Many LastPass users say they've been locked out of their accounts and can't access their vault after being asked to reset their authenticator apps in early May
LastPass password manager users have been experiencing significant login issues starting early May after being prompted to reset their authenticator apps.
Context & Ripple Effects
This is the latest entry in a long trust ledger. LastPass disclosed a breach as far back as 2015 that exposed account email addresses and password reminders, fixed an Authenticator app flaw in late 2017 that let attackers bypass PIN/fingerprint locks to read 2FA codes, spent December 2021 fielding reports of compromised master passwords used in blocked login attempts, and then admitted in December 2022 that hackers stole a backup of users' encrypted and unencrypted vault data using cloud storage keys taken from an employee.
First-order effects
- Users who complied with the early-May prompt to reset their authenticator apps are locked out of their vaults right now, cut off from every stored credential until LastPass resolves recovery.
Second-order effects
- Every login failure lands on a customer base already primed to leave by the 2022 vault-backup theft — competitors gain a steady stream of migrants whose main objection is no longer price but reliability.
- Support channels absorb the load, and with the company freshly spun out of parent GoTo and rolling out new services like shadow-SaaS controls under CEO Karim Toubba, engineering attention gets pulled between recovery firefighting and the post-breach rebuild.
Third-order effects
- If forced authenticator resets keep producing lockouts on top of back-to-back 2022 breaches, the structural lesson hardens: a centralized vault plus mandatory second-factor reset is a single point of failure for a user's entire digital life, pushing buyers toward providers whose recovery paths fail less catastrophically — though whether the market consolidates around rivals or around non-vault alternatives remains genuinely open.
The trend: Consumer trust in centralized password managers is eroding one incident at a time, with each breach and outage converting stored-credential convenience into concentration risk.