← Blog

LastPass Data Breaches: Full Timeline Through 2026

Share on X

People search LastPass data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 6 LastPass-linked incidents (1 company-confirmed), with headline counts up to 1.6M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why LastPass breach history matters

LastPass operates in Cybersecurity (United States). Across indexed rows, recurring themes include credential theft and social engineering, third-party and supply-chain exposure, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — Klue OAuth supply-chain breach; Salesforce CRM customer data accessed

Verified breach. Downstream Klue supply-chain victim — June 2026. LastPass disclosed June 23, 2026 that on June 12 it learned of the Klue (klue.com) security incident affecting the market-intelligence integration connected to LastPass Salesforce and Gong systems. Investigation found an unauthorized actor obtained OAuth tokens Klue held for customers and used them to access LastPass customer data within Salesforce—names, phones, emails, addresses, support cases, and CRM/sales data. LastPass found no evidence of Gong-related data acc Exposed categories include Customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM-related data per LastPass—no evidence Gong call/email data accessed; pas. No attested victim count is published for this row yet. See the lastpass-klue-salesforce 2026 record and canonical BreachHistory entry.

2022 — vault data stolen

Cataloged incident. Two incidents: August—developer laptop compromised, source code and backup encryption key stolen. December—DevOps engineer phished, vault keys stolen. Customer account info and encrypted vault data (URLs, usernames, passwords) obtained. Exposed categories include Passwords, Usernames, Names, Source code. No attested victim count is published for this row yet. See the lp2022 and canonical BreachHistory entry.

2022 — 1.6M users, developer laptop

Cataloged incident. Hacker compromised developer laptop, then senior employee Plex. Customer names, emails, phones, URLs. Passwords remained encrypted. ICO fined £1.2M in 2025. Exposed categories include Names, emails, phones, URLs. BreachHistory cites approximately 1.6M+ affected records in this row. See the lastpass-uk2022 and canonical BreachHistory entry.

2022 — — Password vaults

Cataloged incident. Hacked. Password vaults. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the lastpass2022 and canonical BreachHistory entry.

2022 — — Password vaults

Cataloged incident. Hacked. Password vaults. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the lastpass-20222022 and canonical BreachHistory entry.

2015 — — LastPass: LastPass notified customers of a data breach when…

Cataloged incident. LastPass notified customers of a data breach when they discovered suspicious activity on their network. The company has communicated that In our investigation, we have found no evidence that encrypted user vault data was taken, nor that LastPass user accounts were accessed. The investigation has shown, however, that LastPass account email addresses, password reminders, server per user salts, and authentication hashes were compromised.The company is requiring that all users who are logging in Exposed categories include Personal information. No attested victim count is published for this row yet. See the lastpass2015 and canonical BreachHistory entry.

Patterns and analysis

  • Credential theft and social engineering — appears across multiple LastPass catalog entries; prioritize controls that address this class of failure.
  • Third-party and supply-chain exposure — appears across multiple LastPass catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple LastPass catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the LastPass company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/lastpass · Latest: lastpass-klue-salesforce2026.

Sources: BreachHistory catalog (6 rows for LastPass), company and regulator disclosures cited in individual breach records.