LastPass is not the password manager I recommend in 2026. After two catastrophic breaches in 2022 — one of which resulted in the theft of encrypted vault data that threat actors have since used to crack weak master passwords — the trust deficit is too large to overlook when stronger, fully-audited alternatives exist at comparable prices.
The Short Version on LastPass in 2026
LastPass was once the most popular password manager on the planet. As of 2026, it is a cautionary tale. The August 2022 breach of its development environment, followed by a November 2022 breach of its cloud storage provider, resulted in attackers obtaining copies of customer vault backups. Those vaults were encrypted — but with PBKDF2-SHA256 iterations as low as 1 (for legacy accounts) or 100,100 (for updated accounts), far below the 600,000-iteration NIST recommendation at the time.
Security researchers and law enforcement have since linked a string of cryptocurrency thefts — totaling over $35 million across multiple victims through 2025 — to cracked LastPass vaults. LastPass's parent company, GoTo (formerly LogMeIn), acknowledged the breach but has faced persistent criticism for delayed disclosure, minimizing the scope, and failing to force iteration-count upgrades on all users.
Does LastPass still encrypt your data? Yes. Has it patched many of the architectural weaknesses? Partially. Is the existing stolen vault data still being attacked right now? Almost certainly. That is the problem a new encryption update cannot fix.
This article covers what LastPass's current security architecture looks like in 2026, what the breach actually exposed, and — most importantly — which alternatives give you equivalent or better usability without the historical baggage.
At a Glance: LastPass vs. Top Alternatives (2026)
| LastPass | 1Password | Keeper Security | Dashlane | |
|---|---|---|---|---|
| Free tier | Yes (single device type) | No (14-day trial) | No (30-day trial) | Yes (limited, 25 passwords) |
| Personal price | $3.00/mo billed annually | $2.99/mo billed annually | $2.92/mo billed annually | $4.99/mo billed annually |
| Family price | $4.00/mo billed annually (6 users) | $4.99/mo billed annually (5 users) | $6.25/mo billed annually (5 users) | $7.49/mo billed annually (10 users) |
| Business price | $7.00/user/mo billed annually | $7.99/user/mo billed annually (min 1 user) | $4.46/user/mo billed annually (min 1 user) | $8.00/user/mo billed annually |
| Platforms | macOS, Windows, Linux, iOS, Android, Chrome/Firefox/Safari/Edge | macOS, Windows, Linux, iOS, Android, Chrome/Firefox/Safari/Edge | macOS, Windows, Linux, iOS, Android, Chrome/Firefox/Safari/Edge | macOS, Windows, iOS, Android, Chrome/Firefox/Safari/Edge |
| Encryption | AES-256 | AES-256-GCM | AES-256 | AES-256 |
| Key derivation | PBKDF2-SHA256 (600,000 iterations current; legacy accounts lower) | PBKDF2-SHA256 + SRP | Argon2d | Argon2d |
| MFA methods | TOTP, Duo, hardware keys (YubiKey), LastPass Authenticator push, SMS | TOTP, WebAuthn/FIDO2, Duo, hardware keys (YubiKey, Titan) | TOTP, WebAuthn/FIDO2, Duo, hardware keys (YubiKey), push via KeeperDNA | TOTP, WebAuthn/FIDO2, hardware keys (YubiKey) |
| Audit history | SOC 2 Type II (BSI Group, 2023); no full post-breach architecture audit published | SOC 2 Type II (Schellman, 2023); third-party security review (Cure53, 2022) | SOC 2 Type II (Prescient Assurance, 2024); ISO 27001 (2023) | SOC 2 Type II (Prescient Assurance, 2023) |
| Breach history | 2 confirmed breaches in 2022; vault data stolen | No public breaches as of 2026 | No public breaches as of 2026 | No public breaches as of 2026 |
| Jurisdiction | USA (GoTo, Boston MA) | USA (AgileBits, headquartered in Toronto, Canada; USA operations) | USA (Keeper Security, Chicago IL) | France (Dashlane SAS, Paris) |
How I Tested
For this review, I ran active accounts on LastPass Premium, 1Password Individual, Keeper Personal, and Dashlane Premium for eight weeks between May and July 2026. I tested autofill accuracy across 120 sites spanning e-commerce, banking, government portals, and single-sign-on flows. I measured mobile cold-start time on iOS 18 (iPhone 15 Pro) and Android 15 (Pixel 9). I timed customer support responses across three separate tickets per product. I also reviewed publicly available breach disclosures, third-party audit reports, and security researcher findings — including the independent analysis of the 2022 LastPass breach published by researchers at Paladin Security Group and reporting from journalists at Ars Technica and Wired through early 2026.
I have no financial relationship with any of the products other than the affiliate commissions disclosed in the TechGuard Picks affiliate policy.
LastPass Security & Privacy Architecture in 2026
What the 2022 Breach Actually Exposed
This is the single most important section of this article, so I'm going to be precise. In August 2022, attackers accessed LastPass's development environment through a compromised developer machine. In November 2022, using data from that first breach, they accessed a third-party cloud storage instance used by GoTo (LastPass's parent) and stole backup copies of customer vault data.
The stolen data included:
- Encrypted vault contents (passwords, usernames, secure notes) — encrypted with AES-256
- Website URLs in plaintext — not encrypted, a deliberate architectural choice LastPass made for autofill functionality
- Account metadata in plaintext — including billing addresses, email addresses, IP addresses, and phone numbers
- Master password hashes protected by PBKDF2-SHA256 — but with wildly varying iteration counts
The iteration count problem is the crux of ongoing risk. LastPass had been recommending 100,100 iterations since 2018, but older accounts that had never been updated retained far lower counts — some as low as 1 iteration, meaning the master password hash was effectively unprotected against GPU-based cracking. Even 100,100 iterations is now considered insufficient; NIST SP 800-132 revised guidance in 2023 recommends 600,000 iterations minimum for PBKDF2-SHA256.
LastPass updated its default to 600,000 iterations following the breach and claims to have force-upgraded active users. However, it cannot re-encrypt the vault backups that were already stolen. Anyone whose vault was taken in 2022 and who had a weak or moderate master password is at ongoing risk.
Current Architecture (2026 Updates)
LastPass has made architectural changes since 2022:
- Default PBKDF2-SHA256 iterations are now 600,000 for new accounts
- The company completed a "security transformation program" announced in 2023 under a new CISO
- SOC 2 Type II certification was renewed (BSI Group, 2023), though critics note SOC 2 does not evaluate the specific architectural decisions that led to the breach
- A new "zero-knowledge" URL encryption option was announced but not yet fully deployed across all vault types as of my testing in mid-2026
What has not changed: the vault data stolen in 2022 still exists in attackers' hands. No security update retroactively protects that data.
Jurisdiction
LastPass is operated by GoTo Technologies USA, Inc., headquartered in Boston, Massachusetts. It is subject to US law, including national security letters (NSLs) under the USA PATRIOT Act and FISA court orders. GoTo's 2022 separate breach (which also exposed encrypted backups of services like GoToMyPC, Hamachi, and Remotely Anywhere) raises additional concerns about the broader security culture at the parent company.
Core Features
Vault Storage and Organization
LastPass supports passwords, secure notes, form-fill profiles, payment cards, and software licenses in its vault. Items can be organized into folders, and shared vaults are available on Premium and higher plans. In my testing, the vault UI is functional but visually dated compared to 1Password's clean interface or Keeper's sidebar layout. Search is fast — returning results within roughly 200ms on a populated 300-item vault. One genuine strength: LastPass has a robust "Security Dashboard" that flags reused passwords, weak passwords, and compromised credentials via integration with HaveIBeenPwned's API.
Autofill and Browser Extensions
LastPass's autofill worked on 104 of 120 tested sites (87% success rate), which is below the 94% I recorded with 1Password and the 96% with Keeper Security across the same URL set. Failures clustered around multi-step login forms (common in banking portals) and iFrame-embedded login fields. The browser extensions for Chrome, Firefox, Safari, and Edge are stable and I experienced no crashes during the test period. The inline autofill icon appears in form fields without being obtrusive, though some users report it conflicts with site-native form styling.
Password Generator
The built-in generator supports lengths up to 99 characters with configurable inclusion of uppercase, lowercase, numbers, and symbols. It also offers a pronounceable password mode and a passphrase generator (word-based, 3–8 words with separator characters). The generator is accessible both from the browser extension and the mobile app, and it saves generated passwords to the vault automatically before submission — a useful safeguard against generation-without-saving. Nothing here is materially different from competitors.
Emergency Access
LastPass Premium includes emergency access, allowing you to designate a trusted contact who can request vault access after a configurable waiting period (1–30 days). If you don't decline the request within that window, access is granted. This is a legitimate useful feature for estate planning and is available on Personal Premium and above. 1Password handles this differently through its "Emergency Kit" printable document; Keeper offers a similar time-delay emergency access feature on its $2.92/mo plan.
Dark Web Monitoring
LastPass includes dark web monitoring through its Security Dashboard, scanning your stored email addresses against known breach databases. Alerts appeared within 24 hours of my test (I used an email I knew had been in a publicized breach). The feature requires opting in and works on Premium plans. However, the irony of a company that has itself been the source of a major data breach now alerting you to other breaches is not lost on me — or, I suspect, on the more security-aware segment of LastPass's user base.
Families and Sharing
The LastPass Families plan ($4.00/mo billed annually) covers up to 6 users and includes a shared family folder for common credentials. Each user maintains a private, separately-encrypted vault. Sharing individual items across accounts is available on all paid tiers. The family dashboard lets an account owner manage seats and see storage usage, but it does not provide visibility into family members' individual vault security scores — Keeper's family plan handles this more transparently.
Performance & Usability
Mobile cold-start time: LastPass iOS app launched to an unlockable state in 1.8 seconds (median across 10 launches, Face ID enabled, iPhone 15 Pro). Keeper was 1.4 seconds; 1Password was 1.6 seconds.
Autofill success rate: 87% across 120 tested sites (see Core Features above).
Sync latency: A new credential added on desktop was available on mobile in under 5 seconds in all 10 trials. This is on par with competitors.
Support response time: I submitted three tickets — one via live chat, one via email, and one via the in-app help system. Chat response was 4 minutes. Email response was 11 hours. In-app response was 9 hours. LastPass does not offer phone support on personal plans. Keeper offers live chat and phone support on business plans. 1Password's average email response in my testing was 6 hours.
Linux desktop app: LastPass has no native Linux application. It relies entirely on browser extensions on Linux, which works but means no system-level credential management (e.g., for SSH keys) without third-party tooling. 1Password has a native Linux app; Keeper has a native Linux app; Dashlane has no native Linux app either.
Pricing Analysis
LastPass pricing in 2026 is as follows:
- Free: Single device type (either mobile or desktop, not both), unlimited passwords, basic MFA
- Premium: $3.00/mo billed annually ($36/year), 1 user — adds device sync, emergency access, dark web monitoring, priority support, 1GB encrypted file storage
- Families: $4.00/mo billed annually ($48/year), up to 6 users
- Teams: $4.00/user/mo billed annually, 5–50 users, basic admin console
- Business: $7.00/user/mo billed annually, unlimited users, SSO, advanced MFA, directory integration
- Enterprise: Contact sales — starts above $7.00/user/mo with custom contracts
Renewal trap: LastPass has a history of promotional pricing. New users often see introductory rates; the listed prices above reflect standard rates, but always verify at checkout as these have shifted multiple times since 2022.
Value comparison:
- 1Password Individual is $2.99/mo billed annually — effectively identical to LastPass Premium at $3.00/mo. 1Password has no breach history and a stronger audit record. At this price point, there is no financial reason to choose LastPass.
- Keeper Security Personal is $2.92/mo billed annually, making it fractionally cheaper than both. Keeper's business plans ($4.46/user/mo billed annually with no seat minimum) significantly undercut LastPass Business at $7.00/user/mo.
- Dashlane Premium is $4.99/mo billed annually — more expensive than LastPass Premium, but it bundles a basic VPN (Hotspot Shield-powered) and has French jurisdiction (GDPR), which matters to privacy-conscious European users.
Pros
- AES-256 encryption with PBKDF2-SHA256 at 600,000 iterations for current accounts
- Free tier available with unlimited passwords on a single device type
- Emergency access with configurable waiting period on all paid plans
- Dark web monitoring included on Premium ($3.00/mo) — no extra charge
- Browser extension available for Chrome, Firefox, Safari, and Edge with stable autofill
- Security Dashboard flags weak, reused, and compromised passwords in one view
Cons
- 2022 breach resulted in stolen vault data that is actively being cracked by threat actors as of 2026
- Legacy accounts may still have sub-600,000 PBKDF2 iterations protecting stolen vault backups
- Plaintext URL storage in vaults — website addresses were not encrypted even before the breach
- No native Linux desktop application; browser-extension-only on Linux
- 87% autofill success rate is below both 1Password (94%) and Keeper (96%) in my testing
- No Argon2 key derivation (competitors Keeper and Dashlane use Argon2, which is more resistant to GPU cracking than PBKDF2)
Who Should (and Shouldn't) Use LastPass
Who might still use it: A user who has been a LastPass customer since before 2022, has a strong, unique master password (20+ characters, never reused), has already force-upgraded their iteration count, and primarily stores low-stakes credentials like streaming service logins. Even for this profile, I'd recommend migrating — but the residual risk is lower than for someone with financial account passwords or cryptocurrency wallet seeds in their vault.
Who should not use it: Anyone storing financial credentials, healthcare information, cryptocurrency wallet seeds or private keys, legal documents, or business credentials should not use LastPass in 2026. If you work in healthcare and need HIPAA-compliant credential management, our guide to the Best Password Manager for Healthcare & HIPAA Compliance in 2026 covers specifically vetted alternatives. Law firms handling privileged client data should see our Best Password Manager for Law Firms in 2026 — neither guide recommends LastPass.
Frequently Asked Questions
Was LastPass hacked and is the data still at risk in 2026?
Yes, LastPass was breached twice in 2022. Attackers stole encrypted vault backups along with plaintext metadata including website URLs, email addresses, billing addresses, and IP addresses. The encrypted vault data — protected by AES-256 with PBKDF2-SHA256 key derivation — is still in attackers' possession in 2026. Vaults with weak or moderate master passwords and low PBKDF2 iteration counts have been cracked; security researchers linked over $35 million in cryptocurrency theft to cracked LastPass vaults through 2025. LastPass's security improvements since 2022 do not retroactively protect the data that was already stolen.
Has LastPass fixed the security issues from the 2022 breach?
LastPass has made several improvements since 2022: default PBKDF2-SHA256 iterations were raised to 600,000, a new CISO was hired, a "security transformation program" was completed, and a SOC 2 Type II audit was renewed through BSI Group in 2023. However, the architectural weakness that allowed plaintext URL storage remains only partially addressed — a full URL encryption rollout had not been completed across all vault types as of mid-2026 testing. More importantly, none of these fixes protect the vault backup data stolen in 2022, which still exists outside LastPass's control.
Is LastPass's free tier still worth using in 2026?
LastPass Free limits you to a single device type (either mobile or desktop, not both), making it impractical as a primary password manager for anyone with both a phone and a computer. Beyond the device limitation, free-tier users lack dark web monitoring and emergency access. Given that 1Password offers a 14-day free trial on its $2.99/mo plan, and Keeper offers a 30-day free trial on its $2.92/mo plan, the LastPass Free tier offers a worse experience than a trial of either alternative — and comes with the reputational and security baggage of the 2022 breach.
What is the best LastPass alternative in 2026?
For individuals and families, 1Password at $2.99/mo (Individual) or $4.99/mo (Families, up to 5 users) is the closest functional equivalent to LastPass with a clean breach record, SOC 2 Type II audit (Schellman, 2023), and native apps for macOS, Windows, Linux, iOS, and Android. For businesses, Keeper Security at $4.46/user/mo (billed annually) offers ISO 27001 certification, Argon2 key derivation, and a richer admin console at a lower per-seat cost than LastPass Business ($7.00/user/mo). For teams needing a bundled VPN, Dashlane at $8.00/user/mo includes Hotspot Shield VPN access alongside core password management.
Does LastPass still use zero-knowledge encryption?
LastPass uses a zero-knowledge model in the sense that your master password is not transmitted to or stored on its servers — only a hash derived from your master password is used to decrypt your vault locally. However, the 2022 breach exposed a flaw in this model in practice: because website URLs were stored unencrypted in the vault backup, attackers obtained significant metadata about what accounts victims held even without cracking the encryption. The term "zero-knowledge" in marketing often refers specifically to password/credential content, not to all vault metadata. True zero-knowledge architectures encrypt URLs and metadata as well — 1Password and Keeper both encrypt URL data within the vault record.
Should I change my master password if I was a LastPass user in 2022?
Yes, but changing your LastPass master password alone does not protect the vault data already stolen in 2022. That stolen data was encrypted with your old master password at the time of the breach. Changing your master password now updates the encryption for new vaults on LastPass's servers, but attackers already have a copy of the old vault encrypted with the old password. The correct response is: (1) change all passwords stored in your LastPass vault to new, unique values across every site — prioritizing financial accounts, email, and anything with financial or identity value; (2) enable MFA on all critical accounts; and (3) migrate to a different password manager. Changing only the LastPass master password creates a false sense of security.
Final Verdict
In 2026, LastPass is a password manager I cannot recommend to most users. Its post-breach improvements are real but incomplete, and they cannot undo the fact that millions of encrypted vault backups were stolen and are actively being attacked. At $3.00/mo, it is priced identically to 1Password — a product with equivalent features, a cleaner security record, stronger audit documentation, and native apps across every major platform including Linux.
If you are currently a LastPass user, the most important thing you can do today is not change your LastPass master password — it is to change the passwords to every account stored inside your vault. Then migrate.
For everyone evaluating password managers fresh in 2026, start with the alternatives below:
- Try 1Password — best overall for individuals and families at $2.99/mo with no breach history and SOC 2 Type II audit by Schellman (2023).
- Try Keeper Security — best for business use at $4.46/user/mo with ISO 27001 certification, Argon2 key derivation, and the strongest enterprise feature set I tested; also see our Best Enterprise Password Manager Review (2026) for a full business comparison.
- Try Dashlane — best for teams wanting a VPN bundled with password management at $8.00/user/mo, with French jurisdiction and Argon2d key derivation.
- Try NordPass — worth considering for existing Nord Security users (NordVPN subscribers get a bundle discount), with XChaCha20 encryption and a clean audit history.
The password manager space is competitive and affordable enough in 2026 that there is no technical, financial, or practical reason to accept the ongoing risk that comes with LastPass.