Desk live·
ForensicPost
Breaches/Concentration/File 22-1222

Encrypted Vault Backups for the Entire Customer Base

The route in was a senior engineer’s home computer, through a media-server flaw left unpatched for over two years. What left was every customer’s vault — and an exfiltrated vault can be attacked offline for as long as the attacker cares to.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetLastPass
ActorUnattributed
S. Rosler13 min readConfidence: high3 sources reviewed

In December 2022 LastPass disclosed that attackers had obtained customer vault data. Reporting describes a second intrusion that used material taken in an earlier August incident, together with credentials from an unrelated breach, to reach the company’s cloud storage and take encrypted vault backups covering the customer base.

The route is reported as one of a small number of engineers with vault decryption access, whose personal home computer was compromised through a known vulnerability in Plex Media Server — CVE-2020-5741 — that had gone unpatched for more than two years, allowing a keylogger to be installed. LastPass settled a class action for $24.5 million in 2025.

Encryption At Rest Is A Timer, Not A Wall

The vaults were encrypted, and the company’s early framing leaned on that. It is a real protection and it is not a boundary.

Once a vault file is in someone else’s possession, the only remaining defence is how long it takes to guess the master password — offline, with no rate limiting, no lockout and no alerting, for as long as the holder finds it worthwhile. A strong master password may make that impractical. A weak one converts the incident from a disclosure into a countdown, and the customer cannot tell which they have.

The Blast Radius Is Every Other Account

A breached retailer loses that retailer’s data. A breached password manager loses the key to the accounts its customers hold everywhere else, including the ones they had forgotten they had.

The corpus records this concentration property at 23-0104, where CircleCI told customers to rotate every secret it held, and at 25-0917. Password managers are worth using — the alternative is reuse, which is worse. That does not make the concentration smaller; it makes it a considered trade, and this is what the downside looks like when it lands.

A Home Computer Was Inside The Boundary

The reported entry point was not a corporate laptop. It was a personal machine running media software, exposed to a vulnerability the vendor had fixed in 2020.

This is the boundary the corpus keeps finding has no edge: 26-0703 records that three quarters of intrusions came through the remote-access boundary, and 22-0120 records an outsourced support desk. If four people can decrypt every vault, the security perimeter includes four living rooms, and no amount of corporate hardening reaches into them.

How we reported this

Built on contemporaneous reporting and LastPass’s own disclosures, which were revised repeatedly between December 2022 and early 2023. The use of material from the earlier August incident, access to cloud storage, the taking of encrypted vault backups, the compromise of a senior DevOps engineer’s personal computer, and the identification of CVE-2020-5741 in Plex Media Server as the reported route are as reported. The $24.5m class-action settlement figure is as reported for 2025. The account of what an attacker can do with an exfiltrated encrypted vault is this desk’s reasoning about offline attack, presented as such. No claim is made about how many vaults were subsequently cracked — that is not established. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. LastPass: DevOps engineer hacked to steal password vault data in 2022 breachBleepingComputer
  2. LastPass breach timeline: How a monthslong cyberattack unraveledCybersecurity Dive
  3. LastPass Reveals Second Attack Resulting in Breach of Encrypted Password VaultsThe Hacker News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary