How the LastPass breach happened: the engineer's home computer
The road into LastPass's customer vault backups did not run through the company's data center. It ran through a senior engineer's personal computer at home, via a media server app that had gone unpatched for about 2 years.[2][4] This case file covers how two linked intrusions in 2022 ended with encrypted vaults copied, what the breach has cost since, and the one control that would have kept the keys out of reach.
What happened
On August 8, 2022, an attacker broke into a LastPass software engineer's company laptop and took source code and technical documentation. LastPass spotted the activity by August 12, brought in an outside incident response firm the next day, and on August 25 its CEO told customers the incident was contained and no customer data had been touched.[1]
It was not over. Using what was taken in that first round, the attacker went looking for a person who could open the company's most sensitive storage. From August 12 to October 26, 2022, the attacker worked against one of only 4 DevOps engineers who held the keys to decrypt LastPass's cloud backups.[1][3] The route in was that engineer's home computer.
On November 30, 2022, LastPass said customer information had been accessed. On December 22 it said backups of customer vaults had been copied. Full details of the attack chain came out on March 1, 2023, with an apology from the CEO.[1]
How they got in
The engineer ran a popular home media server program on a personal Windows PC. That version had a known flaw, publicly listed as CVE-2020-5741, that let an outsider run code on the machine. A fix had been available since May 2020, but the copy on the engineer's PC was roughly 75 versions out of date.[2]
The attacker used that flaw to plant a keylogger, software that records what you type. It captured the engineer's LastPass master password as it was typed, after the engineer had already passed multi-factor authentication.[1][3] The UK data protection regulator later found the attacker also grabbed a session cookie, the small token a site uses to remember that you already logged in, which let them skip the second factor.[4]
Why did a home PC matter at all? LastPass allowed, and encouraged, senior staff to link their personal and work vaults under a single master password.[4][5] So one password typed at home opened the corporate vault. Inside were the access and decryption keys for the production backups in cloud storage.[3][4] Because the attacker was using a real engineer's valid credentials, the activity looked like normal work.[3]
What it cost
The copied backups held customer vaults, with passwords and notes encrypted under each user's master password, alongside unencrypted details such as names, email addresses, billing addresses and IP addresses.[1][3] LastPass said master passwords were not compromised. Alerts from its cloud provider's threat detection service eventually flagged the unusual activity.[1][3]
Encryption only helps as much as the password behind it. In September 2023, researchers tied more than $35 million in cryptocurrency thefts from over 150 people to seed phrases stored in LastPass, and suspected criminals were cracking weakly protected vaults offline. Older accounts had weaker default settings. LastPass declined detailed comment, citing the ongoing investigation.[6]
In December 2025 the UK Information Commissioner's Office fined LastPass £1.2 million, about $1.6 million, over the breach, which affected up to 1.6 million UK users.[4][5] In February 2026 a US federal court in Massachusetts gave preliminary approval to a class action settlement of up to $24.5 million.[7] The attacker has never been publicly identified.[1]
The missing control
The missing control: keep the keys that unlock critical systems off personal devices. The decryption keys for every customer backup were reachable from a home PC that the company did not manage, patch or monitor.
If those keys had lived only on company-managed machines, or behind a separate login that could not be reached from a personal vault, the keylogger on the home computer would have captured a password that led nowhere important. A managed work device would also have been patched against a flaw fixed 2 years earlier. The ICO's finding was blunt: linking personal and business vaults turned one compromised family computer into a path to corporate secrets.[4][5]
What to do in your business
- Separate work and personal logins. Do not let staff sync work passwords into personal password managers or personal browser profiles. Give them a business account that stays on business devices.
- List your crown-jewel keys. Write down who can reach your bank logins, backup accounts, domain registrar and cloud admin console, and from which devices. Anything reachable from a home PC is a gap.
- Use company-managed devices for admin work. The people with the most access should do sensitive tasks only on a machine you keep updated and can check.
- Treat home computers as outside your walls. If staff must work from personal machines, limit them to low-risk tools and require hardware security keys for anything important.
- Keep offline copies of backups and key material. Backups that one stolen password can reach are part of the same target, not a safety net.
The LastPass breach, start to finish: a targeted engineer, stolen vaults and a $150 million theft: the long read behind the CL17 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Cybersecurity Dive: LastPass cyberattack timeline
- The Hacker News: LastPass hack, engineer's failure to update Plex software led to massive data breach
- Computer Weekly: LastPass attack saw employee's home computer hacked
- The Register: LastPass hammered with £1.2M fine for 2022 breach
- BleepingComputer: UK fines LastPass over 2022 data breach impacting 1.6 million users
- Krebs on Security: Experts fear crooks are cracking keys stolen in LastPass breach
- Bloomberg Law: LastPass gets initial nod for $24.5 million data breach deal