The Breach
LastPass is a widely used password manager — a vault meant to store all of a person’s logins securely. In 2022, attackers pulled off a serious breach: they first compromised a LastPass employee, ultimately including that employee’s home computer, and used that access to reach LastPass’s systems and steal copies of customers’ vault data. The passwords inside the vaults were encrypted, but some account information and metadata (like website URLs saved in a vault) were not, and encrypted vaults can be attacked offline if a user’s master password is weak. That a company built to protect secrets had its customers’ vaults copied was deeply alarming.
The stakes became concrete when the stolen vaults were tied to real thefts.
The Crypto Thefts and Settlement
Security researchers linked the breach to a string of cryptocurrency thefts: victims who had stored crypto “seed phrases” (the master keys to a crypto wallet) in their LastPass vaults had their funds drained, with losses tied to the breach running into the tens and later hundreds of millions of dollars. Customers filed a class action, and LastPass agreed to a $24.5 million settlement. It provides tiered relief — a modest cash payment for class members, reimbursement of documented losses up to a cap, and much larger payments (up to hundreds of thousands of dollars) for verified stolen-cryptocurrency losses — with a claims deadline set in 2026.
The huge per-person caps for crypto losses reflect just how damaging this particular breach was for some users.
What Users Should Know
Never store cryptocurrency seed phrases or other master secrets in a password manager or anywhere online — keep them offline. Use a long, unique master password and turn on two-factor authentication for your password manager, and change important passwords if you were affected by a breach like this. Password managers are still far safer than reusing passwords, but this case shows even the vault itself can be a target.
Before You Act
Thinking About Filing a Claim?
Most plaintiff lawyers offer a free initial consultation and work on contingency, meaning no fee unless there is a recovery. LawsuitWatch is not a law firm: we publish explainers, and we do not provide legal advice, representation or referrals. Your state bar directory is the reliable place to find and verify a lawyer.
LastPass Breach Lawsuit: The $24 Million Settlement: Frequently Asked Questions
Answers to the most common questions about this case and your legal options.
What happened in the LastPass breach?
In 2022, attackers compromised a LastPass employee (including their home computer) and stole copies of customers' encrypted password vaults, along with some unencrypted account information and metadata. Encrypted vaults can still be attacked offline if the master password is weak.
How much is the LastPass settlement?
$24.5 million. It offers a modest cash payment, reimbursement of documented losses up to a cap, and much larger payments (up to hundreds of thousands of dollars) for verified stolen-cryptocurrency losses, with a claims deadline set in 2026.
How can I protect my password manager?
Never store crypto seed phrases or master secrets in it — keep those offline. Use a long, unique master password, enable two-factor authentication, and change important passwords if you were affected by a breach.
Legal Disclaimer
This article is general legal information, not legal advice, and does not create an attorney-client relationship. Case status, eligibility criteria, and any amounts described are as reported at the date shown and may change. Consult a licensed attorney in your jurisdiction about your own situation.