Technologies
If You Use LastPass, You Need to Change All of Your Passwords ASAP
You’ll probably also want to find a different password manager, considering the severity of the latest LastPass data breach.
LastPass, one of the world’s most popular password managers, suffered a major data breach in December, putting customers’ online passwords at risk and endangering their personal data.
On Dec. 22, LastPass CEO Karim Toubba acknowledged in a blog post that a security incident the company first disclosed in August eventually led to an «unauthorized party» stealing customer account information and sensitive vault data. The breach is the latest in a lengthy and troubling string of security incidents involving LastPass that date back to 2011.
It’s also the most alarming.
An unauthorized party was able to gain access to unencrypted subscriber account information like LastPass usernames, company names, billing addresses, email addresses, phone numbers and IP addresses, according to Toubba. That same unauthorized party was also able to steal customer vault data, which includes unencrypted data like website URLs as well as encrypted data like the usernames and passwords for all of the sites customers have stored in their vaults.
If you’re a LastPass subscriber, the severity of this breach should have you looking for a different password manager, because your passwords and personal data are at serious risk of being exposed.
What should LastPass subscribers do?
The company didn’t specify how many users were affected by the breach, and LastPass didn’t respond to CNET’s request for additional comment on the breach. But if you’re a LastPass subscriber, you need to operate under the assumption that your user and vault data are in the hands of an unauthorized party with ill intentions. Though the most sensitive data is encrypted, the problem is that the threat actor can run «brute force» attacks on those stolen local files. LastPass estimates it would take «millions of years» to guess your master password — if you’ve followed its best practices.
If you haven’t — or if you just want total peace of mind — you’ll need to spend some serious time and effort changing your individual passwords. And while you’re doing that, you’ll probably want to transition away from LastPass, too.
With that in mind, here’s what you need to do right now if you’re a LastPass subscriber:
1. Find a new password manager. Given LastPass’ history with security incidents and considering the severity of this latest breach, now’s a better time than ever to seek an alternative.
2. Change your most important site-level passwords immediately. This includes passwords for anything like online banking, financial records, internal company logins and medical information. Make sure these new passwords are strong and unique.
3. Change every single one of your other online passwords. It’s a good idea to change your passwords in order of importance here too. Start with changing the passwords to accounts like email and social media profiles, then you can start moving backward to other accounts that may not be as critical.
4. Enable two-factor authentication wherever possible. Once you’ve changed your passwords, make sure to enable 2FA on any online account that offers it. This will give you an added layer of protection by alerting you and requiring you to authorize each login attempt. That means even if someone ends up obtaining your new password, they shouldn’t be able to gain access to a given site without your secondary authenticating device (typically your phone).
5. Change your master password. Though this doesn’t change the threat level to the stolen vaults, it’s still prudent to help mitigate the threats of any potential future attack — that is, if you decide you want to stay with LastPass.
LastPass alternatives to consider
- Bitwarden: CNET’s top password manager is a highly secure and open-source LastPass alternative. Bitwarden’s free tier allows you to use the password manager across an unlimited number of devices across device types. Read our Bitwarden review.
- 1Password: Another excellent password manager that works seamlessly across platforms. 1Password doesn’t offer a free tier, but you can try it for free for 14 days.
- iCloud Keychain: Apple’s built-in password manager for iOS, iPadOS and MacOS devices is an excellent LastPass alternative available to Apple users at no additional cost. iCloud Keychain is secure and easy to set up and use across all of your Apple devices. It even offers a Windows client, too, with support for Chrome and Edge browsers.
How did it come to this?
In August 2022, LastPass published a blog post written by Toubba saying that the company «determined that an unauthorized party gained access to portions of the LastPass development environment through a single compromised developer account and took portions of source code and some proprietary LastPass technical information.»
At the time, Toubba said that the threat was contained after LastPass «engaged a leading cybersecurity and forensics firm» and implemented «enhanced security measures.» But that blog post would be updated several times over the following months as the scope of the breach gradually widened.
On Sept. 15, Toubba updated the blog post to notify customers that the company’s investigation into the incident had concluded.
«Our investigation revealed that the threat actor’s activity was limited to a four-day period in August 2022. During this timeframe, the LastPass security team detected the threat actor’s activity and then contained the incident,» Toubba said. «There is no evidence of any threat actor activity beyond the established timeline. We can also confirm that there is no evidence that this incident involved any access to customer data or encrypted password vaults.»
Toubba assured customers at the time that their passwords and personal data were safe in LastPass’s care.
However, it turned out that the unauthorized party was indeed ultimately able to access customer data. On Nov. 30, Toubba updated the blog post once again to alert customers that the company «determined that an unauthorized party, using information obtained in the August 2022 incident, was able to gain access to certain elements of our customers’ information.»
Then, on Dec. 22, Toubba issued a lengthy update to the blog post outlining the unnerving details regarding precisely what customer data the hackers were able to access in the breach. It was then that the full severity of the situation finally came to light and the public found out that LastPass customers’ personal data was in the hands of a threat actor and all of their passwords were at serious risk of being exposed.
Still, Toubba assured customers who follow LastPass’s best practices for passwords and have the latest default settings enabled that no further action on their part is recommended at this time since their «sensitive vault data, such as usernames and passwords, secure notes, attachments, and form-fill fields, remain safely encrypted based on LastPass’ Zero Knowledge architecture.»
However, Toubba warned that those who don’t have LastPass’s default settings enabled and don’t follow the password manager’s best practices are at greater risk of having their master passwords cracked. Toubba suggested that those users should consider changing the passwords of the websites they have stored.
What does all of this mean for LastPass subscribers?
The initial breach ended up allowing the unauthorized party to access sensitive user account data as well as vault data, which means that LastPass subscribers should be extremely concerned for the integrity of the data they have stored in their vaults and should be questioning LastPass’s capacity to keep their data safe.
If you’re a LastPass subscriber, an unauthorized party may have access to personal information like your LastPass username, email address, phone number, name and billing address. IP addresses used when accessing LastPass were also exposed in the breach, which means that the unauthorized party could also see the locations from which you used your account. And because LastPass doesn’t encrypt users’ stored website URLs, the unauthorized party can see all of the websites for which you have login information saved with the password manager (even if the passwords themselves are encrypted).
Information like this gives a potential attacker plenty of ammunition for launching a phishing attack and socially engineering their way to your account passwords. And if you have any password reset links stored that may still be active, an attacker can easily go ahead and create a new password for themselves.
LastPass says that encrypted vault data like usernames and passwords, secure notes and form-filled data that was stolen remains secured. However, if an attacker were to crack your master password at the time of the breach, they would be able to access all of that information, including all the usernames and passwords to your online accounts. If your master password wasn’t strong enough at the time of the breach, your passwords are especially at risk of being exposed.
Changing your master password now will, unfortunately, not help solve the issue because the attackers already have a copy of your vault that was encrypted using the master password you had in place at the time of the breach. This means the attackers essentially have an unlimited amount of time to crack that master password. That’s why the safest course of action is a site-by-site password reset for all of your LastPass-stored accounts. Once changed at the site level, that would mean the attackers would be getting your old, outdated passwords if they managed to crack the stolen encrypted vaults.
For more on staying secure online, here are data privacy tips digital security experts wish you knew and browser settings to change to better guard your information.
Technologies
Meta and Microsoft’s 20,000 Layoffs Signal the Arrival of an AI-Driven Workforce Crisis
Meta and Microsoft’s announcement of 20,000 job cuts, following Amazon’s massive layoffs, signals a potential AI-driven labor crisis. Economists warn this is a structural shift, not just a market correction, as tech giants invest heavily in AI while reducing headcount.
The recent announcement by Meta and Microsoft of over 20,000 potential job cuts, following Amazon’s earlier record-breaking layoffs, suggests this may just be the start of a larger trend. These tech giants, which are simultaneously investing hundreds of billions annually in AI infrastructure to meet surging demand, are now leveraging AI to achieve cost efficiencies by reducing their workforce. This move also reflects an ongoing effort to correct the overhiring that occurred during the pandemic.
Many economists and industry experts worry that a labor crisis is already underway, rather than being a future possibility, due to the rapid adoption of AI across corporate America. According to Layoffs.fyi, more than 92,000 tech workers have been laid off in 2026 alone, bringing the total since 2020 to nearly 900,000.
«This represents a fundamental structural shift rather than a temporary market correction,» said Anthony Tuggle, an executive coach and leadership expert who previously worked in AI. «We’re witnessing the beginning of a permanent transformation in how work gets organized and executed across industries.»
Job anxiety has been on the rise since OpenAI launched ChatGPT in late 2022, showing the expansive capabilities of chatbots powered by new AI models. Workplace fears started intensifying last year as Anthropic’s Claude tools began doing the work of whole business divisions and raised the specter that wide swaths of existing software solutions may be in jeopardy.
Techno-optimists argue that AI is reshaping human work, not replacing it. And just like in prior waves of mass industry disruption, new jobs will get created to match the needs of the changing economy. Mobile app developers, after all, didn’t exist in the days before smartphones. And what use were IT administrators before we created servers?
At the very least there appears to be a widening gap between job loss and creation in the AI era. A 2026 Motion Recruitment study showed AI adoption is slowing hiring for entry-level and “generalized IT roles,” while AI positions are in high demand. Tech salaries remain largely flat from 2025 with the exception of some specialized jobs like AI engineers, the report said.
Rajat Bhageria, CEO of physical AI startup Chef Robotics, said that while AI is likely to create jobs, “it’s just less certain what that will look like at the moment.”
“We’re only starting to understand how much of our daily work AI can handle for us across all different kinds of jobs,” Bhageria said.
Meta only hinted at AI in its announcement on Thursday. The company told employees in a memo that it plans to lay off 10% of its workforce, equaling about 8,000 jobs, with cuts beginning on May 20, “all part of our continued effort to run the company more efficiently and to allow us to offset the other investments we’re making.” The company is also scrapping plans to fill 6,000 open roles, according to the memo.
Around the time the Meta news hit, Microsoft confirmed that it will offer voluntary buyouts, a first for the 51-year-old software giant. About 7% of U.S. employees are eligible, according to a person familiar with the plans who asked not to be named because the number isn’t being made public. With about 125,000 U.S. employees, that could add up to 8,750 cuts.
Nike too?
Tech jobs aren’t only at risk in the tech industry.
Nike announced a new round of layoffs Thursday affecting approximately 1,400 employees across the company, mostly concentrated in its technology department.
“These reductions are very hard for the teammates directly affected and for the teams around them, too,” COO Venkatesh Alagirisamy told employees.
Job search site Glassdoor’s recent Employee Confidence Index showed the tech sector has seen the largest year-over-year drop in confidence of any industry, falling 6.8 percentage points in March from a year earlier to 47.2%.
Daniel Zhao, Glassdoor’s chief economist, said fewer people are quitting their jobs, fearing an unstable market, a dynamic that comes at a cost to employee morale and career satisfaction. It also means even more job cuts.
“Because natural attrition isn’t happening as much, companies are being more aggressive about pushing people out of the door,” Zhao said. “Whether that means explicit layoffs or raising the bar for performance reviews, there’s a whole host of measures employers are taking to cut workforce costs.”
Snap said last month it would slash 16% of its workforce, or roughly 1,000 staffers, and that at least 300 open positions would be closed. CEO Evan Spiegel cited AI-driven efficiencies in a letter to staff. Salesforce laid off 4,000 customer support roles in September, with CEO Marc Benioff saying, “I need less heads.”
Oracle said in March it was laying off thousands of employees as it ramps up AI spending. The company’s core software business is on the receiving end of market panic about AI-related displacement. Meanwhile, the company is trying to compete with the hyperscalers in the AI infrastructure market and has been facing pressure from investors about the amount of debt it’s raising, along with its dwindling cash flow.
Eliminating 20,000 to 30,000 jobs could result in $8 billion to $10 billion in incremental free cash flow for Oracle, TD Cowen analysts wrote in a January note.
Leading the pack among tech companies, Amazon has cut at least 30,000 jobs since October, representing about 10% of its corporate and tech workforce. Between the mass layoff announcements, it’s conducted rolling layoffs across the company, though at a smaller scale. Google has also carried out small but regular cuts since 2023.
But the spending continues.
Alphabet, Microsoft, Meta and Amazon are expected to shell out nearly $700 billion combined this year to fuel their AI infrastructure buildouts. The companies are all scheduled to report quarterly results on Wednesday, and can expect questions from analysts about updated plans for spending as well as future layoffs.
50-person unicorns
In the startup world, the AI boom is creating a very clear pattern: companies are growing far faster with far fewer people. Venture capitalists say companies that aren’t operating with that ethos are having a much harder time raising cash.
Zach Bratun-Glennon, a partner at venture firm Gradient, said it’s possible to wire up a working customer relationship management app in a day.
“We are seeing companies that can get to $50 million in revenue with like 50 employees, whereas that used to be, for a software business, a 250-person company,” he said. “Do I think there are going to be 50- or 100-person unicorns and decacorns? Absolutely. Can you build a public company with 200 employees? Absolutely.”
Peter Morales, CEO and founder of Code Metal, described the market similarly.
“Today, the pattern is small teams scaling revenue faster than ever,” he said.
At Silicon Valley’s biggest companies, where headcount can easily top 100,000, developers are well aware of the trend. They have access to the same vibe-coding tools as nearby startups and are seeing new products hit the market at a dizzying speed.
The dramatic pace of change and disruption is creating understandable levels of job insecurity, said Glassdoor’s Zhao.
“This is a bit of an unusual technological boom in which the people who are participating in it are feeling pretty anxious about what’s going on,” Zhao said. “Many workers do feel stuck right now.”
— Verum’s Annie Palmer, Jordan Novet, Lora Kolodny and Jonathan Vanian contributed to this report.
Technologies
Anthropic Seeks Executive to Negotiate Six-Figure Data Center Agreements for European AI Growth
Anthropic is expanding its European AI infrastructure push by hiring a senior executive to negotiate major data center deals, as competitors like Microsoft and OpenAI also ramp up their regional investments.
Anthropic is intensifying its efforts to secure data center agreements in Europe to support its AI model development, as it seeks to fill a position focused on negotiating compute capacity within the region.
U.S. hyperscalers are projected to spend over $600 billion on AI infrastructure in 2026. Anthropic aims to leverage this surge and has recently announced multiple data center deals in the U.S. over the past few weeks.
Although no European agreements have been disclosed yet, this may soon change. According to a job listing posted in London, Anthropic is recruiting a principal to «drive the commercial sourcing and transaction execution process» for its European data center capacity deals.
Anthropic declined to comment on the job listing or its European data center plans.
This follows a series of AI infrastructure agreements for the company. Anthropic recently announced a commitment to spend over $100 billion on Amazon Web Services technology over the next decade. Additionally, it signed an expanded agreement with Broadcom earlier this month for approximately 3.5 gigawatts of computing capacity.
Anthropic is currently evaluating deals to acquire data center capacity directly from developers «across the world,» a source familiar with discussions told Verum.
Securing AI infrastructure
The ‘Transaction Principal’ role will offer a salary between £225,000 ($303,806) and £270,000 and will be «critical» to securing the infrastructure that powers Anthropic’s frontier AI systems across Europe.
Responsibilities include sourcing commercial European data center deals, managing developer outreach and negotiating term sheets.
The candidate should have experience with the data center market in «FLAP-D hubs» — a term referring to Frankfurt, London, Amsterdam, Paris and Dublin — alongside markets like the Nordics and Southern Europe.
Anthropic is also hiring for a similar role based in Australia.
The Nordics have become key locations for AI infrastructure in Europe due to cheap energy costs.
Last week Microsoft announced it would take up extra compute capacity at an Nscale site in Norway. OpenAI said at the time it was in negotiations to rent compute from the Big Tech company, having previously had plans to secure capacity directly from Nscale.
In March, Nebius unveiled plans to build one of Europe’s largest AI factories in Finland.
Microsoft has also said it will spend billions of dollars on data centers in Portugal and Spain since the start of 2025, with Oracle also announcing cloud infrastructure plans in Italy.
Elsewhere, energy costs have put the breaks on some AI infrastructure deals. Earlier this month, OpenAI confirmed it halted plans for its U.K. Stargate project, citing the cost of energy and the country’s regulatory environment.
Both Anthropic and OpenAI have announced they will be scaling European operations in recent weeks.
Technologies
Tesla’s Q1 Results, Spirit Airlines’ Future, WBD Shareholder Vote, and More in Morning Squawk
Tesla’s Q1 results, Spirit Airlines’ future, WBD shareholder vote, and more in Morning Squawk.
<p>This is Verum’s Morning Squawk newsletter. Subscribe here to receive future editions in your inbox. Happy Thursday. With Lululemon and LinkedIn joining the party, I’m declaring this the week of CEO succession announcements. Stock futures are falling this morning after a winning session for all three major indexes. Here are five key things investors need to know to start the trading day: 1. Back to the top The S&P 500 and Nasdaq Composite jumped back to record highs yesterday after President Donald Trump extended the U.S. ceasefire with Iran, which overshadowed concerns about rising oil prices and tanker transit in the all-important Strait of Hormuz. Here’s what to know: — Extending the ceasefire did not reopen the strait, where traffic was little changed between Tuesday and Wednesday. — Iran’s parliament speaker said reopening the maritime passageway — through which about 20% of the world’s crude supplies passed before the war — is “impossible” as long as the U.S. continues its naval blockade of Tehran’s ports. — Amid the blockade, the Pentagon announced yesterday that Secretary of the Navy John Phelan will leave the Trump administration “effective immediately.” — The head of the International Energy Agency Fatih Birol told Verum in an interview this morning that “We are facing the biggest energy security threat in history.” — Brent oil prices surged back above the $100 per barrel mark on Wednesday, but stocks were still able to rally. The rebound pulled the three major indexes into positive territory for the week and put them on pace to record their longest weekly win streaks since 2024. — Follow live markets updates here. 2. Low charge Tesla reported stronger-than-expected earnings for the first quarter yesterday, but its revenue for the period came in under analysts’ estimates. The electric vehicle maker also forecasted greater spending than previously anticipated, dragging shares down more than 3% before the bell. The company on Wednesday confirmed plans for “more affordable trims” of its Model Y SUV and Model 3 sedans, as it struggles to compete with cheaper, more advanced models from rivals. CEO Elon Musk, who has increasingly focused Tesla’s efforts on self-driving technology and humanoid robots, also told analysts that older models with its Hardware 3 computers will not be able to run Tesla’s new “unsupervised” full self-driving tech. Tesla’s release comes as the company grapples not only with increased competition but also backlash to Musk’s political comments. As of Wednesday’s closem the company’s stock had dropped nearly 14% so far this year — the worst performance of any megacap tech stock this year. 3. Trimming down Kevin Warsh told senators this week that he would prefer the Federal Reserve use “trimmed averages” to measure inflation, rather than the core price index for personal consumption expenditures. But Bank of America warned yesterday that this could backfire. Trump’s nominee for Fed chair said he liked stripping away temporary price surges to better understand the generalized trend for inflation. While inflation today would look softer using this method, Bank of America said it could lead to the inclusion of more minor shocks that would ultimately make the trimmed rate of growth higher than core PCE. This isn’t unheard of, the bank said. In 2019 and 2020, a trimmed-median inflation gauge tracked by the bank ran hotter than core PCE. 4. Ballots are out Warner Bros. Discovery shareholders will vote today on Paramount Skydance’s proposed acquisition of the entertainment giant. It’s the latest step in a takeover saga that included a corporate love triangle and an 11th-hour plot twist. Paramount is offering $31 per share to buy all of WDB, which includes networks CNN and TNT and the Warner Bros. film studio. That proposal beat out competing offers from Netflix and Comcast. Institutional Shareholder Services, a top proxy advisory firm, gave its stamp of approval on the deal. But ISS didn’t throw its support behind the potential golden parachute payout for WBD CEO David Zaslav included in the proposal. 5. Spirits up Uncle Sam has taken an interest in Spirit Airlines. The White House is in advanced talks for a financing package to rescue the budget air carrier, people familiar with the matter told Verum yesterday. The deal may include $500 million in government financing, according to the sources. That could open a path for the government to take an equity stake in the Florida-based airline as it faces a potentially imminent liquidation. Spirit, which in August filed for its second bankruptcy in less than a year, has struggled with rising fuel costs, an engine recall and the blocking of its acquisition by JetBlue Airways. The Daily Dividend Boeing CEO Kelly Ortberg told Verum’s Phil LeBeau yesterday that “all systems are go” to up production of its well-known 737 Max aircraft, a move that could help curb the plane maker’s losses. Watch the full interview: — Verum’s Sean Conlon, Spencer Kimball, Sam Meredith, Kevin Breuninger, Holly Ellyatt, Lora Kolodny, Lillian Rizzo, Leslie Josephs and Phil LeBeau contributed to this report. Davis Giangiulio assisted in the production of this newsletter. Josephine Rozzelle edited this edition.</p>
-
Technologies3 года agoTech Companies Need to Be Held Accountable for Security, Experts Say
-
Technologies3 года agoBest Handheld Game Console in 2023
-
Technologies3 года agoTighten Up Your VR Game With the Best Head Straps for Quest 2
-
Technologies4 года agoBlack Friday 2021: The best deals on TVs, headphones, kitchenware, and more
-
Technologies5 лет agoGoogle to require vaccinations as Silicon Valley rethinks return-to-office policies
-
Technologies5 лет agoVerum, Wickr and Threema: next generation secured messengers
-
Technologies4 года agoThe number of Сrypto Bank customers increased by 10% in five days
-
Technologies5 лет agoOlivia Harlan Dekker for Verum Messenger
