LastPass confirms credential stuffing attack against some of its users


Been using it for a few years and love it. My wife and I share an account so she can access any account if something happens to me. I also setup both my parents and my in laws (non-technical folks) and have only heard good things.

Thinking about this specific issue, one thing I really appreciate about Dashlane is that it requires you to provide your MFA code on a new device BEFORE you’re prompted for your master password. Not sure if LastPass is the same way, but this means someone needs to get my randomly generated MFA code before they can even take a whack at my master password.

