

It’s important to note that we do not have any indication that accounts were successfully accessed or that the LastPass service was otherwise compromised by an unauthorized party. “LastPass investigated recent reports of blocked login attempts and determined the activity is related to fairly common bot-related activity, in which a malicious or bad actor attempts to access user accounts (in this case, LastPass) using email addresses and passwords obtained from third-party breaches related to other unaffiliated services. You can read the full statement provided to Android Police below: Interestingly, LastPass’ owner, LogMeIn, says there’s no indication that its servers were hacked. According to the LastPass emails, these login attempts include correct passwords, but were blocked because of the unusual geographic location. The reports explain that LastPass informed users about blocked login attempts that originated from other parts of the world, often from Brazil. Reports were first spotted on the ‘Hacker News’ forum by AppleInsider(via Android Police). Although that may sound like a recipe for disaster, password managers allow people to use randomly generated passwords for all their accounts, meaning you only need to remember one really strong password for your password manager instead of hundreds of mediocre passwords (or worse, the same password reused).

LastPass, one of the more well-known and popular password managers available, is seeing several reports of attempted log-ins with users’ correct master passwords.įor those unfamiliar with LastPass or password managers in general, they typically require users to have a primary or master password that unlocks their password vault, which contains the passwords for all their other accounts.
