and law enforcement was alerted.
“We have determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information. Our customers’ passwords remain safely encrypted due to LastPass’s Zero Knowledge architecture,” Toubba said.
“We are working diligently to understand the scope of the incident and identify what specific information has been accessed. In the meantime, we can confirm that LastPass products and services remain fully functional.”
LastPass said it continues to “deploy enhanced security measures and monitoring capabilities across our infrastructure to help detect and prevent further threat actor activity.”
Further updates will be provided as the company learns more details, Toubba said.
This isn’t the first time that LastPass has been subject to a hack or data breach. In August, LastPass announced that an unauthorized party had gained access to portions of the LastPass development environment, using a single compromised developer account. Portions of the source code and some proprietary LastPass technical information were taken.
After an investigation, Toubba announced in early September that the activity had been limited to a four-day span, and confirmed that there was no evidence that the incident impacted any customer data or encrypted passwords.
“We recognize that security incidents of any sort are unsettling but want to assure you that your personal data and passwords are safe in our care,” he said at the time.
LastPass was one of Wired’s honorable mentions for password managers in an article posted on November 18. It was the tech publication’s favorite free option before the company changed its free plan limiting users to a single device.
“Lastpass’ paid plan offers most of the same features you’ll find in our other top picks, though it lacks the travel features of 1Password and isn’t open source like BitWarden,” Wired wrote. “We just don’t see any reason to suggest it over our top picks, and it was recently hacked.”



