Some LastPass users say their master passwords were compromised and used in blocked login attempts from unknown IPs; LastPass blames “credential stuffing”
Many LastPass users report that their master passwords have been compromised after receiving email warnings that someone tried …
BleepingComputerSergiu Gatlan
Context & Ripple Effects
The reports land against the backdrop of LastPass's 2015 breach disclosure, which said account email addresses and password reminders were compromised while password vaults were not accessed. Its credential-stuffing explanation again makes the boundary between account-login exposure and vault compromise central to the story.
First-order effects
Affected users received warnings for login attempts that LastPass says were blocked, preventing the reported attempts from becoming confirmed account access.
LastPass is treating the reports as credential-stuffing activity, framing the immediate issue as compromised or reused credentials rather than a disclosed vault-system breach.
Second-order effects
LastPass faces a higher burden to clearly distinguish credential attacks against individual accounts from a breach of its own systems, a distinction already tested by its 2015 incident disclosures.
Users evaluating the alerts must assess the security of the master-password login path separately from the security of the stored vault.
Third-order effects
If users continue to evaluate login attacks and infrastructure breaches together, password managers will be judged across both the account-access boundary and the encrypted-vault boundary, not on vault protection alone.
The trend: Password-manager trust is broadening from vault encryption to the security and transparency of the account-login layer.
Something very strange and bad is happening to a lot of people's @LastPass accounts. I posted this to Hacker News and it gathered 192 comments, including 7 separate reports of master password breaches & login attempts from the same Brazil IP range. Uhh. https://news.ycombinator.c…
At the same time thousands of LastPass login pairs were found in the recent Redline Stealer malware logs I reported earlier... Coincidence? https://twitter.com/...
In case you are using Lastpass (or any other password manager - which you should!), make sure you don't reuse your master password and keep it absolutely unique. Looks like Lastpass is being hit with credential stuffing. https://www.bleepingcomputer.com/ ...
LastPass has had another major breach. This is what the third, fourth time they've had this happen? Don't use LastPass. https://www.bleepingcomputer.com/ ...
This is the worst case scenario with a password manager. Still unclear, but definitely worrying. If you use a password manager you should absolutely also be using multifactor auth with it. https://www.bleepingcomputer.com/ ...
This is why I refuse to use a password manager. Centralizing all my passwords so an attacker needs just one master password to get into all my accounts? No thanks. https://twitter.com/...