LastPass
Still one of the most used password managers and the one with the record: encrypted vaults stolen in 2022 and disclosed at Christmas, master-password defaults weak enough that around $35 million in cryptocurrency has since been traced to cracked vaults, a £1.2 million ICO fine in December 2025 for 1.6 million UK users, and a June 2026 supply-chain breach of its customer database. Pound pricing, Teams at £3.83 a user, passkeys and an authenticator on every plan; ISO 27001 and SOC 2 since; Trustpilot 1.4 on 930 reviews.
How we testLastPass (LastPass US L.P., independent of GoTo since 2024) has a longer security record than any product here, and it is why the score is what it is. In August 2022 an attacker used a compromised developer account to take source code from the development environment. Between November and December 2022 the same attacker used that material to reach third-party cloud storage and copy customer account details and encrypted vault backups, in which website URLs were stored unencrypted; LastPass confirmed the vault theft in a blog post on 22 December 2022, three weeks after a notice that had described only cloud-storage access. In March 2023 it disclosed that the way in had been a senior DevOps engineer's computer, compromised through vulnerable third-party software, which yielded a decryption key. The vaults were only as strong as their master passwords and the key-stretching behind them: the default was 5,000 rounds of PBKDF2 from 2018, and old accounts were found with as few as one to five hundred, against the million that RoboForm and Keeper use. Krebs on Security reported in September 2023 that researchers had linked more than $35 million of cryptocurrency theft to cracked vaults; TRM Labs put the figure at about $35 million again in a report published in January 2026, tracing the proceeds to Russia-based operators, and the US Secret Service seized $23 million of it in 2025. On 11 December 2025 the UK Information Commissioner fined LastPass £1.2 million over the 2022 breach, which affected up to 1.6 million UK users; the Commissioner said customers "had a reasonable expectation that their personal information would be protected". And on 23 June 2026 LastPass confirmed that an extortion group had used OAuth tokens stolen from a third-party vendor, Klue, to read customer names, addresses, phone numbers and support cases from its Salesforce system; vaults were not involved.
LastPass has changed a good deal since. Master passwords must now be twelve characters (January 2024), URLs in vaults are encrypted (May 2024), the company built a new cloud platform and internal security teams, and it lists ISO 27001, ISO 27701, SOC 2 Type II, SOC 3 and BSI C5. The current product is competent: passkeys and a built-in authenticator on every plan, shared folders and an admin console from Teams, directory integration with Entra ID, Google Workspace, Okta and OneLogin from Business, SaaS monitoring on Business Max, a legacy open-source CLI, an admin API and no MCP server. Prices in pounds before VAT on 8 September 2026, all billed annually: Free for one device type, Premium £2.60 a month, Families £3.40 for six, Teams £3.83 a user a month for up to fifty users, Business £5.50 with SSO limited to three applications and unlimited users, and Business Max £8.50 with unlimited SSO applications and advanced MFA; business trials run fourteen days without a card. Support is 24/7 and multilingual; a data-residency choice was not found.
Trustpilot is 1.4 on 930 unprompted reviews, 80% one-star, with lockouts without a recovery path, support that free users cannot reach and charges after cancellation the themes. Our position is the one a reader would expect: the breach was four years ago and the fixes are real, but the disclosure pattern, the weak defaults left on old accounts, the regulator's finding and a further customer-data breach in 2026 mean we cannot put it above any provider on this page. Every other product here does the job without that history. Saaskly has no commercial relationship with LastPass.
Pros
- +Pound pricing before VAT; passkeys and a built-in authenticator on every plan; shared folders and an admin console from £3.83 a user
- +ISO 27001, ISO 27701, SOC 2 Type II, SOC 3 and BSI C5 since the breach; twelve-character master passwords and encrypted URLs now enforced
- +24/7 multilingual support and directory integration from the Business tier
Cons
- −Encrypted vaults stolen in 2022 and disclosed on 22 December; weak key-stretching on old accounts; about $35 million of crypto theft traced to cracked vaults
- −A £1.2 million ICO fine in December 2025 for 1.6 million UK users, and a June 2026 breach of customer CRM data through a supplier
- −Trustpilot 1.4 on 930 reviews; SSO capped at three apps on Business; no MCP server; annual billing only
Pricing
Minimum commitment: £2.60 (£2.60/yr for the entry licence). The least you can spend before walking away; excludes numbers, minutes and add-ons.
Premium (individual)
£2.60/yr · annual commitment
Month-to-month: not published
- ✓£2.60/mo billed annually, ex VAT (taxes at checkout), 8 Sep 2026; Families £3.40/mo for 6. Free: one device type. 30-day Premium trial, no card. Passkeys and built-in authenticator on every plan.
Teams
£3.83/yr · annual commitment
Month-to-month: not published
- ✓£3.83/user/mo billed annually, up to 50 users: admin console, shared folders, basic reporting, directory integration. Business £5.50 (unlimited users, SSO for 3 apps, 100+ policies, SCIM-style provisioning); Business Max £8.50 (unlimited SSO apps, SaaS monitoring, advanced MFA). 14-day trial, no card. No monthly billing.
Specifications
| Rating | 2.3 |
| Business per user* | £3.83/user/mo annual only (Teams (up to 50 users)) |
| Individual | £2.60/mo annual only |
| Free tier | Limited |
| Seat minimum | 1 |
| Breach on record | ✓ |
| Last audit | None published |
| Open source | No |
| Self-host | No |
| Passkeys | Store |
| TOTP codes | ✓ |
| Hardware key | ✓ |
| SSO | Extra cost |
| SCIM | ✓ |
| Shared vaults | ✓ |
| Secrets manager | No |
| CLI | ✓ |
| MCP server | No |
| Owned in** | US-owned |
| Data location | Not published |
| Trustpilot (reviews) | 1.4 (930) |
| Family plan | £3.40/mo (6 seats) |
| Scored tier | Teams (up to 50 users) |
| Tier above | Business (£5.50/user) |
| Free tier limits | One device type (computer or mobile) |
| Money-back (days) | 0 |
| Encryption | AES-256; PBKDF2-SHA256 (defaults as low as 5,000 rounds before 2023) |
| Zero-knowledge | ✓ |
| Breach note | Aug to Dec 2022: source code then encrypted vault backups stolen; about $35m crypto theft traced to cracked vaults; ICO fine £1.2m on 11 Dec 2025; Jun 2026 Salesforce data taken via supplier Klue |
| Bug bounty | ✓ |
| Email aliases | No |
| Built-in VPN | No |
| Admin console | ✓ |
| Role-based permissions | ✓ |
| Password health reports | ✓ |
| Dark-web monitoring | ✓ |
| External sharing | No |
| Guest accounts | No |
| Emergency access | ✓ |
| Audit logs | ✓ |
| Browser extensions | Chrome, Firefox, Safari, Edge |
| Desktop apps | ✓ |
| Linux | ✓ |
| API | ✓ |
| HQ | US |
| Owner | LastPass US L.P. |
| SOC 2 | ✓ |
| ISO 27001 | ✓ |
| Live chat | ✓ |
| Phone support | No |
| Support channels | Live support 24/7 (paid plans), Support centre, Community forum |
*Business per user: the business or teams tier the score is set on, per user per month on annual billing and then month-to-month, in the currency the vendor shows a UK visitor on the research date; see each profile for the VAT basis, the seat minimum and what the tier above adds.
**Owned in: where the company that owns the provider answers to. A US-owned provider is subject to US law (including the CLOUD Act) wherever the vault is stored; with a zero-knowledge design the vendor cannot read the vault either way, so this column is about the company, not the encryption. "Data location" records where the encrypted vault is stored.
Researched and drafted with AI assistance; reviewed and approved by Tim Meredith. How we use AI
Work at LastPass? Something not look right? Register in the vendor portal to see what we publish and send corrections.