LastPass Hit Again: What Users Need to Know About the Latest Breach
By: Jim Stickley and Tina Davis
August 2, 2026
Password management company LastPass is once again notifying customers about a security incident involving exposed user information. According to the company, the latest breach did not occur directly on LastPass systems. Instead, attackers reportedly gained access to customer information through a compromise at Klue, a third-party software provider used by LastPass. The stolen data is believed to include customer support case information and certain personal details submitted by users while seeking assistance.
At the time of disclosure, LastPass said there was no evidence that encrypted password vaults, master passwords, or stored credentials were accessed during the incident. However, security experts warn that even limited personal information can be valuable to cybercriminals. For users, the biggest concern is the increased risk of phishing attacks. Criminals may use information obtained from support tickets to create convincing phishing emails, text messages, (smishing) or phone calls (vishing) that appear to come from LastPass.
If you use LastPass, be especially cautious of unexpected communications requesting login credentials, multi-factor authentication codes, or account information. You should never give these out to anyone. Never click links in unsolicited emails claiming your account needs immediate attention. Instead, visit the LastPass website directly through your browser.
Remember that using a password manager, no matter which one it is, comes with a risk of your information being used to steal all of your passwords stored in them. That said, if there really is no other way you can keep track of using one password per website, proceed with caution. Whatever you do, make sure your master password is most definitely unique.
Users should also enable multi-factor authentication, review account activity regularly, and ensure their master password remains unique and strong. Staying alert may be the best defense against criminals looking to turn stolen support data into a much larger security problem.
The identity of the attackers has not been officially confirmed, some believe it was the group Icarus, a newly established extortion group. They also claim to have stolen information from several other companies. Investigators are still examining the incident, and no public attribution has been announced. However, the breach follows a series of security incidents that have kept LastPass under intense scrutiny since its major 2022 compromise.