Episode · LASTPASS 2022

The LastPass breach, start to finish: a targeted engineer, stolen vaults and a $150 million theft

Published 2026-09-29 · 7 min read · Episode 17 of the Cyber Heists long-form series
LastPass 2022: one engineer's home PC, stolen vaults, $150M in cryptoPremieres 2026-11-29

In 2022 a company whose whole business was keeping passwords safe lost backups of its customers' encrypted password vaults, and federal agents later tied a single $150 million cryptocurrency theft to data from those breaches.[1][2] This long read follows the LastPass heist from a developer's laptop to a senior engineer's machine, the stolen vaults, the crypto thefts that followed, and the one control that would have kept the keys out of reach.

The first break-in: a developer's laptop

A password manager stores every login a person owns in one encrypted vault, locked by a single master password. LastPass built its service on a zero-knowledge model: the company never stored customers' master passwords, so in principle it could not read what was inside their vaults.[1]

In August 2022 that promise was tested. An attacker compromised a software engineer's corporate laptop and used it to reach LastPass's cloud-based development environment. From there, the company later said, the intruder copied source code from 14 of its 200 code repositories, technical documents describing how the development environment worked, and internal scripts that contained LastPass secrets and certificates.[1]

On August 25, 2022, LastPass disclosed that its development environment had been breached. In September it said no customer data had been accessed, which was true at that point. The development environment held no customer vaults.[1][2]

What the attacker took, though, was a map. Documentation that explains how systems fit together, plus secrets pulled from scripts, tells an intruder where the valuable data lives and which people and credentials can reach it. The first incident was the reconnaissance for the second.

It is also a reminder that disclosure is a moving target. The first public statement was accurate about what was known in August. It did not, and could not yet, account for what the stolen material would make possible a few weeks later. Customers who read only the first notice had little reason to act.[1][2]

The second break-in: a senior engineer targeted

In its March 2023 update, LastPass explained what came next. The attacker targeted a senior DevOps engineer, one of the staff who managed the company's infrastructure, by exploiting vulnerable third-party software. That delivered malware which got around the company's controls and gave the attacker access to cloud backup storage.[1]

The engineer's access was the prize. LastPass said the attacker obtained DevOps secrets, restricted credentials, configuration and integration secrets, and ultimately the customer data and vault backups themselves.[1] The last activity by the intruder that LastPass detected was on October 26, 2022.[1]

The lesson in this chapter is about where powerful access lives. A handful of people at any technology company hold keys that open everything. If any device those people use can be taken over through an outdated program, then the strongest encryption on the servers only protects data until the attacker reaches that person's keyboard.

What was inside the stolen vault backups

LastPass disclosed a second incident on November 30, 2022, and in the following weeks explained that encrypted password vaults had been taken.[2] Its March 2023 update laid out the details. Customer metadata and vault backups were copied, along with the seeds for LastPass's own authenticator app and backup phone numbers used for multifactor sign-in, and part of the database used for business customers who sign in through their company's identity system.[1]

The vault contents were encrypted under the zero-knowledge model, and LastPass stressed that master passwords were never stored and were not taken. But not everything in a vault was encrypted. LastPass said website addresses, file paths and, in some cases, email addresses were stored in a readable form.[1] For a thief, a list of which banks, exchanges and services a person uses is a useful guide to which stolen vaults are worth attacking.

The loss of the authenticator seeds and backup phone numbers mattered too. Those are the pieces of information that make up a second sign-in step. LastPass said the database holding them was encrypted, but that the key to decrypt it had also been taken, so the second sign-in step itself had to be treated as exposed.[1] For many customers, resetting multifactor settings became as important as changing passwords.

The bigger risk was time. Once a vault is copied, there is no login screen, no lockout after failed attempts and no alert. A thief can make guesses at the master password offline for as long as they like. How long that takes depends on the strength of the password and on how many times the vault's encryption repeats its scrambling step. Newer LastPass accounts were set to a much higher number of those repetitions, eventually 600,000, while some older accounts were protected by far fewer.[2]

The crypto thefts that followed

After the breach, a pattern began to show up among cryptocurrency investors. Researchers tracking the thefts documented six-figure heists happening several times a month, hitting dozens of victims. In a September 2023 analysis, they found a common thread: the victims had stored the seed phrases for their crypto wallets in LastPass secure notes before the 2022 breaches.[2] A seed phrase is the master key to a crypto wallet. Anyone who has it can move the money, and the transfer cannot be reversed.

The largest case came later. On January 30, 2024, a co-founder of a major cryptocurrency company lost about $150 million in a single theft.[2] On March 6, 2025, federal prosecutors in Northern California filed to seize about $24 million in cryptocurrency recovered from it. In the filing, the Secret Service and FBI said stolen data and passwords had been used to get into victims' accounts and steal cryptocurrency, and investigators tied the theft to the LastPass breaches of 2022.[2]

LastPass responded that its law enforcement partners had not made it aware of any conclusive evidence connecting crypto thefts to its incident.[2] No attacker has been publicly named or convicted for the LastPass intrusions.

What LastPass changed afterward

LastPass said it rebuilt its entire development environment, added security technology and controls, and rotated every secret and certificate that had been exposed in plain text.[1] For the backup storage, it applied new policies, changed how privileged access worked and rotated the secrets the attacker had reached.[1]

It also published recommended actions for customers.[1] For anyone whose vault might be cracked, the sensible to-do list was the same: change the master password, then change the passwords stored inside the vault, starting with the most valuable accounts. For crypto holders who had stored seed phrases, the only real fix was to move funds to a new wallet with a new phrase.

For business customers the list was longer, because the stolen material included secrets used to connect LastPass with other company systems. Every one of those had to be treated as known to the attacker and replaced.[1] That is the hidden cost of a breach at a security vendor: the cleanup lands on every customer, not just the company that was hit.

The sequence is the lesson. The company did not lose its customers' data to a flaw in its encryption. It lost it through the people and machines that held the keys to its backups.

Timeline

DateWhat happened
Aug 2022Developer's corporate laptop compromised; source code and documents copied.[1]
Aug 25, 2022LastPass discloses the development environment breach.[2]
Sep 15, 2022LastPass says no customer data was accessed.[2]
Oct 26, 2022Last detected activity by the intruder.[1]
Nov 30, 2022Second breach disclosed; vault backups compromised.[2]
Mar 1, 2023LastPass publishes its full account of both incidents.[1]
Sep 2023Researchers link a run of crypto thefts to seed phrases stored in LastPass.[2]
Jan 30, 2024About $150 million stolen from a crypto company co-founder.[2]
Mar 6, 2025Prosecutors file to seize about $24 million tied to that theft.[2]

The missing control

The missing control: keep the most powerful keys reachable only from locked-down, company-managed devices that are patched and monitored, and force every customer vault up to current protection settings. A single engineer's machine should never be one piece of outdated software away from every backup.[1]

  1. Separate admin work from everything else. Anyone who can reach backups, payroll or customer data should do that work on a dedicated company device, not a machine that also runs personal apps.
  2. Keep every program on those devices updated. Turn on automatic updates for the operating system and every installed app, and remove software nobody needs.
  3. Limit who holds the master keys. List the people who can open backups or admin accounts, keep that list as short as possible, and review it every quarter.
  4. Never store crypto seed phrases or master keys in a cloud notes field. Keep them offline, on paper or a hardware device, in a secure place.
  5. Upgrade old security settings on purpose. When a service raises its default protection, check that older accounts, including yours, actually moved to the new setting.

What it means now

Password managers remain far safer than reusing passwords or writing them in a spreadsheet. The LastPass breach does not change that. What it shows is that a vault is only as safe as the people and devices that hold its keys.

For a small business, the takeaway is simple: find out which few people could open everything, and make sure the computers they use for that work are the most boring, locked-down, fully updated machines you own.

The short version

How the LastPass breach happened: the engineer's home computer: the case file and the Shorts from this case.

Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

Related case files

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. LastPass: Security incident update and recommended actions (March 1, 2023)
  2. Krebs on Security: Feds link $150M cyberheist to 2022 LastPass hacks