/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Some LastPass users say their master passwords were compromised and used in blocked login attempts from unknown IPs; LastPass blames “credential stuffing”

what to do Lee Mathews / Forbes : LastPass Users Warned After Suspicious Login Attempts From Strange Locations Chris Smith / BGR : LastPass says there's no data breach, so your passwords were not hacked Michael Simon / Macworld : LastPass ‘resolves’ security scare, assures passwords are safe Martin Brinkmann / gHacks Technology News : LastPass: some users report compromised accounts Nehal Malik / iPhone in Canada Blog : LastPass Denies Reports of Mass Hack, No Passwords Breached Tyler Lee / Ubergizmo : LastPass Master Passwords Might Be Compromised Annie Rauwerda / Input : LastPass users are skeptical after company insists it wasn't hacked Duncan Riley / SiliconANGLE : LastPass users report attempted logins using their master passwords Pierluigi Paganini / Security Affairs : LastPass investigated recent reports of blocked login attempts Filipe Espósito / 9to5Mac : LastPass says no passwords were compromised following reports of unauthorized logins Daniel Sims / TechSpot : Users report LastPass master passwords possibly compromised, company assures there's no breach Tweets: Kevin Collier / @kevincollier : Per LastPass, the whole kerfuffle yesterday was that somebody unsuccessfully tried credential stuffing, but that prompted the company to mistakenly send customers security alerts. No actual harm done, but another blow to public confidence in one of the biggest password managers. https://twitter.com/... @technology_greg : Something very strange and bad is happening to a lot of people's @LastPass accounts. I posted this to Hacker News and it gathered 192 comments, including 7 separate reports of master password breaches & login attempts from the same Brazil IP range. Uhh. https://news.ycombinator.com/ ...' @briankrebs : LastPass/LogMeIn updated their statement, saying “some of the security alerts were likely triggered in error.” https://twitter.com/... https://twitter.com/... Troy Hunt / @troyhunt : And the answer to the @LastPass riddle is... not credential stuffing: “Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error”: https://blog.lastpass.com/... Marcelo Calbucci / @calbucci : Start investigating here: 1) Do all these users use Android? Have they sideloaded an app? 2) Do all these users have the same Chrome Extension? 3) Do all these users have the same external keyboard? https://twitter.com/... Nic Nguyen / @nicnguyen : “no actual harm done” is an important point here. though multiple past vulnerability reports prompted me to switch from lastpass years ago. https://twitter.com/... Kevin Collier / @kevincollier : That security alert, per @serghei: “Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Was this you?” https://www.bleepingcomputer.com/ ... Subrahmanyam Kvj / @sub8u : In case you are using Lastpass (or any other password manager - which you should!), make sure you don't reuse your master password and keep it absolutely unique. Looks like Lastpass is being hit with credential stuffing. https://www.bleepingcomputer.com/ ... Bob Diachenko / @mayhemdayone : At the same time thousands of LastPass login pairs were found in the recent Redline Stealer malware logs I reported earlier... Coincidence? https://twitter.com/... Laurie Voss / @seldo : LastPass has had another major breach. This is what the third, fourth time they've had this happen? Don't use LastPass. https://www.bleepingcomputer.com/ ... Dylan Reeve / @dylanreeve : This is the worst case scenario with a password manager. Still unclear, but definitely worrying. If you use a password manager you should absolutely also be using multifactor auth with it. https://www.bleepingcomputer.com/ ... Robert Stephens / @rstephens : iOS15 now supports MFA one-time password tokens. https://twitter.com/... Emil Protalinski / @epro : This is why I refuse to use a password manager. Centralizing all my passwords so an attacker needs just one master password to get into all my accounts? No thanks. https://twitter.com/... Martin Sfp Bryant / @martinsfp : *Supposedly* not something to worry too much about, but this is like the start of every password manager user's nightmare. https://twitter.com/...

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

LastPass had already drawn a line between an account-security incident and vault exposure in its 2015 breach disclosure, which said customer account information was affected while the password vault was not accessed. The current reports test that distinction again: users describe blocked attempts while LastPass attributes them to credential stuffing and says alerts for some users were likely erroneous.

The later related coverage shows why that reassurance became consequential: a 2022 source-code theft was followed by reports that customer data and ultimately vault backups had been accessed. The arc shifts scrutiny from whether a single login alert signals a breach to how a password manager contains and communicates successive security events.

First-order effects

  • Users who received alerts face uncertainty over whether their master-password credentials were reused elsewhere or whether the alerts were false positives; LastPass maintains that passwords were not compromised.
  • LastPass must defend its credential-stuffing explanation against user reports of unknown-IP login attempts, making the accuracy of its security alerts an immediate trust issue.

Second-order effects

  • The gap between user reports and LastPass's denial raises the value of MFA as an account-control layer, because blocked login attempts are occurring at the account-access boundary rather than being described as vault access.
  • LastPass's incident messaging becomes part of its product risk: the earlier assurance that vaults were untouched offers a precedent, but later disclosures make each similar assurance more consequential for user confidence.

Third-order effects

  • The related sequence points toward password-manager security being judged across a chain of controls—user authentication, employee access, source code, and cloud backups—rather than by whether a single vault was accessed.
  • As incidents move from reported credential abuse to customer-data access through cloud storage, providers face a durable credibility burden: narrowly accurate statements about one layer may not settle concerns about the broader service.

The trend: Password-manager trust is increasingly determined by layered incident resilience and clear boundary-setting between account attacks, internal systems, and stored vault data.

Discussion

  • @kevincollier Kevin Collier on x
    Per LastPass, the whole kerfuffle yesterday was that somebody unsuccessfully tried credential stuffing, but that prompted the company to mistakenly send customers security alerts. No actual harm done, but another blow to public confidence in one of the biggest password managers. …
  • @technology_greg @technology_greg on x
    Something very strange and bad is happening to a lot of people's @LastPass accounts. I posted this to Hacker News and it gathered 192 comments, including 7 separate reports of master password breaches & login attempts from the same Brazil IP range. Uhh. https://news.ycombinator.c…
  • @briankrebs @briankrebs on x
    LastPass/LogMeIn updated their statement, saying “some of the security alerts were likely triggered in error.” https://twitter.com/... https://twitter.com/...
  • @troyhunt Troy Hunt on x
    And the answer to the @LastPass riddle is... not credential stuffing: “Our investigation has since found that some of these security alerts, which were sent to a limited subset of LastPass users, were likely triggered in error”: https://blog.lastpass.com/...
  • @calbucci Marcelo Calbucci on x
    Start investigating here: 1) Do all these users use Android? Have they sideloaded an app? 2) Do all these users have the same Chrome Extension? 3) Do all these users have the same external keyboard? https://twitter.com/...
  • @nicnguyen Nic Nguyen on x
    “no actual harm done” is an important point here. though multiple past vulnerability reports prompted me to switch from lastpass years ago. https://twitter.com/...
  • @kevincollier Kevin Collier on x
    That security alert, per @serghei: “Someone just used your master password to try to log in to your account from a device or location we didn't recognize. LastPass blocked this attempt, but you should take a closer look. Was this you?” https://www.bleepingcomputer.com/ ...
  • @sub8u Subrahmanyam Kvj on x
    In case you are using Lastpass (or any other password manager - which you should!), make sure you don't reuse your master password and keep it absolutely unique. Looks like Lastpass is being hit with credential stuffing. https://www.bleepingcomputer.com/ ...
  • @mayhemdayone Bob Diachenko on x
    At the same time thousands of LastPass login pairs were found in the recent Redline Stealer malware logs I reported earlier... Coincidence? https://twitter.com/...
  • @seldo Laurie Voss on x
    LastPass has had another major breach. This is what the third, fourth time they've had this happen? Don't use LastPass. https://www.bleepingcomputer.com/ ...
  • @dylanreeve Dylan Reeve on x
    This is the worst case scenario with a password manager. Still unclear, but definitely worrying. If you use a password manager you should absolutely also be using multifactor auth with it. https://www.bleepingcomputer.com/ ...
  • @rstephens Robert Stephens on x
    iOS15 now supports MFA one-time password tokens. https://twitter.com/...
  • @epro Emil Protalinski on x
    This is why I refuse to use a password manager. Centralizing all my passwords so an attacker needs just one master password to get into all my accounts? No thanks. https://twitter.com/...
  • @martinsfp Martin Sfp Bryant on x
    *Supposedly* not something to worry too much about, but this is like the start of every password manager user's nightmare. https://twitter.com/...