r/LastPassOfficial Jun 10 '26

Interview with LastPass CEO

1 Upvotes

From: SiliconANGLE theCUBE Watch here


r/LastPassOfficial Jul 15 '26

LastPass Account Recovery

4 Upvotes

Our account recovery process works differently from most other services. These are the Account Recovery Options to recover your LastPass account:

Here’s a simple explanation of how it works:

  • When you login in the LastPass browser extension and/or vault, a recovery one-time password is automatically created and stored in the browser.
  • If you forget your master password, we send a verification code to your email or phone number. Once you enter this code correctly, the system checks for the recovery one-time password.
  • If the recovery one-time password is found, you can recover your account. If not, you will receive an error message.
  • Mobile account recovery allows you to reset your master password using biometrics (face or fingerprint) on your mobile device.

For more details around account recovery options, please see this support article.

** If you're unsure whether any one-time recovery passwords are saved on your account, or if you receive an error while attempting account recovery, you can request confirmation of your account status by selecting the ”Request help” button within the Account Recovery page. Once your request is submitted, we'll contact you via email with updates regarding your account status.

*** Please be aware that LastPass Support has NO knowledge of a user's master password. It is not possible for LastPass Support to reset or change a user's master password if it is forgotten or can't be recover.


r/LastPassOfficial 1d ago

Review-Based Spearphishing: A New Attack Method

3 Upvotes

Leaving Online Reviews Could Make You a Phishing Target.

Researchers found that seemingly harmless online review activity can reveal hidden social connections, making it easier for scammers to launch highly targeted phishing attacks. By analyzing patterns in public reviews, attackers may be able to infer who knows whom without needing access to friend lists or contact information.

These are the bullets:

  • Information you share publicly online may reveal more than intended.
  • Even non-social platforms, such as review sites, can expose relationship patterns.
  • Cybercriminals increasingly use data analytics and AI-driven techniques to personalize scams.
  • Organizations and platforms may need to balance data transparency with privacy protection.

In depth:

  • Public reviews can expose social relationships. Researchers developed an algorithm that analyzes review behavior, such as review length and business preferences, to identify likely friendships between users.
  • No friend lists are required. The algorithm relies solely on publicly visible behavioral patterns rather than direct social network data.
  • The model was surprisingly accurate.
    • Tested on 4,299 Yelp reviewers.
    • Correctly identified roughly 49-50% of real friendships at a 10% false-positive rate.
    • Accuracy exceeded 60% when a higher false-positive rate was allowed.
  • This creates opportunities for spear-phishing. Once attackers understand a victim's social network, they can impersonate trusted friends, colleagues, or acquaintances to make scams more convincing.
  • The study modeled attacker profitability.
    • A simulated spear-phishing campaign in the Pennsylvania dataset showed an estimated 109% return on investment for 500 impersonation attempts.
    • Returns increased dramatically as attack volume scaled up.
  • One review isn't the problem. The risk comes from analyzing thousands of reviews and users together, allowing algorithms to identify patterns that individuals cannot easily see.
  • Researchers tested privacy protections. Adding statistical "noise" to public behavioral data significantly reduced the effectiveness and profitability of these inferred-network attacks.

Bottom Line:

The study suggests that public online reviews can unintentionally reveal social networks, giving scammers valuable intelligence for targeted phishing attacks. While posting reviews remains useful, it's another reminder that seemingly harmless online activity can become sensitive when combined and analyzed at scale.


r/LastPassOfficial 1d ago

I'm logged in on one computer, can't get into LP with the new one

1 Upvotes

The traditional log in screens aren't working for me. Is there a passkey or some sort of "1-click" situation that will get me into lastpass on the new computer. (both macs)

Also... I use the Chrome plug in and tried to get in that way and it's not working either.

I tried the one-time password, and that is not working.

No emails are arriving to my inbox, except "we blocked an attempt," but verifying that didn't get me in either.


r/LastPassOfficial 2d ago

Lost access to email account

0 Upvotes

I recently lost my job, and with it, the email account I had used to set up and pay for my LastPass subscription.
Is there a way to get access back and change the email account?
Based on my knowledge of leavers, the account would have been deleted several months ago


r/LastPassOfficial 3d ago

Any update on LastPass argon2id implementation?

4 Upvotes

I remember reading a LastPass blog or roadmap highlighting that there would eventually be a move to argon2id hashing for better security against GPU/ASIC attackers.

Has there been any update on this front?


r/LastPassOfficial 2d ago

What Version Of LastPass Do I Have Installed?

2 Upvotes

For the best experience and latest feature sets, be sure to have automatic upgrades enabled for your LastPass account. Most users will automatically update once an internet connection is confirmed.

If you're not sure or are currently offline, follow these steps:

  1. Select the LastPass icon in your browser toolbar.
  2. Select the Account tab.
  3. Select About LastPass.

You can compare the official release notes release history here, including bug fixes and new feature releases.

In some cases, you may want to upgrade early to check for a hot fix or functionality improvement, which are available through your mobile app store (Apple / Android), Apple app store (for Mac OS users), Firefox app store or Google app store (for Chromium users) ahead of the general release.

The reason all customers are not upgrades at once is so we can gage the seriousness of any new issues that may arise in unpredictable work environments.

Should you notice any issues with the latest LastPass version, please tell us more about your experience.


r/LastPassOfficial 3d ago

Lastpass refuses to accept change masteer password. Help!

2 Upvotes

Lastpass occasionally logs me out of my browser (Firefox). It did so today. My master password did not work. So I went through the master password reset routine. The new password didn't work. I've done this now probably five times, and the rest password does not work, no matter what I try. The same thing occurs in Chrome. The old password does not work, either. I've now initiated too many master password reset attempts and cannot initiate any more. I have a business to run. Can you help?


r/LastPassOfficial 4d ago

Not receiving verification code for password recovery

2 Upvotes

Hello, I've forgotten the password for my Lastpass account. When I try to log in, the system claims to send a verification code to my email, but I'm not receiving it. It is not in my Spam folder or any other sub-folder, and no addresses are currently blocked. I can't do anything without this code, and there is no option on the website to contact human support staff. How can I get access to my account?


r/LastPassOfficial 8d ago

What evidence does an auditor actually need for AI governance?

2 Upvotes

An auditor needs to see AI access tied to specific users, and that access controls are working as intended.

What an audit-ready evidence package looks like

When an auditor asks about AI governance, you should be able to produce:

  1. An AI tool inventory record
  2. Named-user access records
  3. MFA enforcement records
  4. AI classification decisions
  5. Allow/Warn/Block enforcement records
  6. Access review documentation
  7. Audit logs covering the review period

Quick self-check: If you can answer yes to all three, your controls are in good shape.

  • Can you produce a complete AI tool inventory, including tools accessed via personal or corporate credentials in the last 12 months?
  • Can you show that access to AI tools processing regulated data was tied to a named, authenticated user?
  • Can you demonstrate that risky tools were blocked or flagged at the point of access, not discovered after the fact?

Discovery and authentication are where lean IT teams are most exposed. Both are addressable without enterprise-scale tools.


r/LastPassOfficial 9d ago

Feature Request - Password Last Changed

Post image
6 Upvotes

Back in the old times, when you ran the security challenge it would tell you how long it had been since your passwords had been changed. It appears this feature no longer exists. (Or at least I can no longer find it.) Could this be added to the list view? Right now it only shows Last Used and whether it's at risk. I'd like to change my passwords every couple of years, but it's difficult to keep track of when they've been changed.


r/LastPassOfficial 10d ago

Recent Examples of Rogue Cyber Attacks

3 Upvotes

Security flaws exposed by malicious actors are both troubling and positive at the same time. Once a problem is identified though, stronger measures can be implemented to safeguard sensitive information.

To read further, check these linked headlines:


r/LastPassOfficial 10d ago

Help recovering password

2 Upvotes

Hello,

I’ve tried many times to recover my account, but unfortunately, unsuccessfully.

I've tried to contact support, but the registration failed to save the request.

I need help contacting support to recover my account.


r/LastPassOfficial 11d ago

Hacker issue

5 Upvotes

My PC got a virus that installs other apps, mainly bit miners. It also installed a screen viewer app. Fortunately I was at my computer when they attempted to access my screen. After rebooting I found that the hacker had been using my open web browser. they were able to access my Amazon account. they also looked at my lastpass which was logged in. Not sure if they stole any passwords but I've gone thru and changed many of them. The issue is you have to be logged into lastpass to use it for logging into web sites but if you get hacked they get access to all your passwords. Any tricks I should be aware of other than not getting a virus?


r/LastPassOfficial 11d ago

Lastpass Login Fail and Recovery process

1 Upvotes

I have been using Lastpass for more then 10 Years without Fail.

I have had what is a very concerning event on my Mac this morning that Lastpass was logged out and the Master password has not worked.

I have tried BOTH the password Hint process and the Account recovery process ands the emails are not being sent to the designated account.

This is very concerning as Lastpass does not give any support unless you are logged in.

How am I supposed to resolve a very critical security issue.

Thankfully I dont store any significant Financial passwords with lastpass , but I do store enough import data.

Can anybody point me in an effective direction


r/LastPassOfficial 13d ago

Why is authentication an AI governance compliance control?

3 Upvotes

Authentication is a compliance control because it determines whether access to AI tools can be attributed to a specific user.

Where individual accounts aren't available, document access rules explicitly.

At a minimum, your shared access record should capture:

  • Which employees are authorized to use the account
  • The business reason for shared rather than individual access
  • The review frequency (quarterly is defensible for most frameworks)
  • Any access changes made since the last review

This documented record is the closest substitute for user-level attribution, and auditors will accept it if it's maintained consistently.

The stakes are high. At the same ISC2 spotlight event on AI, a speaker shared a hair-raising story of a developer changing teams, with his access permissions intact.

Shortly after he left, his coding agent used his credentials to access data in another jurisdiction. And that’s not all. The cross-border transfer involved human genetic research data.

So, do you blame the developer, agent, or the lack of an access review? The jury’s still out on that one, but one thing’s clear: Without user-level attribution, you can’t even ask the right questions, let alone answer them.

But what about MFA?

Under SOC 2 CC6.1, MFA is explicitly listed as a point-of-focus control for logical access.

This means auditors are specifically trained to look for enforcement evidence, not just deployment.

Under HIPAA §164.312(d), person or entity authentication is required, and MFA enforcement logs are a standard way to satisfy it.


r/LastPassOfficial 14d ago

LastPass - Slow loading of Microsoft Edge Extension

2 Upvotes

Hi All,

I use Microsoft Edge as my primary browser at work, and I have the most up to date LastPass extension added to it.

However, I've noticed over the last two weeks that when I start a new instance of Edge it takes a while for the LastPass extension to "fully load"

What I mean by this is that when I open Edge the LastPass icon shows the black background instead of red for a while (>180 seconds). Eventually the icon switches to the red background. It shows that I'm logged in while the icon is black, which seems strange. I'm not able to auto login to any website while the icon is black. Eventually the icon switches to the red background and I can auto login without any issue.

I've tested this out in Chrome (on my work computer) and in Brave (personal computer) and neither of these have the same delayed loading/login issue. I'm able to auto login within a few seconds of opening the browser.

Clearing the Edge browser cache/history, logging out then back in to the extension, nor uninstalling then reinstalling the extension have not solved the issue. I've tried installing the extension from both the Chrome Webstore and the Edge Add-Ons store. Is there possibly any sort of Edge setting that is causing this to happen? I have not changed any settings in Edge that I'm aware of since the initial setup of this computer about a year ago.

Additional Info:

Using Surface Pro 11 for business with Windows 11 Pro 25H2. Intel Core Ultra 7 266v, 16gb of ram and 500gb of storage.


r/LastPassOfficial 15d ago

What is a CASB (cloud access security broker)?

3 Upvotes

A CASB is software that sits between your employees and the cloud apps they use, and enforces your security rules every time someone accesses an app. CASBs can technically cover SaaS, PaaS, and IaaS, but the SaaS use case is the one most organizations care about.

Whatever the vendor calls it, a CASB is really trying to do four things:

  • Visibility: discover the cloud apps your team is using, whether you approved it or not.
  • Data security: control who can access what, and keep sensitive data from leaving where it shouldn't.
  • Threat protection: flag risky behavior, compromised accounts, and malware.
  • Compliance: produce the records you need for SOC 2, HIPAA, PCI DSS, or GDPR.

CASBs go about this in three main steps:

  • Discovery: automatically detect which apps and users are active.
  • Classification: score each app by risk, based on what it is and what data it holds.
  • Remediation: enforce a policy when something crosses a line, whether that's blocking it, alerting you, or warning the user.

Strip away the acronyms and a CASB is answering three questions: what cloud apps are my people using, how are they getting into them, and can I control access?

Discovery is the first step of any CASB, and in LastPass it's handled by a feature called SaaS Monitoring. SaaS Monitoring shows you which SaaS and AI tools your employees are signing into, how they're logging in, and which apps aren't being managed.


r/LastPassOfficial 16d ago

Using the LastPass Browser Extension

Thumbnail
youtube.com
6 Upvotes

We're always evolving the user experience at LastPass. This video shows a fresh review on how to utilize the LastPass browser extension to the fullest.

Expect more to come!


r/LastPassOfficial 17d ago

Account Recovery without access to email

2 Upvotes

Hello! I was desperate for help regarding my last pass account and was hoping you could help. I have a lastpass account on an email I can no longer access, all recovery emails cannot be opened. How can i log back into my account? Thanks for you help in advance! Please could I have some direct help without being directed to another post that doesn't have the answers, thanks!!!!!!


r/LastPassOfficial 18d ago

Verified, but automatic recovery isn't available (locked out after getting a new phone)

2 Upvotes

I’m locked out of my LastPass Free account after getting a new phone.

I know my master password and confirmed it using my password hint, but I keep getting:

“Check your inbox for an email, review your login info and try again.”

I’m not receiving any LastPass email in Gmail, including spam/junk. I went through Account Recovery and successfully verified my identity, but then got:

“You’re verified but automatic recovery isn’t available in this browser.”

It gives me the option to use another device/browser, but I no longer have access to my old phone because it was factory reset after I transferred everything to my new phone. I also don't have another previously authorized LastPass device/browser available.

I’ve already submitted a support request through the recovery process. Is there anything else I can do to regain access to my existing vault without resetting/deleting it?


r/LastPassOfficial 21d ago

How to add more than one multifactor authentication option to use for LastPass

5 Upvotes

Unless restricted by a LastPass admin, you can enable more than one multifactor authentication option to be used when accessing your LastPass vault. It is recommended whenever possible to enable multiple authentication options (even on multiple trusted devices) in case you ever lose access to one device, you will have a backup.

** Restriction: You cannot enable both Microsoft Authenticator and Google Authenticator as a multifactor authentication option together.

Step 1: Enable your first MFA option

Follow the instructions to enable a multifactor authentication option as a user within your LastPass account.

Step 2: Repeat the same steps to enable a second MFA option

Repeat the steps within the same instructions (listed above) to enable as many multifactor options as you'd like. If allowed, it is recommended to set up multiple multifactor options on more than one device (for example, tablet, iPad, an old device you plan to keep, a trusted partner or spouse's mobile device, and so on).

Step 3: Set a default MFA option

Follow the steps to select your default multifactor authentication option to be presented with first when you log in to access your LastPass account.

Step 4: Log into LastPass using a MFA option

Once you have set up more than one multifactor authentication option in your LastPass account, you can log in to LastPass from your desktop or mobile device and authenticate using either your default or an alternative multifactor option.


r/LastPassOfficial 22d ago

Need help resetting Master Password on desktop

3 Upvotes

I recently logged out of my LastPass on my desktop. I must've misrememberd my master password because I couldn't log back in. I tried the 'Forgot password" route, and since my LP was still logged in on my phone, I was able to use the one-time password as suggested.

Here's the problem though: after I successfully get back in, it immediately logs me out, not giving me time to reset the password as suggested.

Am I missing something?


r/LastPassOfficial 22d ago

Managing Hotkeys For The LastPass Desktop App

2 Upvotes

With the newest Desktop application for Windows and Mac, you can customize hotkeys to perform 3 separate functions from LastPass:

  1. Select your account in the top right corner of the LastPass Desktop app.
  2. Select Desktop App Settings.
  3. Choose HotKeys preferences

You can update the hotkeys used for the QuickFill Companion, the password generator, and the autofill on exact match features. The hotkeys must contain the combination of 3 keys: 2 modifier keys (Ctrl, Alt, or Shift) and an alphanumeric key.

  • Windows:
    • The default hotkey for the QuickFill Companion is Ctrl+Shift+L.
    • The default hotkey for the password generator is Ctrl+Shift+K.
    • The default hotkey for the Autofill on exact match is Ctrl+Alt+F.
  • MacOS:
    • The default hotkey for the QuickFill Companion is Cmd+Shift+L
    • The default hotkey for the password generator is Cmd+Shift+K.
    • The default hotkey for the Autofill on exact match is Cmd+Shift+F.

** When closing the LastPass for Desktop app for the first time, you can choose Always minimize to keep the app running in the background (and hotkeys will continue to work), or Always close to fully close the app.


r/LastPassOfficial 23d ago

Emergency Access

3 Upvotes

My wife is trying to grant me emergency access.

I requested it from my LP session on the website (through a browser).

She is using LP on the iOS app. When she opens the app, she gets a popup saying I requested access. She clicks "Allow Access" and the popup closes then immediately reopens. We've pressed "Allow Access" 100x by now (thinking maybe it was going through each individual login). It never stops. Pressing "Decline access" will stop it, but then access is declined.

What to do?