LastPass Breach Analysis: The 2022 Hack, the 2026 Klue Leak and Kiwi Safety

LastPass Breach Analysis: Security History, the 2026 Hack, and Kiwi Trust

Choosing a digital vault to hold your passwords is as much a question of trust as convenience. A password manager stores the keys to your email, banking, and identity, so its track record on security matters just as much as how neatly it fills in login forms. This analysis walks through the security history of LastPass — one of the best-known password managers used across Aotearoa New Zealand — including the supply-chain leak disclosed in June 2026, the far more serious vault theft of late 2022, and the rebuild the company has run since. The goal is a clear, fact-based picture of whether LastPass still deserves a place on your devices, without hype in either direction.

Key Points

  • June 2026 leak: attackers hit a third party, Klue, and reached LastPass’s Salesforce CRM through stolen OAuth tokens — password vaults were not accessed.
  • What leaked: customer names, emails, phone numbers, postal addresses, and support-case histories, raising the risk of targeted phishing.
  • The 2022 theft: a far more serious breach exposed encrypted vault backups plus unencrypted website URLs, and has been linked to hundreds of millions in crypto losses.
  • Security rebuilt: LastPass now defaults to 600,000 PBKDF2 iterations, encrypts URL fields, and carries a Google Play Independent Security Review badge.
  • Your move: use a long, unique master password and phishing-resistant two-factor authentication, and stay alert to scam messages that reference real support tickets.

What happened in the June 2026 LastPass breach?

In mid-June 2026, LastPass disclosed that customer data had been exposed through a third party rather than through its own systems. The attackers did not break into LastPass’s core infrastructure, and they did not touch the encrypted vaults where your passwords live. Instead, an extortion group known as “Icarus” compromised Klue, a market-intelligence platform that LastPass used internally and that connected to LastPass’s Salesforce CRM. CRM stands for customer relationship management — the database a company uses to track customers, sales enquiries, and support tickets.

The entry point was a single credential that had been sitting dormant inside Klue’s systems since 2022. Using it, the attackers stole active OAuth tokens. An OAuth token is a digital “access pass” that lets one service connect to another without re-entering a password; because Klue’s tokens were trusted by Salesforce, the attackers could quietly query LastPass’s customer support and sales records. LastPass detected the unauthorised access on 12 June 2026 and publicly disclosed the incident around 22 June 2026, after the compromised tokens were revoked. The same forgotten credential exposed the Salesforce environments of roughly 190 to 200 organisations in total, with a dozen or more — including LastPass, HackerOne, Tanium, and Snyk — confirming they were affected.

Which customer data was exposed

The most important point for New Zealand users is that password vaults, master password hashes, and encryption keys were not accessed in this incident. Because the breach was confined to a peripheral customer-relationship database, your stored credentials stayed protected by their existing client-side encryption. What the attackers did take was a set of unencrypted contact and support records:

Exposed data (June 2026)SensitivityWhy it matters for you
Customer namesLowLets scammers address you by name to seem legitimate
Email addressesMediumFuels targeted spam and phishing to a verified inbox
Phone numbersMediumEnables scam texts (smishing) and call-based fraud
Postal addressesLowAdds a convincing “detail” to social-engineering attempts
Support case historiesHighGives attackers real context to make scams believable

The 2022 vault theft and why it still matters

The 2026 incident was rated a medium-severity event because it never reached the vaults. Judging whether LastPass is genuinely safe, though, means looking back at the far more serious breach of late 2022 — one of the most consequential incidents in the history of consumer cyber security, and the reason many analysts still treat cloud-hosted vaults with caution.

That attack unfolded in stages. Threat actors first compromised a senior DevOps engineer’s home computer by exploiting a vulnerability in a third-party media-player application, installing a keylogger to capture keystrokes. With the corporate access keys taken from that machine, they reached LastPass’s cloud storage and exfiltrated full backups of customer data — including copies of millions of encrypted password vaults.

The problem of partly encrypted backups

The structural weakness was in how those backups were built. Usernames and passwords were sealed behind client-side 256-bit AES encryption (a strong, industry-standard cipher applied on your device before data is uploaded). But several fields around them were left unencrypted by design:

  • Website addresses were readable: the URL of every account in a vault was stored in plain text, handing attackers a map of each victim’s most valuable accounts.
  • Offline cracking was possible: because the attackers held their own copies of the vaults, they could run automated password-guessing software indefinitely, with no account lockouts or alerts to stop them.
  • Other metadata leaked too: billing addresses, email addresses, phone numbers, and IP addresses were also exposed in the unencrypted portions of the backup.

The consequences were severe and long-running. Vaults protected by short or reused master passwords could be cracked offline, and investigators later tied the breach to large-scale cryptocurrency theft. In 2025 the FBI linked a single US$150 million crypto heist to the 2022 LastPass compromise, and independent researchers have connected the incident to hundreds of millions of dollars in stolen digital assets overall. In late 2025, LastPass agreed to a proposed class-action settlement of up to US$24.45 million, covering both general claims and documented cryptocurrency losses.

At a Glance

Aspect2022 vault theftJune 2026 Klue leak
Where it happenedLastPass cloud backups (direct)Klue third-party vendor / Salesforce CRM
SeverityCriticalMedium
Vaults affected?Yes — encrypted vaults copiedNo — vaults untouched
Data exposedEncrypted passwords plus unencrypted URLs and metadataNames, emails, phones, addresses, support cases
Main riskOffline cracking; crypto theftTargeted phishing and scam messages

What LastPass has changed since the hacks

After the 2022 fallout, and following its 2024 spin-off into a standalone company separate from GoTo, LastPass ran a multi-year security rebuild. The company says it discarded legacy code in favour of a modern “secure software factory,” with continuous tracking of every software component (a software bill of materials, or SBOM) and stricter compliance controls. Its corporate history and ownership changes are documented on Wikipedia.

The most meaningful defence against offline vault cracking is the combination of a long master password and a strong key-derivation function — the process that turns your master password into an encryption key. LastPass has hardened both its defaults and the way vault data is stored.

Hashing and storage upgrades

PBKDF2 is the key-derivation function LastPass uses; it deliberately repeats a calculation many times so that each password guess is slow and expensive for an attacker. The table below shows how the current baseline compares with the 2022-era configuration:

Configuration layerLegacy 2022 setupModern 2026 setup
PBKDF2 iterations100,100 (older accounts often far fewer)600,000 (current default)
Website URL fieldsStored unencryptedFully encrypted
Independent auditsInfrequent internal reviewsOngoing SOC 2 Type II and ISO 27001 programmes
Mobile app assuranceStandard vendor submissionGoogle Play Independent Security Review (MASA AL2)

It is worth knowing that raising the iteration count does not automatically re-protect a vault that was already stolen in 2022. Any backup copied back then reflects the settings in place at the time, which is why anyone who was a LastPass user before 2023 and has not since changed their master password should still treat their old credentials as potentially exposed.

The phishing threat the 2026 leak creates

Even though encrypted passwords were untouched in June 2026, the exposure of names, verified email addresses, phone numbers, and support-case text creates a real risk: highly targeted phishing. Phishing is a scam that impersonates a trusted organisation to trick you into handing over sensitive information. Because the Icarus group holds genuine details from real support tickets, its messages can be far more convincing than generic spam.

Picture a New Zealand user who once raised a ticket about a billing glitch. A scam email or text could reference that exact issue, claim the account has been locked because of “breach activity,” and push the person to click a link and re-enter their master password. The urgency is engineered to make you act before you think.

How to spot these scams

  • Master-password requests are always fake: LastPass will never ask you to reveal your master password by email, text, or phone.
  • Check the sender’s domain: inspect the full email address; lookalike domains and small misspellings are a giveaway.
  • Never use “reset” links from messages: if an alert claims you must change your password, ignore the link and log in yourself through the official app or extension.
  • Distrust urgency: threats of imminent account deletion or data loss are a pressure tactic, not a real security process.

How to secure your LastPass account now

If LastPass suits your routine and you plan to stay, a few steps will harden your account even if your contact details are already circulating. If you are still weighing it up, our LastPass review covers its current features and the LastPass pricing guide sets out what each plan costs.

The single most important action is your master password. If it is short, guessable, or reused anywhere else, it is the weak point an offline attacker would target first. Replace it with a long, unique passphrase — aim for something like 16 characters or more that you do not use on any other service.

  • Confirm your iteration count: in your account settings, check that PBKDF2 is set to 600,000 iterations; older accounts may still sit on a lower legacy value.
  • Turn on phishing-resistant 2FA: two-factor authentication (2FA) adds a second check at login. Move away from SMS codes, which can be intercepted through SIM-swapping, and use an authenticator app or a hardware security key such as a YubiKey.
  • Review saved logins: use the built-in security dashboard to find weak or reused passwords and change any that also appeared in past breaches.
  • Rotate high-value credentials: if you were a user before 2023, prioritise changing passwords for banking, email, and crypto accounts, and remove any that no longer need to be stored.

How LastPass compares with other password managers

The pattern of incidents has led many people to look at how rival services isolate data, so a single server-side leak does less damage. Architecture varies widely. Bitwarden, for example, is open source and lets advanced users self-host their vault on their own hardware, while 1Password pairs your master password with a separate 34-character Secret Key stored only on your devices. The table below compares a few widely used options; provider names link to their official sites.

ProviderKnown vault breachCore architectureSelf-hosting
LastPassYes — 2022 vault backup theftSingle key derived from master passwordNo (cloud only)
1PasswordNone knownMaster password plus local Secret KeyNo (cloud only)
BitwardenNone knownOpen source, Argon2id optionYes (Docker/self-host)
KeeperNone knownClosed source, zero-knowledgeNo (cloud only)
Proton PassNone knownOpen source, end-to-end encryptedNo (managed cloud)

For a broader look at how these tools work and which fits different needs, see our New Zealand password manager guide.

What this means for New Zealanders

New Zealand’s fast Chorus fibre and 5G mobile networks from Spark, One NZ, and 2degrees keep your apps syncing quickly, but they cannot protect you when a third-party vendor leaks your contact details. Because the June 2026 leak exposed names and phone numbers, it pays to be extra cautious with the accounts that matter most to Kiwi households and to keep them decoupled from any single reused password:

  • Online banking: use a unique, strong password for every bank — ANZ, ASB, BNZ, Westpac NZ, and Kiwibank — and never reuse your email password on them.
  • Government services: protect your logins for RealMe, IRD’s myIR, and ACC, which link to tax and identity records.
  • Investing platforms: secure accounts on services such as Sharesies, Hatch, and Kernel, where credentials guard real money.
  • Everyday accounts: Trade Me, retailers, and streaming logins are also worth unique passwords, since reused ones let one leak cascade into many.

If you receive a suspicious message referencing LastPass, you can report it to CERT NZ. Broader advice on staying safe online is covered in our guide to cyber security in New Zealand.

Is LastPass safe to keep using?

The honest picture is mixed. Day to day, LastPass remains capable: its autofill, onboarding, security dashboard, and dark-web monitoring are polished, and its rebuilt apps now carry an independent Google Play security review. On the technology alone, the modern version is stronger than it has ever been, and the June 2026 leak never reached the vaults.

But a password manager is fundamentally a trust product, and LastPass has now confirmed two customer-data incidents in four years on top of the catastrophic 2022 vault theft. If you value the interface and are willing to enforce a long, unique master password plus a hardware security key, staying is a defensible choice. If an unblemished security record is what gives you peace of mind, moving to a manager with no history of vault theft — such as Bitwarden, 1Password, or Proton Pass — is the more cautious path. Either way, the right response to the recent leak is the same: harden your account and stay alert to phishing.

Frequently asked questions

Was LastPass hacked again in June 2026?

Yes, but not directly. Attackers compromised a third-party vendor called Klue and stole OAuth tokens that gave them access to LastPass’s Salesforce CRM. They took customer contact details and support-case records; LastPass’s own infrastructure and password vaults were not accessed.

Were my saved passwords exposed in the 2026 breach?

No. Password vaults, master password hashes, and encryption keys were untouched. Only unencrypted customer-relationship data — names, emails, phone numbers, postal addresses, and support histories — was taken, so your stored logins stayed protected by client-side encryption.

What was the 2022 LastPass breach?

In late 2022, attackers compromised a LastPass engineer’s home computer and used the stolen keys to exfiltrate cloud backups of customer vaults. Passwords were encrypted, but website URLs and other metadata were not, and vaults with weak master passwords could be cracked offline.

What should I do right now to stay safe?

Set a long, unique master passphrase, confirm your account uses 600,000 PBKDF2 iterations, and switch on phishing-resistant two-factor authentication with an authenticator app or hardware key. Treat any message asking for your master password as a scam.

Should I switch to a different password manager?

That depends on your priorities. LastPass’s current technology is solid, but it has a repeated breach history. If a clean record matters most to you, alternatives such as Bitwarden, 1Password, or Proton Pass have no known vault breaches; Bitwarden also supports self-hosting for full data control.