Why this review is organised around one event
Most reviews on this site weigh ownership, jurisdiction, pricing and features and arrive at a balance. This one cannot, because LastPass is the only product in the category where the failure everybody worries about actually occurred, at scale, and cannot be undone.
That is not a rhetorical position. It is the practical one. Every other consideration on this page is downstream of a vault archive that is still in circulation.
The breach, in sequence
In August 2022 an attacker compromised a LastPass developer account and took source code and internal technical documentation. The company’s early communication said customer data had not been reached.
The attacker used what they had taken to go further, and in December 2022 LastPass confirmed that backups of customer vault data had been exfiltrated from cloud storage. Those vaults held encrypted usernames and passwords, protected by each customer’s master password, and unencrypted site URLs sitting alongside them.
Two features of this make it worse than a typical breach.
The first is that the URLs were in plain text. An attacker holding a million encrypted vaults has to decide where to spend cracking effort, and unencrypted URLs answer that question for them. Vaults containing exchanges, banks and corporate logins can be identified and prioritised without decrypting anything.
The second is that the theft is permanent. A stolen password can be changed. A stolen encrypted vault cannot be recalled, cannot be expired, and can be attacked offline indefinitely with no rate limit and no lockout. Accounts on older low iteration counts, or with master passwords short enough to guess, have continued to fall in the years since, and public reporting has connected cryptocurrency thefts to credentials recovered from that archive.
What it taught the rest of the category
Two design lessons came out of it, and both are visible in the products we rank above this one.
Encrypt the metadata, not just the secret. A record’s URL is not incidental data; in bulk it is a targeting map.
And put something other than a human-chosen password in front of the vault. 1Password’s Secret Key exists precisely so that a stolen vault cannot be attacked with the master password alone, and after 2022 that stopped looking like a marketing feature.
Ownership
LastPass US LP sits under GoTo, formerly LogMeIn, which was taken private in 2020 by Francisco Partners and Evergreen Coast Capital in a $4.3B transaction. LastPass was spun out as a separate company in 2024 but remains under the same private-equity control, alongside sibling brands including GoTo, LogMeIn and Rescue.
Private-equity ownership is not itself a security failure and we do not present it as one. What it changes is the horizon. A firm holding an asset toward an eventual sale is optimising for a period measured in years, while the vault you build is something you intend to keep for decades, and cost discipline in a portfolio company is not a neutral fact when the product is security infrastructure. The structure is recorded on our ownership explorer.
The United States jurisdiction, inside the Five Eyes, is worth noting and is a long way down the list of concerns here.
Audits, or the absence of them
Our provider record for LastPass has an empty audit list, and that is not an oversight. We could find no published independent audit of the current architecture to link to.
The company has published bulletins describing what it changed after 2022: higher default iteration counts for key derivation, and encryption extended over more of each record. Those are the correct remedies and we do not dismiss them. They are also the company’s own account of its own security, following an incident that was disclosed in stages over several months, and that is exactly the situation where an external report is not optional. Bitwarden, 1Password and Proton Pass all publish external audits. This one does not.
What it costs
| Plan | Intro | Renewal | True cost per month over 3 years |
|---|---|---|---|
| Free | $0 | $0 | $0, and limited to one device type |
| Premium (1 year) | $36.00 | $36.00 | about $3.00 |
| Families (1 year) | $48.00 | $48.00 | about $4.00 |
Pricing is at least honest in structure: the renewal matches the intro on both plans, so there is no second-year surprise for our true cost calculator to unwind.
The problem is the comparison. Premium at about $3.00 a month over three years is more than three times Bitwarden Premium and slightly above 1Password Individual. You are paying a premium price for the only product here with no published audit and a stolen vault archive in circulation.
The free tier deserves its own sentence. Unlimited passwords, but only on one device type, computers or phones and not both. For almost everyone that ends its usefulness the moment they pick up a phone, which is the point at which the upgrade prompt appears. Calling that a free tier is generous.
If you are still on it
Do not start with migration. Start with the credentials.
Anything that was in your vault before December 2022 should be treated as compromised. Change email passwords first, because email is the reset path to everything else, then financial accounts, then anything touching cryptocurrency, and enable two-factor authentication wherever it is available. Then move to another manager, and choose a master password that has never existed anywhere before; our password generator runs entirely in your browser and will produce one.
Changing only your LastPass master password does not solve this. The attacker has a copy of the old encrypted vault, not access to your live account, and nothing you do to that account affects the copy.
The verdict
There is no set of requirements we can construct where LastPass is the right answer for a new user. Cheaper, audited, open-source alternatives exist, and so does a better-designed closed-source one at a similar price. It appears in the avoid section of our best password managers ranking, and this review exists mainly so that people arriving from a search know precisely why, and know what to do about a vault that was taken.
What we have not tested
We have not run our own hands-on testing of LastPass. We have not verified the post-breach architecture changes ourselves, we have not measured autofill or import behaviour, and everything above about the 2022 incident comes from the company’s own disclosures and public reporting rather than from any work of ours. The pending dimensions of the score stay pending until we test.



