vpnandprivacy

password manager review · 2026

LastPass review: the one case where the worst outcome actually happened

Customer vaults were stolen in 2022. That is the whole review.

50
Weak · #7 of 7 password managers
By The VPN and Privacy team Updated 6 Sept 2026 Facts re-checked 6 Sept 2026
Runs on iOS Android Mac Windows Linux Router Browser TV
JurisdictionUnited States
Intelligence allianceFive Eyes
No-logs auditNone found
Founded2008
Ultimate owner GoTo (LogMeIn) United States · Five Eyes
Operates LastPass LastPass US LP
GoToLogMeInRescue
Sibling brands share the same ultimate owner as LastPass.

Owned by GoTo, formerly LogMeIn, which was taken private in 2020 by Francisco Partners and Evergreen Coast Capital for $4.3B. LastPass was spun out as a separate company in 2024 but remains under the same private-equity control.

Public-source facts, not yet checked against primary documents. How we verify.

Lab test pending: score uses public, checkable data only. How we verify.

Verdict

In 2022 an attacker took backups of LastPass customer vaults. The password fields inside were encrypted with each user's master password, but the site URLs were not encrypted at all, and those stolen vaults cannot be recalled, rotated or expired, which means weak master passwords from that era are still being cracked offline years later. Around that sits private-equity ownership through GoTo, no published independent audit of the current architecture, and a free tier restricted to a single device type. There are three better products at the same price or less, and no reason we can construct for a new user to start here.

Best for

Existing users who have not migrated yet, and who need to understand what to do about credentials that were in a vault taken in 2022.

Not for

Anyone choosing a password manager now. There is no configuration of requirements where this is the answer.

Visit LastPass Compare with Bitwarden Not an affiliate link. We earn nothing if you buy.
LastPass iPhone app, screen 1 of 4LastPass iPhone app, screen 2 of 4LastPass iPhone app, screen 3 of 4LastPass iPhone app, screen 4 of 4
LastPass's current iPhone app, as listed on the App Store. Screenshots are the developer's; we reproduce them to identify the product.

Score breakdown

Privacy & trust
16
Price & renewal
93
Features
66
Streaming
0
Censorship bypass
0
App quality
58
Speed (our tests)
0
Support & refunds
52
Score by dimension LastPass: Privacy 16, Price 93, Features 66, Streaming 0, Censorship 0, Apps 58, Speed 0, Support 52. PrivacyPriceFeaturesStreamingCensorshipAppsSpeedSupport
All eight dimensions scored from checkable data or our own tests.

Weights: default profile. How the score works.

Pros

  • Long-established with wide platform support
  • Passkey support arrived early
  • Free tier still syncs, within one device type

Cons

  • In 2022 an attacker took backups of customer vaults, including encrypted passwords, alongside unencrypted site URLs
  • Vaults taken in that breach are being brute-forced offline, and old weak master passwords are still being cracked years later
  • No published independent audit of the current architecture
  • Private-equity ownership since 2020
  • Free tier restricted to one device type

Pricing, including what it costs after renewal

PlanIntro totalPer monthRenewal totalTrue cost / mo over 3 years
Premium · 12 months$36.00$3.00$36.00$3.00
Families · 12 months$48.00$4.00$48.00$4.00
Intro, per monthRenewal, per month
Renewal price matches the intro price on every confirmed plan. Prices in USD.

The free tier is restricted to one device type — either computers or phones, not both — which effectively ends its usefulness.

iOS app quality

App Store review analysis

100 most recent reviews across 2 storefronts, 2025-02-28 to 2026-08-30. Listing rating 4.38★ from 57,188 ratings. Version 6.57.0, released 2026-08-10.

58
Sentiment improving last 90 daysCritical complaints 44%
Customer support
20%
iOS integration
17%
Crashes & bugs
15%
Privacy concerns
12%
Billing & auto-renew
7%
Interface & usability
4%
Slow speeds
1%
Battery drain
1%
  • ★☆☆☆☆ “I pay for premium and it tells me I need to ‘upgrade to premium’?!?!” App Store reviewer, 2026-06-06
  • ★☆☆☆☆ “Which makes me think leaving is the best decision to make.” App Store reviewer, 2026-06-01
  • ★☆☆☆☆ “Recently won’t save passwords from apps.” App Store reviewer, 2026-04-15
  • ★★★★☆ “Like … >10 years old, so kinda understandable, but still a really big issue” App Store reviewer, 2026-08-30
  • ★★★★☆ “(The log in screen has this feature, but not the lock screen.)” App Store reviewer, 2025-09-17

Themes tagged by keyword rules; percentages are share of sampled reviews mentioning the theme. Method.

What it does, feature by feature

Feature LastPass
Platforms iOS, Android, Mac, Windows, Linux, Browser
Open source
Self-hostable
Passkeys
End-to-end encrypted
Usable free tier
Family plan
Emergency access
Breach monitoring
Secure sharing
Works offline
Browser extension

A question mark means we have not confirmed the feature, not that it is missing. Hover a feature name for what it means.

Why this review is organised around one event

Most reviews on this site weigh ownership, jurisdiction, pricing and features and arrive at a balance. This one cannot, because LastPass is the only product in the category where the failure everybody worries about actually occurred, at scale, and cannot be undone.

That is not a rhetorical position. It is the practical one. Every other consideration on this page is downstream of a vault archive that is still in circulation.

The breach, in sequence

In August 2022 an attacker compromised a LastPass developer account and took source code and internal technical documentation. The company’s early communication said customer data had not been reached.

The attacker used what they had taken to go further, and in December 2022 LastPass confirmed that backups of customer vault data had been exfiltrated from cloud storage. Those vaults held encrypted usernames and passwords, protected by each customer’s master password, and unencrypted site URLs sitting alongside them.

Two features of this make it worse than a typical breach.

The first is that the URLs were in plain text. An attacker holding a million encrypted vaults has to decide where to spend cracking effort, and unencrypted URLs answer that question for them. Vaults containing exchanges, banks and corporate logins can be identified and prioritised without decrypting anything.

The second is that the theft is permanent. A stolen password can be changed. A stolen encrypted vault cannot be recalled, cannot be expired, and can be attacked offline indefinitely with no rate limit and no lockout. Accounts on older low iteration counts, or with master passwords short enough to guess, have continued to fall in the years since, and public reporting has connected cryptocurrency thefts to credentials recovered from that archive.

What it taught the rest of the category

Two design lessons came out of it, and both are visible in the products we rank above this one.

Encrypt the metadata, not just the secret. A record’s URL is not incidental data; in bulk it is a targeting map.

And put something other than a human-chosen password in front of the vault. 1Password’s Secret Key exists precisely so that a stolen vault cannot be attacked with the master password alone, and after 2022 that stopped looking like a marketing feature.

Ownership

LastPass US LP sits under GoTo, formerly LogMeIn, which was taken private in 2020 by Francisco Partners and Evergreen Coast Capital in a $4.3B transaction. LastPass was spun out as a separate company in 2024 but remains under the same private-equity control, alongside sibling brands including GoTo, LogMeIn and Rescue.

Private-equity ownership is not itself a security failure and we do not present it as one. What it changes is the horizon. A firm holding an asset toward an eventual sale is optimising for a period measured in years, while the vault you build is something you intend to keep for decades, and cost discipline in a portfolio company is not a neutral fact when the product is security infrastructure. The structure is recorded on our ownership explorer.

The United States jurisdiction, inside the Five Eyes, is worth noting and is a long way down the list of concerns here.

Audits, or the absence of them

Our provider record for LastPass has an empty audit list, and that is not an oversight. We could find no published independent audit of the current architecture to link to.

The company has published bulletins describing what it changed after 2022: higher default iteration counts for key derivation, and encryption extended over more of each record. Those are the correct remedies and we do not dismiss them. They are also the company’s own account of its own security, following an incident that was disclosed in stages over several months, and that is exactly the situation where an external report is not optional. Bitwarden, 1Password and Proton Pass all publish external audits. This one does not.

What it costs

PlanIntroRenewalTrue cost per month over 3 years
Free$0$0$0, and limited to one device type
Premium (1 year)$36.00$36.00about $3.00
Families (1 year)$48.00$48.00about $4.00

Pricing is at least honest in structure: the renewal matches the intro on both plans, so there is no second-year surprise for our true cost calculator to unwind.

The problem is the comparison. Premium at about $3.00 a month over three years is more than three times Bitwarden Premium and slightly above 1Password Individual. You are paying a premium price for the only product here with no published audit and a stolen vault archive in circulation.

The free tier deserves its own sentence. Unlimited passwords, but only on one device type, computers or phones and not both. For almost everyone that ends its usefulness the moment they pick up a phone, which is the point at which the upgrade prompt appears. Calling that a free tier is generous.

If you are still on it

Do not start with migration. Start with the credentials.

Anything that was in your vault before December 2022 should be treated as compromised. Change email passwords first, because email is the reset path to everything else, then financial accounts, then anything touching cryptocurrency, and enable two-factor authentication wherever it is available. Then move to another manager, and choose a master password that has never existed anywhere before; our password generator runs entirely in your browser and will produce one.

Changing only your LastPass master password does not solve this. The attacker has a copy of the old encrypted vault, not access to your live account, and nothing you do to that account affects the copy.

The verdict

There is no set of requirements we can construct where LastPass is the right answer for a new user. Cheaper, audited, open-source alternatives exist, and so does a better-designed closed-source one at a similar price. It appears in the avoid section of our best password managers ranking, and this review exists mainly so that people arriving from a search know precisely why, and know what to do about a vault that was taken.

What we have not tested

We have not run our own hands-on testing of LastPass. We have not verified the post-breach architecture changes ourselves, we have not measured autofill or import behaviour, and everything above about the 2022 incident comes from the company’s own disclosures and public reporting rather than from any work of ours. The pending dimensions of the score stay pending until we test.

LastPass against the top two password managers

Feature LastPassBitwardenProton Pass
Platforms iOS, Android, Mac, Windows, Linux, BrowseriOS, Android, Mac, Windows, Linux, BrowseriOS, Android, Mac, Windows, Linux, Browser
Open source
Self-hostable
Passkeys
End-to-end encrypted
Usable free tier
Family plan
Emergency access
Breach monitoring
Secure sharing
Works offline
Browser extension

A question mark means we have not confirmed the feature, not that it is missing. Hover a feature name for what it means.

Sources

2 sources · verification needs primary source check

The 2022 breach details come from LastPass own incident disclosures; confirm the current architecture claims against its security bulletin before restating them.

Frequently asked questions

What actually happened in the 2022 LastPass breach?

In August 2022 an attacker compromised a developer account and took source code and technical information. The company initially said customer data was not affected. Using information from that first intrusion, the attacker went on to reach cloud storage, and in December LastPass confirmed that backups of customer vault data had been taken. The vaults contained encrypted username and password fields protected by each user's master password, and alongside them, in plain text, the URLs of the sites those credentials belonged to.

Why does the breach still matter years later?

Because stolen encrypted data does not expire. An attacker who holds a vault file can keep guessing the master password offline for as long as they like, with no rate limiting and no way for LastPass to intervene. Vaults protected by short or reused master passwords, or by accounts still on old low iteration counts, have continued to fall over time, and researchers have linked cryptocurrency thefts to credentials recovered from that data. Every one of those vaults is still out there, and nothing the company does now can change that.

Why were the URLs not encrypted?

That was the architecture at the time: LastPass encrypted the credential fields but left the site URLs in each record unencrypted. The consequence in a mass theft is severe, because it turns an undifferentiated pile of encrypted blobs into a sorted target list. An attacker can see which vaults contain cryptocurrency exchanges, banks or corporate systems and spend their offline cracking effort on those, rather than on a randomly chosen vault holding nothing of value.

I still use LastPass. What should I do?

Assume everything that was in your vault before December 2022 is compromised, and treat migration as the second step rather than the first. Change the passwords on financial accounts, email and anything holding cryptocurrency now, starting with email because it is the reset path to everything else, and turn on two-factor authentication where it is not already on. Then move to another manager and choose a new master password that has never been used anywhere, which our password generator will produce. Changing your master password alone does not help, because the attacker holds a copy of the old encrypted vault, not your live account.

Has LastPass been independently audited?

There is no published independent audit of the current architecture that we can point you to, which is why our provider record shows an empty audit list rather than a summary. The company has published bulletins describing improvements it has made, including higher default iteration counts and changes to what is encrypted. Those are the right changes. They are also the company's own account of its own security, which after a breach of this size is not sufficient evidence, and every competitor in this category publishes external audits.

How much does LastPass cost and is the free tier usable?

Premium is $36 for a year and Families is $48 for a year, and neither rises at renewal, so three years costs $108 and $144 respectively. The free tier syncs unlimited passwords but only within one device type, computers or phones, not both, which for most people ends its usefulness at the point they pick up a phone. At $36 a year Premium costs more than three times Bitwarden's paid tier, from a company with no published audit and a stolen vault archive in circulation.