

The breach and security incident also revealed that LastPass stores unencrypted URLs in user vaults, a practice that can potentially expose users' credentials. In 2022, LastPass failed to immediately inform users after a malicious third party stole data related to their encrypted vaults. At PCMag, we expect password management companies to secure users' credentials and inform customers when their vaults may be at risk. Using a password manager is difficult without trusting the company behind the product. Keeping track of dozens or hundreds of strong and unique passwords isn't possible without a password manager. PCMag is currently reviewing its recommendations of password managers and retesting them.Īt this time, we recommend open-source Editors' Choice winner Bitwarden for anyone looking to switch to a new password manager. Additional details about the breach and the aftermath came to light in February 2023.īecause LastPass initially failed to inform its users of the breach and to adequately protect them, we removed the score and Editors' Choice designation from this review.
/cdn.vox-cdn.com/uploads/chorus_image/image/55782269/lp.0.jpg)
In late 2022, the company announced that a data breach exposed users' encrypted vault data and other unencrypted personal data.

