The LastPass data breach of 2022-2023 serves as a reminder of how sophisticated cyber attacks can cascade into long-term security disasters. This comprehensive analysis breaks down the incident, its impact, and crucial lessons for organizations looking to strengthen their security posture.
The breach's consequences have been severe and long-lasting:
Enterprise Passkey Whitepaper. Practical guidance, rollout patterns and KPIs for passkey programs.
The breach began when attackers gained unauthorized access to LastPass's development environment through a single compromised developer account. At this stage, the attackers obtained:
Why are Passkeys important?
Passwords & phishing put enterprises at risk. Passkeys offer the only MFA solution balancing security and UX. Our whitepaper covers implementation and business impact.

What initially seemed contained quickly escalated when attackers leveraged the stolen information to:
Subscribe to our Passkeys Substack for the latest news.
In a revealing update, LastPass disclosed that attackers had:
Igor Gjorgjioski
Senior Product Lead, VicRoads
We hit 80% mobile passkey activation across 5M+ users without replacing our IDP.
See how VicRoads scaled passkeys to 5M+ users, alongside their existing IDP.
Read the case studyWhat this incident keeps demonstrating is that a stolen secret stays useful long after the intrusion itself is over. Passkeys remove the secret. The question a security team reaches first after a timeline like this one is narrower though: how much of our own login still rests on a shared secret today? Corbado Observe produces that figure from the login you already operate, reading password, SMS OTP, social and passkey flows alike, with no passkey programme running yet. It is the number a risk committee will ask for by the end of the week.
See Adoption Forecast in Corbado Observe →The second question is what a migration would realistically reach. The Adoption Forecast runs a Monte Carlo projection, and only two of the numbers going into it are measured: your OS mix and the platform authenticator availability Observe sees in your traffic. User count, average logins, skew and how hard you plan to ask are all typed in, and the login-frequency curve is derived from them. What comes out is a range under stated assumptions, which is the honest shape for a paper that has to survive a risk committee, because the assumptions go into the room with it.
Given the subject of this post, one point deserves precision. Nothing in Observe needs a
name or an email address to work, since it keys on opaque tus- and flw- values. The
SDK will still carry an identifier when your own code supplies one, which means the blast
radius of this telemetry is a function of your payload. Decide it once, document it, and
the next incident review starts from a known answer.
The LastPass data breach serves as a crucial lesson in the importance of comprehensive security measures and proper incident response. Organizations must take a proactive approach to security, implementing multiple layers of protection while preparing for potential breaches. By learning from this incident, companies can better protect their assets and maintain trust with their customers.
Corbado is the Passkey Intelligence Platform for large-scale CIAM teams running consumer authentication. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert →
Attackers used source code and technical information stolen from LastPass's development environment in August 2022 to access a third-party cloud storage service holding customer vault backups. This multi-stage escalation unfolded over several months before the full scope was disclosed in early 2023.
Attackers obtained both the encrypted vault backups and, critically, the decryption keys by deploying a keylogger on a senior DevOps engineer's home computer. Capturing master passwords alongside decryption keys meant encryption alone could not fully protect customer data.
A senior DevOps engineer's personal home computer was compromised through a vulnerability in third-party media software, a risk that robust endpoint protection policies for remote work devices are designed to prevent. Restricting personal software installation and enforcing security audits of home setups are key mitigations.
Exposed data spanned two categories: customer information including names, billing addresses, email addresses, phone numbers and IP addresses, plus technical data covering customer vault backups, DevOps secrets, cloud-based backup storage and MFA/Federation Database backups. This combination of personal and infrastructure data made the breach especially damaging.
Related Articles
Table of Contents