Most people comparing LastPass with an alternative in 2026 are doing so because of the 2022 breach. This page treats that honestly and factually rather than gleefully — the details are a matter of public record, and they matter for anyone deciding where to keep their passwords. It also covers the architectural differences and how to migrate safely if you decide to move.
In 2022 LastPass disclosed two linked security incidents. An attacker first accessed parts of LastPass’s development environment, then used information from that intrusion to compromise a senior engineer’s device and reach a cloud backup store. The result, confirmed by LastPass and the UK Information Commissioner’s Office, was that attackers exfiltrated backup copies of customer vault data — including encrypted fields such as usernames and passwords, and unencrypted fields such as website URLs.
Because the stolen vaults were encrypted, they were not immediately readable. But an offline copy gives attackers unlimited time to brute-force weak master passwords, and security researchers and law enforcement have since linked the stolen data to a long series of cryptocurrency thefts continuing for years afterward. In November 2025 the UK ICO issued a monetary penalty against LastPass’s UK entity, and a class-action settlement was reached in the US. These are not allegations; they are documented outcomes.
If you had a LastPass vault before December 2022, treat its contents as potentially exposed to offline cracking — especially anything financial or any stored recovery phrases. Rotating those credentials is worth doing regardless of which manager you move to.
| HexVault | LastPass | |
|---|---|---|
| Encryption | AES-256-GCM | AES-256-CBC |
| Key derivation | Argon2id (memory-hard) | PBKDF2 |
| Per-entry key separation | Yes (per-entry HKDF) | No |
| Unencrypted metadata in vault | No — URLs are encrypted too | Yes historically (URLs were not encrypted) |
| Known vault-data breach | None | Yes (2022, confirmed) |
| Free tier | Yes (full personal vault) | Yes (limited) |
| Jurisdiction | United Kingdom | United States |
Competitor details as of July 2026 and subject to change. The breach facts are drawn from LastPass’s own disclosures, the UK ICO, and public reporting.
The LastPass breach is instructive regardless of which product you choose, and it shaped choices in HexVault:
None of this makes any product breach-proof, and HexVault does not claim to be. The honest difference is in what an attacker gets if a copy is ever taken.
LastPass remains a functioning password manager, and its current encryption is standard. But if the 2022 breach is why you are here, the reasonable response is to move your credentials somewhere with a clean record and a more conservative design, and to rotate anything sensitive that lived in a vault stolen in that incident. HexVault offers memory-hard key derivation, encrypted metadata, per-entry separation, and a free personal tier — and, like LastPass, is zero-knowledge, so we cannot read your vault.
Importing from LastPass takes about five minutes — and rotate the important ones after →