https://en.wikipedia.org/wiki/LastPass#2022_customer_data_an...
https://en.wikipedia.org/wiki/LastPass#2022_customer_data_an...
2017: Design flaws in LastPass two factor authentication. http://www.martinvigo.com/design-flaws-lastpass-2fa-implemen...
2016: More LastPass security vulnerabilities. https://palant.de/2016/09/16/more-last-pass-security-vulnera...
2015: Even the LastPass will be stolen. http://www.martinvigo.com/even-the-lastpass-will-be-stolen-d...
If I understand:
Attackers got access to LastPass's account data backups directly and in bulk. 2FA doesn't help here.
While LastPass since increased their password rounds for new accounts to 100k+, many users especially long-time users had them set well below and never updated. Reports of 5000 rounds, 500 rounds, ... even 1 round.
URLs were not encrypted. If you had sensitive URLs, I think you have to treat them as compromised. If you had crypto exchange logins or high-value URLs, I'd imagine you might attract extra attention.
[edit for typos].
The article text mentions 1Password as the first listed PWM product.