
Summary box
- Incident date
- 01 Aug 2022
- Reported date
- 22 Dec 2022
- Sources verified
- 3
LastPass breach guide
You do not need drama. You need signal. Here is the fast reality: what was reported, what may be exposed, and the practical moves worth doing right now.
Status: Confirmed
Last updated: 22 May 2026

Company
LastPass
Status
Confirmed
Data potentially exposed
Customer metadata, Encrypted vault backups, Website URLs, Potentially sensitive vault notes depending on user setup
Affected scope
Broad customer metadata and encrypted vault backups were reported as impacted.
An attacker accessed development and cloud storage environments, leading to exposure of customer metadata and copied encrypted vault backups.
Metadata and stolen backups can support long-window offline attacks and social engineering, making post-breach hygiene urgent.
Hushfolk helps identify where exposure signals overlap so users can focus on the highest-risk accounts and cleanup actions first.
New to security jargon? These quick definitions keep the page readable.
Need the full list? Open the security glossary.