Skip to main content

LastPass suspects a breach, meaning it’s time for a password change

LastPass, the password management service, posted an update on June 15 to its blog noting that there had been “suspicious activity” on its website. The company stated, however, that its encryption measures have kept all of its users’ data safe.

“LastPass strengthens the authentication hash with a random salt and 100,000 rounds of server-side PBKDF2-SHA256, in addition to the rounds performed client-side,” wrote LastPass CEO and Founder Joe Siergrist. “This additional strengthening makes it difficult to attack the stolen hashes with any significant speed.”

Recommended Videos

As a result of the suspected breach, LastPass says it’s requiring all of its users who are logging in from a new device or IP address to verify their email, unless a multifactor authentication is enabled. LastPass is also asking everyone to update their master password, which could be a downer if you already committed your old one to memory.

And to make sure everyone is up to speed, LastPass is emailing all of its customers about the breach. Now, it appears that the website is handling a large wave of customers attempting to keep their data secure, according to TechSpot.

As of late Monday afternoon, a server overload message has been popping up when you attempt to change your master password. This doesn’t mean you should give up on taking LastPass’ advice, however, especially if it turns out the breach is worse than expected.

“We apologize for the extra steps of verifying your account and updating your master password, but ultimately believe this will provide you better protection,” Siergrist continued.

LastPass, which is headquartered in Virginia, does business in 71 countries around the world. In addition to encrypting passwords, LastPass encrypts and decrypts information locally before syncing it. This allows you to keep your sensitive data on your device.

“Security and privacy are our top concerns here at LastPass,” said Siergrist, reassuring customers following the breach.

Krystle Vermes
Former Digital Trends Contributor
Krystle Vermes is a professional writer, blogger and podcaster with a background in both online and print journalism. Her…
This massive exploit lets hackers breach apps like Chrome, 1Password, and Telegram
A dark mystery hand typing on a laptop computer at night.

A massive security bug has just been discovered that affects WebP images used in untold numbers of websites and apps, and it could potentially let hackers break into your computer and extract data from it. In fact, Google has already seen it being actively exploited in the wild. Because of that, it’s essential that you patch your computer as soon as possible.

The discovery has been detailed by researcher Alex Ivanovs, who wrote about the bug in a blog post. Right now, it seems to affect almost all of the best web browsers, including Chrome, Firefox, Edge, and Brave. WebP images are used all over the web, meaning huge numbers of sites and apps could be affected.

Read more
AI can now steal your passwords with almost 100% accuracy — here’s how
A digital depiction of a laptop being hacked by a hacker.

Researchers at Cornell University have discovered a new way for AI tools to steal your data -- keystrokes. A new research paper details an AI-driven attack that can steal passwords with up to 95% accuracy by listening to what you type on your keyboard.

The researchers accomplished this by training an AI model on the sound of keystrokes and deploying it on a nearby phone. The integrated microphone listened for keystrokes on a MacBook Pro and was able to reproduce them with 95% accuracy -- the highest accuracy the researchers have seen without the use of a large language model.

Read more
Google wants you to ditch LastPass and finally switch to Chrome
Google security logo.

Google has announced a major security update to the Password Manager on its Chrome browser that is aimed at helping users maintain their passwords natively and rely less on third-party managers such as 1Password, Bitwarden, Dashlane, and LastPass.

While the update is set to include seven new features, Google has highlighted five of the new functions as of Friday. The update will have support for Chrome on desktop and iOS.

Read more