/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Some LastPass users say their master passwords were compromised and used in blocked login attempts from unknown IPs; LastPass blames “credential stuffing”

Many LastPass users report that their master passwords have been compromised after receiving email warnings that someone tried …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The reports land against the backdrop of LastPass's 2015 breach disclosure, which said account email addresses and password reminders were compromised while password vaults were not accessed. Its credential-stuffing explanation again makes the boundary between account-login exposure and vault compromise central to the story.

First-order effects

  • Affected users received warnings for login attempts that LastPass says were blocked, preventing the reported attempts from becoming confirmed account access.
  • LastPass is treating the reports as credential-stuffing activity, framing the immediate issue as compromised or reused credentials rather than a disclosed vault-system breach.

Second-order effects

  • LastPass faces a higher burden to clearly distinguish credential attacks against individual accounts from a breach of its own systems, a distinction already tested by its 2015 incident disclosures.
  • Users evaluating the alerts must assess the security of the master-password login path separately from the security of the stored vault.

Third-order effects

  • If users continue to evaluate login attacks and infrastructure breaches together, password managers will be judged across both the account-access boundary and the encrypted-vault boundary, not on vault protection alone.

The trend: Password-manager trust is broadening from vault encryption to the security and transparency of the account-login layer.

Discussion

  • @technology_greg @technology_greg on x
    Something very strange and bad is happening to a lot of people's @LastPass accounts. I posted this to Hacker News and it gathered 192 comments, including 7 separate reports of master password breaches & login attempts from the same Brazil IP range. Uhh. https://news.ycombinator.c…
  • @mayhemdayone Bob Diachenko on x
    At the same time thousands of LastPass login pairs were found in the recent Redline Stealer malware logs I reported earlier... Coincidence? https://twitter.com/...
  • @sub8u Subrahmanyam Kvj on x
    In case you are using Lastpass (or any other password manager - which you should!), make sure you don't reuse your master password and keep it absolutely unique. Looks like Lastpass is being hit with credential stuffing. https://www.bleepingcomputer.com/ ...
  • @seldo Laurie Voss on x
    LastPass has had another major breach. This is what the third, fourth time they've had this happen? Don't use LastPass. https://www.bleepingcomputer.com/ ...
  • @dylanreeve Dylan Reeve on x
    This is the worst case scenario with a password manager. Still unclear, but definitely worrying. If you use a password manager you should absolutely also be using multifactor auth with it. https://www.bleepingcomputer.com/ ...
  • @rstephens Robert Stephens on x
    iOS15 now supports MFA one-time password tokens. https://twitter.com/...
  • @epro Emil Protalinski on x
    This is why I refuse to use a password manager. Centralizing all my passwords so an attacker needs just one master password to get into all my accounts? No thanks. https://twitter.com/...
  • @martinsfp Martin Sfp Bryant on x
    *Supposedly* not something to worry too much about, but this is like the start of every password manager user's nightmare. https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    LastPass might be having some kind of credential stuffing incident, with master passwords.