LastPass
LastPass is a password manager that stores encrypted user credentials and provides autofill across devices. Owned by private equity firms Francisco Partners and Elliott Management, the service suffered a catastrophic 2022 breach that compromised encrypted vault data for approximately 33 million users.
Score generated by AI agents based on publicly cited evidence and reviewed by the project maintainer. Not independently validated. Last assessed 2026-09-27. Score revised 2026-09-27: 56 → 44.
Score History
Timeline events are AI-curated from public reporting. Score trajectory is derived from documented events.
LastPass was founded in 2008 as an independent password manager with a free browser-based vault and a low-cost Premium tier. It took over the Xmarks bookmark-sync service in 2010 to keep it running. Breaches in 2011 and 2015 were disclosed publicly and handled with precautionary resets; the 2015 intrusion exposed email addresses, password reminders and authentication hashes but not vaults.
LogMeIn bought LastPass for $110 million in October 2015, folding it into a publicly traded SaaS company over user protests. The first years under LogMeIn were generous: in November 2016 multi-device sync became free for all users. Browser-extension flaws found by outside researchers in 2016 and March 2017 were patched quickly, and Premium stayed at $12 a year.
In August 2017 LastPass doubled Premium to $24 a year and moved emergency access and unlimited sharing behind the paywall; by February 2019 Premium cost $36, triple its 2017 price. LogMeIn shut down Xmarks in May 2018. Francisco Partners and Elliott Management agreed in December 2019 to take LogMeIn private for $4.3 billion and closed the deal in August 2020, putting LastPass under private-equity control.
In February 2021 LastPass announced that from March 16 free users would be limited to either computers or mobile devices, reversing its 2016 free multi-device sync; free users lost email support later that year. In June 2021 Enterprise was replaced by Business, with Advanced SSO and MFA moved into paid add-ons. GoTo (formerly LogMeIn) announced a LastPass spinoff in December 2021, and Karim Toubba became CEO in April 2022.
LastPass disclosed an intrusion into its development environment on August 25, 2022, saying no customer data was taken; in December it revealed that attackers had used the stolen information to copy customer vault backups holding encrypted credentials alongside unencrypted URLs and account data. Researchers called the disclosures misleading and showed older accounts had weak PBKDF2 settings. Crypto thefts traced to cracked vaults followed, employees reported layoffs, and LastPass began enforcing 12-character master passwords in January 2024.
LastPass completed its spinoff from GoTo in May 2024, becoming a standalone company still owned by Francisco Partners and Elliott Management. The era combines remediation and new products (URL encryption, passkeys, SaaS Protect, Secure Access Essentials) with the breach's legal and financial fallout: federal investigators linking a $150 million crypto theft to it, a £1.23 million ICO fine, a US$3 million Canadian settlement and a $24.5 million U.S. settlement awaiting final approval. A June 2026 breach at partner Klue exposed customer contact and support data, while pricing and the one-device-type free tier stayed unchanged.
Alternatives
Open-source password manager, far less enshittified than LastPass. Free tier includes unlimited passwords across unlimited devices (no device type restriction), the opposite of what LastPass took away in 2021. Never had a breach remotely comparable to LastPass's 2022 catastrophe. Easy switch — Bitwarden has a direct import tool for LastPass CSV exports. The free tier is genuinely free, not a crippled upsell funnel.
Premium password manager, far less enshittified than LastPass, with a strong security track record and no history of catastrophic breaches. No free tier (individual plan $3.99/month since March 2026), but the polished apps, Travel Mode, and Watchtower breach monitoring make it the top choice for users willing to pay. Easy switch — 1Password offers a direct LastPass import guide. Better option if you want the polish of a premium product without the PE ownership baggage.
Dimensional Breakdown
Summaries below were written by AI agents based on the cited evidence. They are editorial interpretations, not independent research findings.
Dimension History
Timeline (50 events)
First security breach detected at LastPass
LastPass reported detecting unusual network traffic from a database, indicating a possible intrusion. The company required all users to reset their master passwords as a precaution, though no evidence of vault data exfiltration was confirmed. This was the first of seven publicly known security incidents.
Second breach exposes email addresses and authentication hashes
LastPass discovered suspicious activity on their network and confirmed that account email addresses, password reminders, server per-user salts, and authentication hashes were compromised. Encrypted vault data was reportedly not taken, but the stolen password reminders could help attackers target individual users. All users were required to change master passwords. The breach raised questions about whether the small bootstrapped company had sufficient resources for enterprise-grade security.
LogMeIn acquires LastPass for $110 million
LogMeIn, a publicly traded SaaS company, acquired LastPass for $110 million in cash with an additional $15 million contingent on milestone targets. At the time, LastPass had 7 million users and 15,000 business customers. Founder Joe Siegrist's blog was flooded with criticism from users concerned about LogMeIn's reputation for aggressive price increases.
Researchers find two password-stealing LastPass extension flaws
Google Project Zero's Tavis Ormandy found a design flaw in the LastPass Firefox add-on that let a malicious website take over the extension and steal all passwords, and Detectify's Mathias Karlsson disclosed an autofill URL-parsing bug that leaked credentials for other sites. LastPass patched Ormandy's flaw within hours and Karlsson's within a day, paying a $1,000 bug bounty, though Karlsson said he had reported his more than a year before disclosure.
Multi-device sync made free for all users
LastPass announced that free users could now sync passwords across all device types, a feature previously locked behind the $12/year Premium plan. This represented LastPass's peak generosity to free users, making it one of the most capable free password managers available. By deepening user investment across all devices, it also increased switching costs. The feature would be reversed in March 2021.
Browser extension vulnerabilities expose user credentials
Google Project Zero researcher Tavis Ormandy found flaws in the LastPass Chrome and Firefox extensions that could let malicious websites steal users' passwords or, where the LastPass binary component was installed, load and run malware on their computers. Help Net Security called LastPass's first Chrome fix 'slapdash and incomplete' and advised users to disable the extension until both versions were fixed.
Premium price doubled, free tier features removed
LastPass doubled Premium pricing from $12/year to $24/year while removing emergency access and unlimited sharing from the free tier and moving them behind the paywall (free users already using emergency access kept it). The Families plan launched alongside at $48/year for six users. This marked the first clear sign of LogMeIn applying its aggressive pricing playbook to LastPass.
LogMeIn shuts down Xmarks bookmark sync service
LogMeIn discontinued the Xmarks bookmark-syncing service that LastPass had acquired in 2010, shutting it down on May 1, 2018 so it could 'focus on offering the best possible password vaulting'. LastPass had rescued Xmarks in 2010 after its creators planned to shut the service down, and its FAQ on the 2015 LogMeIn acquisition had told users 'We will continue to support Xmarks.' Xmarks users lost cross-browser bookmark synchronization; any remaining Xmarks balance was credited toward LastPass Premium.
Premium price tripled to $36/year in two years
LastPass increased Premium pricing from $24/year to $36/year ($3/month), completing a 200% price increase over just two years under LogMeIn ownership. Critics noted that no significant new features accompanied the increase. Bruceb Consulting wrote that LastPass had 'learned the wrong lessons about price increases from LogMeIn.'
Google Project Zero finds credential-leaking browser extension bug
Google Project Zero researcher Tavis Ormandy discovered a vulnerability in the LastPass browser extension that allowed malicious websites to steal credentials from the previously visited site. The flaw exploited how the extension generated pop-up windows via HTML iframes rather than through the expected do_popupregister() function. LastPass patched the Chrome and Opera extensions before public disclosure, but the vulnerability underscored ongoing security architecture weaknesses in the browser extension.
Francisco Partners and Elliott announce $4.3B LogMeIn buyout
Francisco Partners and Evergreen Coast Capital (Elliott Management's PE affiliate) announced a $4.3 billion acquisition of LogMeIn at $86.05 per share, taking it private. The deal, completed August 31, 2020, placed LastPass under private equity control with PE firms whose playbook centers on cost-cutting and value extraction from portfolio companies.
PE acquisition of LogMeIn closes at $4.3 billion
Francisco Partners and Evergreen Coast Capital (Elliott Management's affiliate) completed the $4.3 billion acquisition of LogMeIn, taking it private at $86.05 per share. LogMeIn's stock was delisted from NASDAQ. The deal placed LastPass under private equity control, concentrating governance with financial sponsors whose obligations run to limited partners rather than users. The privatization reduced public transparency requirements including SEC reporting obligations.
Free tier restricted to single device type
LastPass announced that starting March 16, 2021, free users would be limited to either computers or mobile devices, but not both. This reversed the 2016 decision to make multi-device sync free. The restriction effectively made the free tier unusable for most people, as modern password management requires cross-device access. Users had only three opportunities to switch their device type.
1Password says family signups doubled after LastPass restricted free tier
Competitors picked up users after LastPass announced its free-tier restriction. 1Password CEO Jeff Shiner said signups for paid 1Password family accounts doubled when LastPass restricted its free tier, and 1Password said it 'never made sense' to offer its product at no cost, pitching itself as 'up front with our billing'.
Free tier device restriction takes effect
The single device type restriction officially took effect on March 16, 2021. Free users' first login set their active device type permanently, with only three chances to switch. The restriction trapped existing free users into choosing between desktop and mobile access, creating pressure to upgrade to Premium or switch to competitors like Bitwarden that maintained free multi-device sync.
Email support removed for free tier users
LastPass removed email support for free users, limiting them to self-help resources and community forums. Free users were allowed to continue receiving technical support through August 23, 2021, to help with the device type transition. Premium and Families customers retained full email support access.
LastPass Enterprise replaced by Business plan with paid SSO and MFA add-ons
LastPass replaced its Enterprise plan with LastPass Business at $6/user/month, moving Advanced SSO ($2/user/month) and Advanced MFA ($3/user/month) into paid add-ons, or a $9/user/month bundle. Existing Enterprise customers moved to Business at renewal, keeping their password-management features but with single sign-on limited to 3 cloud apps unless they bought the Advanced SSO add-on.
GoTo announces LastPass spinoff as independent company
GoTo (formerly LogMeIn) announced plans to spin LastPass off as a separate company, saying the move would let LastPass increase focus, investment and support for its business, which then counted 30 million users and 85,000 business customers. LastPass would remain under the same private equity owners, Francisco Partners and Elliott Management; the separation was not completed until May 2024.
Karim Toubba appointed as CEO
LastPass appointed Karim Toubba as CEO, replacing interim-CEO Mike Kohlsdorf. Toubba, a cybersecurity veteran from Cisco/Kenna Security, was brought in to lead LastPass through its separation from GoTo. He would face the breach crisis within months of taking office.
First breach disclosure: developer environment compromised
LastPass disclosed that an unauthorized party accessed portions of its development environment through a compromised developer account, stealing source code and proprietary technical information. CEO Toubba's blog post stated the breach was contained and that no customer data or vault contents were accessed. This initial disclosure drastically understated the severity of what had actually occurred.
First class action filed over 2022 data breach
Debt Cleanse Group Legal Services LLC, a LastPass business customer, filed a proposed class action against GoTo Technologies USA and LastPass US LP in the U.S. District Court for the District of Massachusetts (No. 1:22-cv-12047), over the breach first disclosed in August 2022, bringing claims for negligence, negligent misrepresentation, breach of contract and unjust enrichment. Its docket became the lead case of the consolidated In re LastPass Data Security Incident Litigation (1:22-cv-12047-PBS) before Judge Patti B. Saris.
Full breach severity revealed: customer vaults stolen
Four months after the initial disclosure, LastPass revealed that attackers had used information from the August incident to copy a backup of customer vault data containing unencrypted data such as website URLs alongside encrypted fields such as usernames and passwords, as well as customer names, billing addresses, email addresses, phone numbers and IP addresses. In February 2023 LastPass disclosed that the attacker had reached the storage keys by planting a keylogger on a senior DevOps engineer's home computer through a vulnerable third-party media software package (later identified as Plex, CVE-2020-5741).
Security experts blast LastPass for misleading breach communication
Security researcher Wladimir Palant published a detailed analysis calling LastPass's December 22 statement 'full of omissions, half-truths and outright lies.' Separately, researcher Jeremi Gosney (as reported by The Verge and SC Media) called LastPass's 'zero-knowledge' claim 'a bald-faced lie,' noting that the vault is a plaintext file with only select fields encrypted, and accused LastPass of committing 'every crypto 101 sin'.
PBKDF2 iteration weakness exposed across older accounts
Palant's analysis revealed that LastPass's PBKDF2 iteration count varied wildly across accounts: from 1 iteration for the oldest accounts, to 500 (2012), 5,000 (2013), and finally 100,100 for newer accounts. LastPass never forcibly upgraded older accounts' iteration counts, leaving long-term users with dangerously weak protection. At 100,100 iterations, LastPass was already the lowest among current password managers.
Enterprise admin details hurdles migrating off LastPass Enterprise after breach
As organizations weighed leaving LastPass after the breach, an administrator who had run LastPass at several companies, including in government, documented his move from LastPass Enterprise to Dashlane for Business, saying the migration 'isn't super simple'. Shared credentials had to be re-shared to groups by hand in the new tool's web app because the API documentation wasn't helpful.
Users report LastPass auto-renewing cancelled accounts
A Hacker News discussion ('LastPass will autorenew a cancelled account') centered on a user who received an auto-renewal notice four weeks after LastPass emailed that his account had been deleted and all his data purged. Another commenter said cancelling a LastPass business account had been 'basically impossible to do without calling them up on the phone' and that they switched billing to a generated card with a $1 limit before cancelling.
DevOps engineer Plex compromise details revealed
LastPass disclosed that the second breach specifically targeted one of only four DevOps engineers with access to the corporate vault. The attacker exploited CVE-2020-5741, a Plex vulnerability patched in May 2020, on the engineer's personal home computer. The employee had never updated Plex, leaving a version roughly 75 updates behind. The attacker installed a keylogger to capture the engineer's master password.
Post-breach layoffs reported at LastPass
Employees reported on Fishbowl that they were laid off from LastPass 'due to the result of their security incident,' with reports of many layoffs within the company. Glassdoor reviews from this period describe a 'sinking ship' atmosphere with constant restructuring and concern that leadership had no real strategy beyond cost-cutting.
One year post-breach: security expert says LastPass has not improved
Security researcher Wladimir Palant published a follow-up assessment concluding that one year after the catastrophic breach, LastPass had not meaningfully improved its security practices. Palant found that the same fundamental issues with the security architecture remained, and that LastPass's public statements continued to be misleading about the strength of its protections.
Researchers link $35 million in crypto heists to cracked LastPass vaults
Security researchers including MetaMask's Taylor Monahan concluded that a wave of cryptocurrency thefts hitting more than 150 people, totalling over $35 million, shared one common factor: the victims had stored seed phrases in LastPass. The findings, first reported by KrebsOnSecurity, suggested thieves were cracking master passwords for vaults stolen in 2022. LastPass declined to answer questions, citing law enforcement and pending litigation.
LastPass maintains $36/year pricing despite breach-driven trust deficit
Despite the 2022 breach and user exodus, LastPass kept Premium at $36/year ($3/month) and Families at $48/year ($4/month), while Business rose from $6 to $7/user/month. Unlimited SSO ('Advanced SSO') and passwordless 'Advanced MFA' remained separately priced per-user add-ons to the Business plan, as LastPass's own pricing page showed in March 2024, while Bitwarden's Premium plan cost $10/year at the time. The free tier stayed limited to one device type.
LastPass enforces 12-character master passwords for all accounts
LastPass began requiring every customer to use a master password of at least 12 characters. It had been the default since 2018 and enforced for new accounts and resets since April 2023, but older accounts could keep shorter passwords. LastPass also said it would check new or reset master passwords against a database of credentials leaked on the dark web, changes it tied to the 2022 breaches.
$150 million cryptocurrency heist linked to LastPass breach
On January 30, 2024, thieves stole about $150 million in cryptocurrency from a victim whom blockchain researcher ZachXBT identified as Ripple co-founder Chris Larsen. In a March 2025 seizure complaint covering about $24 million clawed back from the theft, federal prosecutors said the U.S. Secret Service and FBI believed the attackers used a password stored in the victim's online password manager account, linking the heist to the 2022 LastPass breach.
LastPass completes spinoff from GoTo as independent company
LastPass completed its separation from GoTo, becoming a standalone company headquartered in Boston with over 800 employees. Despite the independence branding, the company remains controlled by the same PE firms (Francisco Partners and Elliott Management) that took LogMeIn private in 2020. Business customers faced transition uncertainties as infrastructure and support structures were separated.
LastPass begins encrypting vault URLs after breach exposed them
LastPass announced a two-phase initiative to encrypt URLs stored in vaults, addressing one of the most criticized aspects of the 2022 breach: that website URLs had been stored unencrypted, revealing which services users had accounts with. Phase 1, completed by August 2024, encrypted primary URL fields. Phase 2, completed September 2025, extended encryption to URL rules, equivalent domains, and never-URL lists. The company cited advances in device processing power as enabling encryption that was previously too computationally expensive.
Fake Chrome Web Store reviews used to phish LastPass users
LastPass warned of a social engineering campaign in which attackers posted fake reviews on the LastPass Chrome Web Store page directing users to call a fraudulent support number. Callers were steered to a malicious site (dghelp[.]top) that, per BleepingComputer, downloaded a ConnectWise ScreenConnect remote-access agent. In a November 6, 2024 update LastPass said the scammers had begun posting the number using emojis and had changed the phone number.
FBI and Secret Service confirm $150M cyberheist tied to LastPass
Krebs on Security reported that federal investigators confirmed the connection between the $150 million Ripple co-founder cryptocurrency theft and the 2022 LastPass breach. The seizure document showed the U.S. Secret Service and FBI agreed with blockchain researcher ZachXBT's finding that private keys stored in a LastPass vault were used to execute the theft.
LastPass marks clickjacking report 'informative' before promising fixes
Independent researcher Marek Tóth showed at DEF CON 33 that browser extensions of major password managers, including LastPass 4.146.3, could be tricked by hidden overlays into leaking credentials, 2FA codes and card details. LastPass had marked the report 'informative'; after publication it said it had some clickjacking safeguards, such as a prompt before autofilling cards and personal details, and was working on the issues.
UK ICO fines LastPass £1.23 million for GDPR violations
The UK Information Commissioner's Office fined LastPass UK Ltd £1,228,283 for infringing UK GDPR Articles 5(1)(f) and 32(1)(f), finding the company failed to implement appropriate technical and organisational security measures. The breach affected up to 1.6 million UK users. The ICO found the hacker reached decryption keys by compromising a senior employee's personal device, and said stopping staff from accessing business accounts on personal devices would have significantly reduced the risk. The fine was reduced 30% for measures LastPass had taken.
LastPass launches Business Max tier and passkeys for all customers
LastPass made passkeys available to all customers, letting users create and store them in the vault alongside passwords. It also introduced Business Max, a new top business SKU that holds its SaaS Monitoring and SaaS Protect features for discovering and controlling unapproved apps and AI tools.
TRM Labs traces $35 million in LastPass-linked crypto theft to Russian actors
TRM Labs published research showing that vault backups stolen in 2022 were still being cracked to drain cryptocurrency as recently as late 2025. It traced more than $35 million in stolen assets, including $28 million converted to Bitcoin and laundered via Wasabi Wallet between late 2024 and early 2025, and found on-chain indicators of Russian cybercriminal involvement, with funds off-ramped through high-risk Russian exchanges. Earlier researcher tallies (Nefture Security, July 2025) put total crypto losses tied to the breach above $437 million.
First major phishing campaign of 2026 targets LastPass customers
LastPass's Threat Intelligence, Mitigation, and Escalation (TIME) team alerted customers to a phishing campaign that began around January 19, 2026. Attackers sent emails claiming LastPass would conduct maintenance, urging users to backup their vaults within 24 hours. Phishing links directed victims to sites hosted on AWS S3 buckets, redirecting to spoofed domains like mail-lastpass.com and security-lastpass.com. The campaign was timed over a U.S. holiday weekend to exploit reduced staffing and delayed detection.
Court approves $24.5 million class action settlement
A federal court granted preliminary approval to a $24.5 million settlement of the LastPass data breach class action. The settlement included an $8.2 million general fund for class members and a separate $16.25 million fund for documented cryptocurrency losses, with individual payouts up to $900,000 for proven crypto theft. Class members could also receive a complimentary six-month LastPass Premium upgrade.
CEO details post-breach security overhaul in trust pitch
CEO Karim Toubba said LastPass had made a 'multi-year, multi-million-dollar investment' in security since 2022: employees are limited to locked-down company devices, hardware YubiKeys guard access, and more stored data is encrypted, including billing and email addresses of the kind exposed in the breach. He argued customers could trust the company again.
ETH Zurich study finds seven attacks against LastPass vaults
ETH Zurich researchers analysing Bitwarden, LastPass and Dashlane under a malicious-server model found seven attacks against LastPass, including abuse of its key-escrow account recovery and flawed item-level encryption that allowed integrity violations and metadata leakage. LastPass said it had applied hardening measures and was working to bind items, fields and metadata more strongly; there was no evidence of exploitation.
B.C. court approves US$3 million Canadian breach settlement
The Supreme Court of British Columbia approved a US$3,000,000 settlement of the Canadian class action filed in February 2023 over the 2022 breach, covering legal fees and administration costs. The defendants, GoTo and LastPass entities, denied liability.
Second phishing campaign of 2026 spoofs LastPass account alerts
In early March 2026 LastPass warned of a second phishing campaign in two months. Attackers used display name spoofing and fake email chains to impersonate LastPass, claiming unauthorized actions on accounts such as vault exports or new trusted-device registrations. Links redirected to verify-lastpass[.]com, a fake single sign-on page designed to harvest master passwords. It followed a January 2026 'maintenance' campaign and an October 2025 campaign claiming LastPass had been hacked.
Outage locks LastPass users out of their vaults
Users reported widespread login failures and vault-access problems as LastPass's status page showed major outages for components including MFA and regional services. LastPass apologised for the disruption and blamed an internal issue. It followed a February 2026 incident in which login verification emails failed for hours.
Klue supply-chain breach exposes LastPass customer data
LastPass told customers that attackers who breached Klue, a market-intelligence tool used by its sales teams, used stolen OAuth tokens to reach its Salesforce environment and take customer names, phone numbers, email and postal addresses, support-case data and sales data. LastPass said its own infrastructure and customer vaults were not affected. The extortion group Icarus claimed the Klue breach, which also hit other security firms.
Judge takes U.S. breach settlement under advisement
At the final-approval hearing for the $24.5 million U.S. class settlement, Judge Patti B. Saris took all matters under advisement and ordered supplemental briefing after an objection was filed. On August 10, 2026 she approved a supplemental notice and appointed a special master, leaving final approval pending.
Evidence (48 citations)
D1: User Value Erosion
D2: Business Customer Exploitation
D3: Shareholder Extraction
D4: Lock-in & Switching Costs
D5: Twiddling & Algorithmic Opacity
D6: Dark Patterns
D7: Advertising & Monetization Pressure
D8: Competitive Conduct
D9: Labor & Governance
D10: Regulatory & Legal Posture
Scoring Log (9 entries)
Checked 85 items + prose. 52 verified, 24 corrected (5 date-only), 8 re-sourced, 1 removed. Invented: Dark Patterns Tip Line 'can't cancel online' claim attributed to LastPass; the cited sighting is about Evens (removed evidence[21], fixed D6 summary/narrative). Also: $438M crypto losses misattributed to TRM Labs (TRM traced ~$35M; figure is Nefture's); $24M seizure misdated to Jan 2024 (was Mar 2025); Business-plan repackaging misdated 2019 (was June 2021); class-action case name/number attached to the wrong suit; Canadian settlement now approved (C$4.2M); export-limitation list unsupported by its source; Glassdoor percentages unverifiable.
56→44. D1 8→7 (recalibration: breach harm persists but remediation since 2023; functionality not buried under monetization, fits 6-7), D2 6→5 (recalibration: no take rate; repackaging, add-on unbundling and breach risk-shifting fit 4-5), D3 7→5 (recalibration: PE ownership and recurring layoffs, but no buybacks/dividends or layoffs during record profits documented), D4 4→3 (recalibration: CSV export, direct import tools, many rivals, mass exit shown), D6 5→4 (correction: fact audit removed invented 'can't cancel online' claim; remaining evidence is user reports), D7 6→5 (recalibration: no ads; paywalled free features and tiering fit 4-5), D8 3→2 (recalibration: no anticompetitive conduct, minor acquisitions), D9 7→5 (recalibration: PE control and layoffs, no anti-union action or layoffs during record profits), D10 6→4 (recalibration: ICO fine and settlements for the breach; no lobbying, SLAPPs or consent-decree violations); D5 unchanged at 4. Eras: all 6 re-dated — Indie Startup 2008-01-01→2008-08-22 (founding); LogMeIn Acquisition 2015-10-01→2015-10-09; Price Extraction Begins 2019-03-01→2017-08-03 (first price doubling/feature paywall); Free Tier Gutted 2021-03-01→2021-02-16 (announcement); Catastrophic Breach 2022-12-01→2022-08-25 (first disclosure); current era 2026-02-11→2024-05-01 (GoTo spinoff) and relabeled Ongoing Fallout→Standalone Reckoning. Since Feb 2026: ETH Zurich study (7 attacks on LastPass), Canadian US$3M settlement approved, March outage, Secure Access Essentials launch, June Klue supply-chain breach exposing customer CRM/support data, U.S. $24.5M settlement final approval under advisement (special master appointed Aug 2026); no price or free-tier change. Trajectory worsening→stable.
Checked 9 removed/trimmed claims: 1 restored, 3 partly restored, 5 confirmed removed. Restored: Debt Cleanse complaint's breach-of-contract claim (complaint Doc. 1). Partly: 2015 LastPass FAQ promise to keep supporting Xmarks (Wayback); 2024 Advanced SSO/MFA paid add-ons (LastPass pricing, Wayback) and Bitwarden Premium $10/yr (Bitwarden pricing, Wayback); export-limitations claim added as new D4 evidence item (LastPass Support: attachments and TOTP codes not exported). Confirmed removed: 2017 business price rise/15,000 orgs, 1Password 'bait-and-switch'/Apple-Google expansion, spinoff 'market demand'/critics, HN refund refusals, Glassdoor 31% outlook (April 2024 snapshot showed 43%).
Removed typed-in site scores from alternatives text (they go stale on re-score; the page shows live scores). No other changes.
Triaged 2026-06-30 (Wave A); no rescore warranted (no material change / changes sub-threshold / flag refuted on verification).
Added 1 missing dimension narrative