/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Many LastPass users say they've been locked out of their accounts and can't access their vault after being asked to reset their authenticator apps in early May

LastPass password manager users have been experiencing significant login issues starting early May after being prompted to reset their authenticator apps.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is the latest entry in a long trust ledger. LastPass disclosed a breach as far back as 2015 that exposed account email addresses and password reminders, fixed an Authenticator app flaw in late 2017 that let attackers bypass PIN/fingerprint locks to read 2FA codes, spent December 2021 fielding reports of compromised master passwords used in blocked login attempts, and then admitted in December 2022 that hackers stole a backup of users' encrypted and unencrypted vault data using cloud storage keys taken from an employee.

First-order effects

  • Users who complied with the early-May prompt to reset their authenticator apps are locked out of their vaults right now, cut off from every stored credential until LastPass resolves recovery.

Second-order effects

  • Every login failure lands on a customer base already primed to leave by the 2022 vault-backup theft — competitors gain a steady stream of migrants whose main objection is no longer price but reliability.
  • Support channels absorb the load, and with the company freshly spun out of parent GoTo and rolling out new services like shadow-SaaS controls under CEO Karim Toubba, engineering attention gets pulled between recovery firefighting and the post-breach rebuild.

Third-order effects

  • If forced authenticator resets keep producing lockouts on top of back-to-back 2022 breaches, the structural lesson hardens: a centralized vault plus mandatory second-factor reset is a single point of failure for a user's entire digital life, pushing buyers toward providers whose recovery paths fail less catastrophically — though whether the market consolidates around rivals or around non-vault alternatives remains genuinely open.

The trend: Consumer trust in centralized password managers is eroding one incident at a time, with each breach and outage converting stored-credential convenience into concentration risk.

Discussion

  • @rklau.bsky.social Rick Klau on bluesky
    LastPass was a great product, until it wasn't. 🤡  —  “affected customers cannot seek assistance from support since reaching out to LastPass support requires logging into their accounts which they can't do because they're locked in an infinite loop of being prompted to reset their…
  • @lauren@mastodon.laurenweinstein.org Lauren Weinstein on mastodon
    I don't use LastPass.  This kind of thing is only one reason why.  - LastPass users furious after being locked out due to MFA resets - https://www.bleepingcomputer.com/ ...
  • @orci@mastodon.social J.R. Orci on mastodon
    Good lord... LastPass is the shitshow that keeps on shitting. #privacy #security  —  LastPass users furious after being locked out due to MFA resets  —  “Compounding the problem, affected customers cannot seek assistance from support since reaching out to LastPass support require…
  • @gtbarry@mastodon.social @gtbarry@mastodon.social on mastodon
    #LastPass still has users?  —  numerous users have been locked out of their accounts and unable to access their LastPass vault  —  Compounding the problem, affected customers cannot seek assistance from support since reaching out to LastPass support requires logging into their ac…
  • @vslick1 @vslick1 on x
    https://www.bleepingcomputer.com/ ... one can only hope that other password managers don't follow LastPass' example. They seem to be the leader in what not to do ! https://www.bleepingcomputer.com/ ...
  • @cybernewslive @cybernewslive on x
    I've been screaming this at the top of my lungs..."If you are still using @LastPass change vendors ASAP!" #cnl #cybernewslive #cyber #cybersecurity #cybersecuritynews https://www.bleepingcomputer.com/ ...
  • @edgardonazario Edgardo Nazario on x
    I recommend anyone who asks to avoid LastPass. IMO, shoddy engineering and lax security. https://twitter.com/...
  • r/InfoSecNews r on reddit
    LastPass users furious after being locked out due to MFA resets