Server racks with glowing lights in a data center

LastPass vs 1Password After the Breach: Is It Safe for Cleared Work?

This post contains affiliate links. If you sign up through one of them, RMF Insider may earn a commission at no additional cost to you. Product selection and opinions are our own.

LastPass vs 1Password after the breach is not a hypothetical comparison anymore — it is a question I get from coworkers who are specifically worried about what “cleared work” tolerance for risk should look like when picking a password manager. LastPass has a breach history that is longer and more serious than most vendors survive. The question is whether that history should actually change your buying decision, or whether it is just internet noise at this point. It should change your decision. Here is the actual timeline and what it means for a password vault you rely on for sensitive accounts.

LastPass’s Breach History, in Order

This is not one incident. It is a pattern, and the pattern matters more than any single event.

2022: The Big One

In 2022, LastPass disclosed a breach that exposed roughly 30 million customers. Attackers exfiltrated encrypted vault backups along with unencrypted metadata — URLs and usernames were not encrypted in the backup, only the password fields themselves were. That metadata alone told attackers which sites a target used, which is a meaningful reconnaissance win even before touching the encrypted fields. The encrypted password data was then subjected to offline brute-force cracking attempts, which is the scenario every password manager is theoretically supposed to make infeasible through strong master-password-derived encryption. For users with weak master passwords, it was not infeasible.

2025: The Settlement

A $24.5 million class-action settlement was reached in 2025 covering losses tied to the breach — a formal acknowledgment, via legal settlement rather than a technical admission, that real financial harm resulted from the incident.

2026: A Third-Party Platform Compromise

In June 2026, LastPass customer data was exposed again, this time through a compromise of Klue, a third-party platform. Vault contents were not affected in this incident, but customer details were exposed. On their own, third-party vendor compromises happen to plenty of companies and are not automatically disqualifying. Stacked on top of a 2022 breach and a 2025 settlement, it reads as a company whose surrounding security posture — not necessarily the core encryption architecture — has had recurring gaps.

Does This Actually Matter If Your Vault Itself Was Not Cracked?

This is the honest, harder question. LastPass’s zero-knowledge architecture means the company itself should not be able to read your vault contents even when breached — that architecture is not unique to LastPass and is standard across major password managers. In the 2022 breach, the encrypted vault data itself was not “cracked” wholesale; it was exfiltrated and subjected to offline attacks that succeed mainly against weak master passwords.

So the technical argument for “the encryption held” is defensible. But for cleared or DoD-adjacent work, the standard is not just “was the cryptography broken.” It is “would I want to explain this vendor’s incident history to a security officer during an assessment, or have it show up during an insider-risk or vendor-risk review.” A recurring breach pattern is the kind of fact that, once it is on record, does not go away just because the crypto held on the worst individual incident. Reputational and procedural risk are real risk categories, not just technical ones.

1Password: The Architecture Difference

1Password’s headline architectural difference is the Secret Key — a locally generated, high-entropy value combined with your master password to derive the encryption key. Even if 1Password’s servers were fully compromised and an attacker obtained the encrypted vault data, they would also need the Secret Key, which is never transmitted to or stored by 1Password’s servers, only kept on your registered devices. That two-factor-for-encryption design is a meaningfully different threat model than a master-password-only scheme, because a stolen server-side vault backup alone is not enough to attempt an offline crack.

1Password runs at $2.99/month on the annual plan, includes unlimited passwords and devices, 1GB of document storage, Watchtower breach monitoring, and passkey support. There is a 14-day free trial and no free tier — you pay for the product, full stop. Worth noting: pricing increased in March 2026, so check current rates before committing, though it remains squarely mid-market compared to competitors.

[AFFILIATE-LINK: 1Password]

1Password has not had a breach of comparable scale or frequency to LastPass’s 2022-2026 pattern. That is not a permanent guarantee — no vendor gets one — but as of this writing it is the honest comparison point.

Side-by-Side: What Changed and What Didn’t

FactorLastPass1Password
Major breach history2022 (30M users), 2025 settlement, 2026 third-party exposureNo comparable breach on record
Server-side key architectureMaster password derives encryption keyMaster password + locally-held Secret Key
Approximate renewal price$36-60/year$47.88/year ($2.99/mo annual)
Free tierLimited free tier availableNone (14-day trial only)
Breach monitoringAvailableWatchtower, included

Is LastPass Safe for Cleared Work?

Set aside brand loyalty and answer this the way you would answer it during a vendor risk assessment. A three-strike breach and incident pattern over four years, involving exfiltrated backups and a third-party compromise, is exactly the kind of finding that would sink a vendor in a formal risk review for a system handling anything sensitive. That standard should not lower just because it is your personal vault instead of a government system. If you are storing credentials tied to cleared work, official accounts, or anything you would not want summarized in a breach notification email, the recurring pattern is reason enough to move.

That does not mean every current LastPass user needs to panic-migrate overnight. It means the next renewal cycle is a good, low-friction moment to switch rather than auto-renewing out of habit.

How to Migrate Without Losing Anything

  • Export your LastPass vault as a CSV before canceling — do this while your subscription is still active, not after.
  • Import the CSV into 1Password’s import tool, which maps LastPass fields automatically in most cases.
  • Delete the plaintext CSV export immediately after import — it is an unencrypted copy of your entire vault sitting on disk until you do.
  • Rotate your highest-value passwords after migration rather than assuming the old ones are still fine — this is also a good moment to enable a hardware key like a YubiKey wherever the service supports FIDO2.
  • Cancel the LastPass subscription only after confirming the import completed and spot-checking a handful of entries.

The Bottom Line

LastPass’s core encryption has not been definitively “broken” in the sense of an attacker reading vault contents at scale without a weak master password. But three incidents in four years, including exfiltrated backups and a 2026 third-party exposure, is a pattern that would fail a vendor risk review in any DoD-adjacent context, and there is no reason to hold your personal password vault to a lower bar. 1Password’s Secret Key architecture is a real, meaningful difference, not just marketing language, and the price difference between the two is small enough that it should not be the deciding factor.

If you want the deeper technical walkthrough of the Secret Key model and how 1Password holds up under the same scrutiny, I cover that in 1Password Review 2026: The Secret Key Advantage, Explained by a Security Practitioner. And if you are rethinking your broader security toolkit at the same time, Best VPN for Security Professionals in 2026 applies the same vendor-scrutiny approach to a different category.

Pro Tools for Working ISSOs

Working a real ATO package right now?

Skip the spreadsheet rebuild. These are the exact tools I use in the field as an active DoD ISSO.


Get the free RMF Quick Reference

All 7 RMF steps on one page — free when you subscribe to the weekly ISSO Insider.

Leave a Reply

Discover more from RMFInsider

Subscribe now to keep reading and get access to the full archive.

Continue reading