Some LastPass users say their master passwords were compromised and used in blocked login attempts from unknown IPs; LastPass blames “credential stuffing”
what to do Lee Mathews / Forbes : LastPass Users Warned After Suspicious Login Attempts From Strange Locations Chris Smith / BGR : LastPass says there's no data breach, so your passwords were not hacked Michael Simon / Macworld : LastPass ‘resolves’ security scare, assures passwords are safe Martin Brinkmann / gHacks Technology News : LastPass: some users report compromised accounts Nehal Malik / iPhone in Canada Blog : LastPass Denies Reports of Mass Hack, No Passwords Breached Tyler Lee / Ubergizmo : LastPass Master Passwords Might Be Compromised Annie Rauwerda / Input : LastPass users are skeptical after company insists it wasn't hacked Duncan Riley / SiliconANGLE : LastPass users report attempted logins using their master passwords Pierluigi Paganini / Security Affairs : LastPass investigated recent reports of blocked login attempts Filipe Espósito / 9to5Mac : LastPass says no passwords were compromised following reports of unauthorized logins Daniel Sims / TechSpot : Users report LastPass master passwords possibly compromised, company assures there's no breach Tweets: Kevin Collier / @kevincollier : Per LastPass, the whole kerfuffle yesterday was that somebody unsuccessfully tried credential stuffing, but that prompted the company to mistakenly send customers security alerts. No actual harm done, but another blow to public confidence in one of the biggest password managers. https://twitter.com/... @technology_greg : Something very strange and bad is happening to a lot of people's @LastPass accounts. I posted this to Hacker News and it gathered 192 comments, including 7 separate reports of master password breaches & login attempts from the same Brazil IP range. Uhh. https://news.ycombinator.com/ ...' @briankrebs : LastPass/LogMeIn updated their statement, saying “some of the security alerts were likely triggered in error.” https://twitter.com/... https://twitter.com/... Troy Hunt / @troyhunt : And the answer to the @LastPass riddle is... not credential stuffing: “Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error”: https://blog.lastpass.com/... Marcelo Calbucci / @calbucci : Start investigating here: 1) Do all these users use Android? Have they sideloaded an app? 2) Do all these users have the same Chrome Extension? 3) Do all these users have the same external keyboard? https://twitter.com/... Nic Nguyen / @nicnguyen : “no actual harm done” is an important point here. though multiple past vulnerability reports prompted me to switch from lastpass years ago. https://twitter.com/... Kevin Collier / @kevincollier : That security alert, per @serghei: “Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Was this you?” https://www.bleepingcomputer.com/ ... Subrahmanyam Kvj / @sub8u : In case you are using Lastpass (or any other password manager - which you should!), make sure you don't reuse your master password and keep it absolutely unique. Looks like Lastpass is being hit with credential stuffing. https://www.bleepingcomputer.com/ ... Bob Diachenko / @mayhemdayone : At the same time thousands of LastPass login pairs were found in the recent Redline Stealer malware logs I reported earlier... Coincidence? https://twitter.com/... Laurie Voss / @seldo : LastPass has had another major breach. This is what the third, fourth time they've had this happen? Don't use LastPass. https://www.bleepingcomputer.com/ ... Dylan Reeve / @dylanreeve : This is the worst case scenario with a password manager. Still unclear, but definitely worrying. If you use a password manager you should absolutely also be using multifactor auth with it. https://www.bleepingcomputer.com/ ... Robert Stephens / @rstephens : iOS15 now supports MFA one-time password tokens. https://twitter.com/... Emil Protalinski / @epro : This is why I refuse to use a password manager. Centralizing all my passwords so an attacker needs just one master password to get into all my accounts? No thanks. https://twitter.com/... Martin Sfp Bryant / @martinsfp : *Supposedly* not something to worry too much about, but this is like the start of every password manager user's nightmare. https://twitter.com/...
Context & Ripple Effects
LastPass had already drawn a line between an account-security incident and vault exposure in its 2015 breach disclosure, which said customer account information was affected while the password vault was not accessed. The current reports test that distinction again: users describe blocked attempts while LastPass attributes them to credential stuffing and says alerts for some users were likely erroneous.
The later related coverage shows why that reassurance became consequential: a 2022 source-code theft was followed by reports that customer data and ultimately vault backups had been accessed. The arc shifts scrutiny from whether a single login alert signals a breach to how a password manager contains and communicates successive security events.
First-order effects
- Users who received alerts face uncertainty over whether their master-password credentials were reused elsewhere or whether the alerts were false positives; LastPass maintains that passwords were not compromised.
- LastPass must defend its credential-stuffing explanation against user reports of unknown-IP login attempts, making the accuracy of its security alerts an immediate trust issue.
Second-order effects
- The gap between user reports and LastPass's denial raises the value of MFA as an account-control layer, because blocked login attempts are occurring at the account-access boundary rather than being described as vault access.
- LastPass's incident messaging becomes part of its product risk: the earlier assurance that vaults were untouched offers a precedent, but later disclosures make each similar assurance more consequential for user confidence.
Third-order effects
- The related sequence points toward password-manager security being judged across a chain of controls—user authentication, employee access, source code, and cloud backups—rather than by whether a single vault was accessed.
- As incidents move from reported credential abuse to customer-data access through cloud storage, providers face a durable credibility burden: narrowly accurate statements about one layer may not settle concerns about the broader service.
The trend: Password-manager trust is increasingly determined by layered incident resilience and clear boundary-setting between account attacks, internal systems, and stored vault data.