In December 2022 LastPass disclosed that attackers had obtained customer vault data. Reporting describes a second intrusion that used material taken in an earlier August incident, together with credentials from an unrelated breach, to reach the company’s cloud storage and take encrypted vault backups covering the customer base.
The route is reported as one of a small number of engineers with vault decryption access, whose personal home computer was compromised through a known vulnerability in Plex Media Server — CVE-2020-5741 — that had gone unpatched for more than two years, allowing a keylogger to be installed. LastPass settled a class action for $24.5 million in 2025.
Encryption At Rest Is A Timer, Not A Wall
The vaults were encrypted, and the company’s early framing leaned on that. It is a real protection and it is not a boundary.
Once a vault file is in someone else’s possession, the only remaining defence is how long it takes to guess the master password — offline, with no rate limiting, no lockout and no alerting, for as long as the holder finds it worthwhile. A strong master password may make that impractical. A weak one converts the incident from a disclosure into a countdown, and the customer cannot tell which they have.
The Blast Radius Is Every Other Account
A breached retailer loses that retailer’s data. A breached password manager loses the key to the accounts its customers hold everywhere else, including the ones they had forgotten they had.
The corpus records this concentration property at 23-0104, where CircleCI told customers to rotate every secret it held, and at 25-0917. Password managers are worth using — the alternative is reuse, which is worse. That does not make the concentration smaller; it makes it a considered trade, and this is what the downside looks like when it lands.
A Home Computer Was Inside The Boundary
The reported entry point was not a corporate laptop. It was a personal machine running media software, exposed to a vulnerability the vendor had fixed in 2020.
This is the boundary the corpus keeps finding has no edge: 26-0703 records that three quarters of intrusions came through the remote-access boundary, and 22-0120 records an outsourced support desk. If four people can decrypt every vault, the security perimeter includes four living rooms, and no amount of corporate hardening reaches into them.
Built on contemporaneous reporting and LastPass’s own disclosures, which were revised repeatedly between December 2022 and early 2023. The use of material from the earlier August incident, access to cloud storage, the taking of encrypted vault backups, the compromise of a senior DevOps engineer’s personal computer, and the identification of CVE-2020-5741 in Plex Media Server as the reported route are as reported. The $24.5m class-action settlement figure is as reported for 2025. The account of what an attacker can do with an exfiltrated encrypted vault is this desk’s reasoning about offline attack, presented as such. No claim is made about how many vaults were subsequently cracked — that is not established. Graded high. Corrections: corrections@forensicpost.com.