LastPass is a
password manager
A password manager is a software program to prevent password fatigue by Random password generator, automatically generating, Autofill, autofilling and storing Password, passwords. It can do this for Application software, local applications or web ...
application.
The standard version of LastPass comes with a
Web interface
In the industrial design field of human–computer interaction, a user interface (UI) is the space where interactions between humans and machines occur. The goal of this interaction is to allow effective operation and control of the machine fro ...
, but also includes
plugins for various
Web browser
A web browser, often shortened to browser, is an application for accessing websites. When a user requests a web page from a particular website, the browser retrieves its files from a web server and then displays the page on the user's scr ...
s and
apps for many smartphones. It also includes support for
bookmarklets.
Founded in 2008 by four developers,
Lastpass was acquired by
GoTo (formerly LogMeIn Inc.) for $110 million in 2015.
LastPass was spun-off from GoTo into a stand-alone business in 2024.
LastPass suffered significant
security incidents between 2011 and 2022. Notably, in late 2022, user data, billing information, and vaults (with some fields encrypted and others not)
were breached, leading many security professionals to call for users to change all their passwords and switch to other password managers.
Overview
A user's content in LastPass, including
password
A password, sometimes called a passcode, is secret data, typically a string of characters, usually used to confirm a user's identity. Traditionally, passwords were expected to be memorized, but the large number of password-protected services t ...
s and secure notes, is protected by one master password. The content is
synchronized to any device the user uses the LastPass software or app extensions on. Information is encrypted with
AES-256 encryption with
PBKDF2 SHA-256
SHA-2 (Secure Hash Algorithm 2) is a set of cryptographic hash functions designed by the United States National Security Agency (NSA) and first published in 2001. They are built using the Merkle–Damgård construction, from a one-way compressi ...
,
salted hashes, and the ability to increase password iterations value. Encryption and decryption takes place at the device level.
LastPass has a
form filler that automates password entering and form filling, and it supports
password generation, site sharing and site logging, and two-factor authentication. LastPass supports
two-factor authentication
Multi-factor authentication (MFA; two-factor authentication, or 2FA) is an electronic authentication method in which a user is granted access to a website or Application software, application only after successfully presenting two or more distin ...
via various methods including the LastPass Authenticator app for mobile phones as well as others including
YubiKey.
Unlike some other major password managers, LastPass offers a user-set
password hint, allowing access when the master password is missing.
History
On December 2, 2010, it was announced that LastPass had acquired
Xmarks, a web browser extension that enabled password synchronization between browsers. The acquisition meant the survival of Xmarks, which had financial troubles, and although the two services remained separate, the acquisition led to a reduced price for paid premium subscriptions combining the two services. On March 30, 2018, the Xmarks service was announced to be shut down on May 1, 2018, according to an email to LastPass users.
On October 9, 2015, GoTo acquired LastPass for $110 million. The company was combined under the LastPass brand with a similar product, Meldium, which had already been acquired by GoTo.
On March 16, 2016, LastPass released LastPass Authenticator, a free two-factor authentication app.
On November 2, 2016, LastPass announced that free accounts would now support synchronizing user content to any device, a feature previously exclusive to paid accounts. Earlier, a free account on the service meant it would sync content to only one app.
In August 2017, LastPass announced LastPass Families, a family plan for sharing passwords, bank account info, and other sensitive data among family members for a $48 annual subscription. They also doubled the price of the Premium version without adding any new features to it. Instead, some features of the free version were removed.
On December 14, 2021, GoTo announced that LastPass would be established as an independent company. The spin-off was completed in May 2024, with LastPass being directly controlled by
Francisco Partners
Francisco Partners Management, L.P., doing business as Francisco Partners, is an American private equity firm focused exclusively on investments in technology and technology-enabled services businesses. It was founded in August 1999 and based in ...
and
Elliott Investment Management, the
private equity firm
A private equity firm or private equity company (often described as a financial sponsor) is an investment management company that provides financial backing and makes investments in the private equity of a Startup company, startup or of an existin ...
s that took GoTo private in 2020.
Reception
In March 2009, ''
PC Magazine
''PC Magazine'' (shortened as ''PCMag'') is an American computer magazine published by Ziff Davis. A print edition was published from 1982 to January 2009. Publication of online editions started in late 1994 and continues .
Overview
''PC Mag ...
'' awarded LastPass five stars, an "Excellent" mark, and their "Editors' Choice" for password management. A new review in 2016 following the release of LastPass 4.0 earned the service again five stars, an "Outstanding" mark, and "Editors' Choice" honor.
In July 2010, LastPass's security model was extensively covered and approved of by
Steve Gibson in his
Security Now podcast episode 256. He also revisited the subject and how it relates to the
National Security Agency
The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
in Security Now podcast episode 421.
In October 2015 when GoTo acquired LastPass, founder Joe Siegrist's blog was filled with user comments voicing criticism of GoTo. Web sites ZDNet, Forbes and Infoworld posted articles mentioning the outcry by existing customers, some of whom said they would refuse to do business with GoTo, and raised other concerns about GoTo's reputation.
In a 2017 ''
Consumer Reports
Consumer Reports (CR), formerly Consumers Union (CU), is an American nonprofit consumer organization dedicated to independent product testing, investigative journalism, consumer-oriented research, public education, and consumer advocacy.
Founded ...
'' article commented LastPass a popular password manager (alongside
Dashlane,
KeePass, and
1Password), with the choice between them mostly down to personal preference.
In March 2019, Lastpass was awarded the Best Product in Identity Management award during the seventh annual Cyber Defense Magazine InfoSec Awards.
Security incidents
2015 security breach
In June 2015, the LastPass team discovered and halted suspicious activity on their network. Their investigation revealed that LastPass account email addresses, password reminders, server per user salts, and authentication hashes were compromised; however, encrypted user vault data was not affected.
2021 third-party trackers and security incident
In 2021, it was discovered that the Android app contained
third-party trackers. At the end of 2021, LastPass warned users that their master passwords were compromised.
2022 customer data and partially-encrypted vault theft
In August 2022, a hacker stole a copy of a customer database, and some copies of the customers' password vaults. The stolen information includes names, email addresses, billing addresses, partial credit cards and website URLs.
Some of the data in the vaults was unencrypted, while other data was encrypted with users' master passwords. The security of each user's encrypted data depends on the
strength of the user's master password, or whether the password had previously been leaked, and the number of rounds of encryption used. Details of the number of rounds for each customer was stolen. Some customer vaults were more vulnerable to decryption than others.
In November 2022, LastPass assured users that passwords stored with the service were still secure.
The customer data included customers' names, billing addresses, phone numbers, email addresses, IP addresses and partial credit card numbers, and the number of rounds of encryption used,
multi-factor authentication (MFA) seeds and device identifiers.
The vault data included, for each breached user, unencrypted website URLs
and site names, and encrypted usernames, passwords and form data for those sites.
The threat actor first gained unauthorized access to portions of their development environment, source code, and technical information through a single compromised developer's laptop computer.
LastPass responded by re-building their development environment and rotating certificates.
The actor, however, used the information to target and hack the computer of a senior
DevOps
DevOps is the integration and automation of the software development and information technology operations. DevOps encompasses necessary tasks of software development and can lead to shortening development time and improving the development life ...
engineer,
and used a
keystroke logger to obtain that engineer's master password. The actor then gained access to an encrypted corporate vault, which was shared between just four engineers. That vault contained keys to
Amazon S3 "buckets" of the backups to customer files. The actor obtained the user database of August 14, 2022, and several password vault backups taken between August 20 and September 16, 2022.
Commentators expressed concerns that if a user's master
password was weak or leaked,
the
encrypted parts of the customer's data could be
decrypted. Initially, LastPass stated no action was necessary for the majority of its customers,
but other sources recommended changing all passwords and vigilance against possible
phishing
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
attacks.
A
class-action lawsuit was initiated in early 2023, with the anonymous plaintiff stating that LastPass failed to keep users' information safe.
Of particular concern in the lawsuit was the increased risk of the details being used in
phishing
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
attacks.
In September 2023, a potential link was made between the 2022 data theft and a total of more than $35 million in cryptocurrency that had been stolen from over 150 victims since December 2022. The link was made due the fact that almost all victims were LastPass users. In 2025, a larger heist of $150 million was also linked to the 2022 data theft.
See also
*
List of password managers
Notes
References
External links
*
{{Password managers
Password managers
Cryptographic software
Nonfree Firefox WebExtensions
Internet Explorer add-ons
2008 software
Google Chrome extensions
Proprietary cross-platform software
2015 mergers and acquisitions
Private equity portfolio companies
Corporate spin-offs