Skip to main content
WhatTermsWhatTerms
← Back to LastPass

Breach exposure

Public breaches involving LastPass

Cross-matched against the WhatTerms breach catalog. Each entry links the breach disclosure, names the data classes confirmed exposed, and matches each class to a concrete recovery action — not just “your email was leaked”.

Recovery actions

Sorted by severity. Each action maps to one or more data classes confirmed exposed across the breaches below.

  • Rotate your password on the breached service. Rotate it everywhere you reused it.

    High

    Hashes are subject to offline cracking — assume it's a matter of time.

  • Add the leaked address to your data-broker opt-out scope (DeleteMe / Optery / Kanary).

    High

    Addresses fuel doxxing and physical-world risk.

  • Switch this service to a per-service email alias and treat the leaked address as compromised.

    Medium

    Exposed emails feed phishing campaigns and credential-stuffing lists.

  • Recognize that geographic and ISP correlation is now possible; consider VPN for sensitive sessions.

    Medium

    IP addresses tie to physical and ISP-level identity.

LastPass

Disclosed 2022-12-22 · 25.0M accounts

Encrypted vaults exfiltrated. Master passwords were not stolen but vaults are now subject to offline brute-force.

Data classes exposed

  • Email address
  • Hashed password
  • Home address
  • IP address

Source: LastPass security advisory; multiple updates through Q1 2023. Read disclosure ↗