LastPass Proves Trust Cannot Be Patched
LastPass's core asset is the vault — and the asset that makes them valuable makes them dangerous to own. That's not a fixable architecture problem; it's a product design contradiction.
LastPass has suffered another data breach, and at this point the product is the breach.
This isn’t a story about a security failure. Security failures happen to good companies — to Okta, to Cloudflare, to firms with genuine engineering discipline. This is a story about institutional trust burning down one incident at a time and the market somehow not reacting fast enough. LastPass had a major breach in 2022. They had another in 2023. Now it’s 2026 and they’re notifying users again. Three breaches in four years at a company whose entire value proposition is that they hold the keys to your digital life.
Everyone says the password manager market is sticky because switching costs are high. The opposite is closer to true: switching costs are low — a weekend and a CSV export — and the only thing keeping users locked in is the status quo bias and the vague hope that the next incident will be someone else’s problem.
Here’s what makes this commercially interesting rather than just embarrassing. LastPass’s core asset isn’t code, it’s the vault. The cryptographic container holding credentials for some meaningful fraction of enterprise and consumer users worldwide. The company keeps breaching and keeps getting breached precisely because that vault is the target. The asset that makes them valuable makes them dangerous to own. That’s not a fixable architecture problem; it’s a product design contradiction that compounds with every news cycle.
The industry framing is that zero-knowledge encryption protects users even in a breach — that the attacker gets encrypted blobs, not plaintext passwords. This is the steelman, and it’s worth engaging with seriously. Properly implemented zero-knowledge vaults do limit blast radius. But “properly implemented” is doing enormous work in that sentence. The 2022 breach exposed vault backups. The question was always how strongly those vaults were encrypted, and the answer depended on whether users had followed LastPass’s own password-length guidance years earlier, before the company raised its requirements. Many hadn’t. The theoretical security model and the actual user population are two different things, and LastPass — better than anyone — should have known that.
What the market keeps mispricing is the compounding cost of repeated disclosure. First breach: users are alarmed, most stay. Second breach: users are annoyed, a fraction leave, the rest rationalize. Third breach: something else happens. Users stop believing the security narrative and start believing the breach narrative instead. At that point, the brand is the liability. No amount of SOC 2 certifications or blog posts from a new CISO reverses it. The company is no longer selling a security product; it’s selling inertia, which is a much shorter runway.
The real tell is what’s happened to competitors. Bitwarden has grown steadily. 1Password raised at a $6.8 billion valuation in 2022 and has kept enterprise momentum. Both are winning precisely because they’re not LastPass — not because they invented something new, but because they didn’t burn down their trust surface three times in public. In security software, absence of failure is the product. LastPass has made absence of failure impossible to demonstrate.
There’s a broader principle at stake for any SaaS company that holds sensitive user data. Custody is a business model, and custody is a liability. The more sensitive the asset, the more consequential each operational failure. Password managers, crypto custodians, healthcare records platforms, communications vaults — they all face the same dynamic. The market will pay for custody right up until it decides the custodian is the threat model. After that, no pricing discount recovers the trust.
LastPass’s private equity owners — Francisco Partners acquired the company from LogMeIn in 2021 — are now holding an asset whose brand is net negative. The software still works. The zero-knowledge model still technically holds. But you cannot run a custody business on a brand that users associate with breaches. The exit path gets narrower with every notification email.
The password manager you trust most is the one you’ve never heard of for the wrong reasons.