DooDooLamb News

Security News This Week: LastPass Users Had Their Data Stolen—Again

Brief published June 29, 2026 · Original source published June 27, 2026

Original reporting by Lily Hay Newman at wired.com.

Automated brief. Verify important details at the original source.

Security News This Week: LastPass Users Had Their Data Stolen—Again

LastPass Got Hacked Again, Which Is Exactly As Funny As It Sounds

LastPass, the company whose entire business model is "trust us with every password you have ever created," has once again allowed someone who is not you to access your data. This is, by the count of people who have been paying attention, not the first time. It is not even close to the second time.

Let's establish the premise clearly, because it deserves to sit in the room for a moment. A password manager is a vault. It is, conceptually, a very secure box. The entire value proposition, the only reason anyone hands over the keys to their digital life, is the implicit promise that the box stays closed. LastPass has now managed to pop that box open with the frequency of a college student checking the fridge, hoping something different will be in there. Nothing different is in there. Your data is gone again.

The story here is both simple and cosmically funny. LastPass users had their data stolen, again, as reported by Wired, which at this point covers LastPass breaches the way local news covers potholes: with weary regularity and the quiet understanding that nothing structural will change. The 2022 breach, which was itself a sequel to earlier incidents, saw attackers walk off with encrypted password vaults, customer metadata, and enough information to make a threat actor's holiday season genuinely festive. The cascading fallout from that breach is still being felt, with researchers linking subsequent cryptocurrency thefts worth tens of millions of dollars to credentials exposed in that incident. And now, like a franchise that refuses to acknowledge its own reviews, there is more. Users had their data stolen. Again. The word "again" is doing so much heavy lifting in that sentence that it deserves its own line item in the Wired editorial budget.

What makes this particularly rich is the architecture of the problem. LastPass stores your passwords in an encrypted vault, which sounds reassuring until you learn that the encryption is only as strong as your master password, and the metadata around your vault (which sites you use, how often you log in, the general shape of your digital life) was stored in ways that were considerably less protected. It is a bit like building a very sturdy safe and then leaving a detailed inventory of everything inside it taped to the front door. The safe itself might hold, but now a determined burglar knows exactly what they are looking for and has forever to work on it. "Forever" is the operative word, because encrypted vaults do not expire. Someone who grabbed your vault in 2022 can spend the next decade throwing compute at it, waiting for the economics of cracking to catch up with the value of what is inside.

Elsewhere in this week's security roundup, Microsoft assisted in taking down infrastructure linked to a major infostealer operation, which is genuinely good news delivered with the energy of a company that also needs some good news right now. Infostealers, for the uninitiated, are a category of malware that sits quietly on your machine and harvests credentials, session cookies, and anything else of value before sending it home to whoever deployed it. They are the digital equivalent of a houseguest who copies your keys, photographs your documents, and leaves without saying goodbye. Microsoft's legal and technical teams have been increasingly aggressive about using civil litigation and infrastructure seizure to disrupt these operations, which is a legitimate and effective strategy, even if it also conveniently generates the kind of press that does not mention Copilot hallucinating financial reports.

Meanwhile, in the corner of the news that belongs in a different genre entirely, former national security advisor John Bolton pleaded guilty in a classified-materials case. Bolton, who spent years operating at the highest levels of American national security, apparently also needed a reminder that classified documents are classified. The overlap between "people who handle the nation's most sensitive secrets" and "people who need to be told not to take the nation's most sensitive secrets home" continues to be a Venn diagram that is, disconcertingly, just one circle.

The reality check is this: if you use LastPass, you are not necessarily doomed, but you should treat your master password as compromised if it was anything less than a randomly generated string of characters that you never used anywhere else and stored only in your memory or a piece of paper in a fireproof safe. If your master password was the name of your childhood dog followed by an exclamation mark (you know who you are), now is the time to rotate every single credential in that vault. The broader lesson, which the industry has been trying to teach for years with mixed results, is that a password manager is a risk concentration device as much as it is a convenience device. You are betting that one company's security is better than the aggregate of your own habits. LastPass has now provided substantial empirical evidence for how that bet can go.

For the engineers and founders reading this, the Microsoft infostealer takedown is worth understanding as a template. The strategy of using civil courts to seize malicious infrastructure, a technique Microsoft's Digital Crimes Unit has refined over years, is one of the more effective tools in the defensive arsenal precisely because it does not require criminal prosecution timelines. You file, you move fast, you cut the command-and-control servers off at the knees. It works, and it scales, which is more than you can say for most security interventions.

LastPass will release a statement, if they have not already, expressing their commitment to user security and outlining the steps they are taking to ensure this does not happen again. They have written some version of that statement before. They are very good at writing it. They are, demonstrably, less good at the part that comes before having to write it.

The funniest and most depressing thing about password manager breaches is that the correct response to losing faith in your password manager is to use a different password manager, because the alternative (reusing passwords across sites like it is 2009) is somehow still worse. We are all, to varying degrees, just picking which vault we trust and hoping for the best. LastPass has simply made the selection process easier by repeatedly demonstrating that it should not be them.

Original source