
LastPass remains one of the most recognized password managers, serving individual users, small businesses, and larger organizations that need a centralized way to store, manage, and share credentials. Consumers use the platform to generate stronger passwords, autofill logins, and synchronize credentials across devices, while businesses rely on it for employee access controls, password sharing, multifactor authentication, and administrative oversight. In recent years, LastPass has also expanded into passkeys, SaaS monitoring, SSO, and broader secure-access tools as organizations look for ways to manage credentials across a growing number of cloud applications and AI services.
The company’s position is shaped by both scale and scrutiny. LastPass continues to serve millions of users and more than 100,000 businesses, but the effects of its 2022 security incidents still influence customer trust, regulatory attention, and competitive comparisons. At the same time, rising adoption of password managers and passkeys is changing how consumers and enterprises approach authentication. The statistics in this article examine LastPass’s users, market position, pricing, financial history, security incidents, enterprise adoption, reputation, and future outlook.
Editor’s Choice
- More than 100,000 businesses worldwide use LastPass, according to current company disclosures carried into 2025 and 2026.
- Current product pages cite more than 79,300 combined Chrome and App Store reviews, providing a sizable public-feedback base for the product.
- The same current product material references more than 1,599 software-review submissions supporting its password-management positioning.
- LastPass collected 72 badges in the Summer 2026 software grid reports, spanning password management and related authentication categories.
- Its partner ecosystem included more than 10,000 resellers, managed service providers, and distributors by March 2025.
- Among surveyed partners, 91% said they planned to renew their LastPass licenses, indicating high partner retention intent in 2025.
- In the same partner data, 88% described LastPass as trustworthy, an important metric given the company’s continuing efforts to rebuild confidence after its earlier security incidents.
Recent Developments
- On Feb. 10, 2026, LastPass appointed Chris Michelmore as chief revenue officer, placing him in charge of global business-to-business sales and acquisition strategy. He joined after more than a decade in revenue leadership at Zoom Communications.
- On March 10, 2026, the company formally expanded its positioning beyond password management with Secure Access Essentials, adding a broader focus on application, AI tool, and credential access.
- That March announcement cited an industry forecast that 75% of employees could acquire, modify, or create technology outside IT visibility by 2027, compared with 41% in 2022. This trend helps explain the company’s move into SaaS and AI access monitoring.
- On April 28, 2026, LastPass announced another wave of secure-access capabilities aimed at lean IT teams, with a focus on discovering unapproved SaaS and AI tools through browser-based workflows.
- On May 5, 2026, LastPass introduced Mobile Smart Scanner in early access for Free, Premium, and Families users. A single scan can extract three core credential fields, site URL, username, and password, from typed or handwritten information.
- By May 26, 2026, LastPass ranked No. 1 among small-business password managers in a Summer 2026 customer-review grid, while also receiving recognition in passwordless and biometric authentication categories.
- On June 16, 2026, LastPass launched a redesigned community platform that consolidated discussions, support material, and educational resources into topical hubs.
- On July 27, 2026, the company’s new Admin Console became the only available console for business customers as the legacy console was retired.
- An Aug. 18, 2026 Admin Console release introduced a policy that allows administrators to prohibit users from creating shared folders, adding another centralized access-control option.
- The desktop product reached version 2.2.0 on Aug. 17, 2026, introducing an administrator policy for disabling application launch alongside other fixes and improvements.
LastPass Market Share and Adoption
- In the 2026 financial-adviser software survey, LastPass held 17.79% market share, the highest figure among the password-management products measured.
- In the comparable 2025 survey, LastPass held 21.43% share, meaning its measured adoption declined by 3.64 percentage points year over year.
- The year-over-year move represented a relative decline of approximately 17% in LastPass’s measured share among respondents, even though it remained the category leader.
- LastPass’s 2026 share was more than twice the 8.53% share recorded by the second-place password-management product in the same study.
- Users gave LastPass an average 8.48 out of 10 rating in the 2026 study, matching the overall category average.
- Its prior-year average rating was 8.28 out of 10, so user satisfaction increased by 0.20 points even as measured adoption declined.
- Password-management tools reached 42.72% total category penetration among surveyed advisers in 2026, down from 46.05% in the prior-year study.
- The 2026 research drew on 2,906 valid responses collected from November 2025 through the first half of February 2026, giving the market-share comparison a substantial professional-user sample.
- The study tracked 14 named password-management options before counting additional write-in products, highlighting how fragmented the competitive market has become.

LastPass User Statistics
- LastPass describes its current consumer base as millions of customers, although it no longer publishes a precise current total for registered users. Therefore, older claims of a specific user count should not be treated as an audited 2026 figure.
- In 2023, after completing its investigation into the 2022 incidents, LastPass said it served millions of users, confirming that its consumer footprint remained substantial even during the breach-response period.
- The iOS application supports three Apple device classes, iPhone, iPad, and Apple Watch, broadening the ways consumer accounts can access saved credentials.
- The iOS listing supports English plus seven additional languages, indicating localized distribution across several non-U.S. markets.
- The iOS application was approximately 200 MB in its current listing, reflecting the size of the full mobile client rather than the much smaller browser extension.
- LastPass released mobile passkey support to all mobile users in September 2025, expanding user accounts beyond stored passwords to passkey-based authentication on compatible services.
- Among channel partners surveyed in 2025, 90% reported high satisfaction with LastPass’s product capabilities and vendor experience. That metric reflects organizations distributing or supporting the product rather than end consumers.
- Another 83% of surveyed partners said LastPass was critical to their success, showing significant dependence on the product among parts of its channel ecosystem.
- LastPass’s current autofill ecosystem covers five major browsers, Chrome, Firefox, Edge, Safari and Opera, as well as desktop and mobile platforms. This cross-platform reach supports users who maintain credentials across multiple device types.
LastPass Data Breach Statistics
- During the first 2022 incident, the attacker gained access to 14 of roughly 200 software repositories, or about 7% of the repositories referenced in the later investigation.
- The first intrusion involved a compromised developer endpoint and remained active for a reported four-day period before the activity was detected and contained.
- The second attack reached cloud backup storage containing backups of all customer vault data, although sensitive vault fields remained encrypted under the company’s zero-knowledge design.
- Sensitive vault fields used 256-bit AES encryption. However, some accompanying information, including stored website URLs, was not encrypted in the stolen backups.
- The stolen information also included customer account metadata such as names, billing addresses, email addresses, telephone numbers and IP addresses, increasing potential phishing and social-engineering exposure.
- At one stage of the 2022 response, LastPass said it had contacted a subset representing less than 3% of business customers because their configurations required specific additional actions.
- By March 1, 2023, LastPass said investigators had detected no threat-actor activity after Oct. 26, 2022, marking the end of the activity observed during its forensic review.
- The second incident also exposed a backup of the MFA and federation database containing authenticator seeds and phone numbers where the MFA backup option had been enabled. The database itself was encrypted, but its separately stored decryption key was among secrets accessed by the attacker.
- In June 2026, LastPass disclosed a separate third-party supply-chain incident in which stolen OAuth tokens provided unauthorized access to customer-related information in its Salesforce environment. LastPass said its password vaults, products and core infrastructure were not accessed.
- The 2026 third-party incident exposed CRM information including customer names, phone numbers, email addresses, physical addresses, support-case information and sales-related data, but the company reported no evidence of access to connected Gong data.
LastPass Revenue Growth Trends
- LastPass estimated revenue shows a strong and consistent upward trend, increasing from approximately $300 million in 2022 to $500 million in 2026, an overall gain of $200 million, or about 66.7%, across the four-year growth period.
- In 2023, LastPass estimated revenue climbed to $350 million, marking an increase of $50 million, or roughly 16.7%, compared with the estimated $300 million generated in 2022.
- Revenue continued to expand in 2024, reaching an estimated $400 million, which represented another $50 million year-over-year increase and placed the company $100 million above its 2022 revenue level.
- By 2025, LastPass estimated revenue had advanced to $450 million, meaning the company added approximately $150 million in annual revenue compared with 2022, reflecting sustained growth across the period.
- LastPass estimated revenue reached $500 million in 2026, the highest figure shown in the dataset and approximately 1.67 times its 2022 level, highlighting the scale of the company’s estimated revenue expansion.
- Across 2022 to 2026, LastPass added an estimated $50 million in revenue every year, demonstrating an unusually consistent annual growth pattern and translating to a compound annual growth rate of approximately 13.6%.

LastPass Security Incident Timeline
- LastPass first detected unusual activity in its development environment in August 2022 after an attacker compromised a single developer account and obtained source code and proprietary technical information.
- The initial attacker activity lasted four days before the security team detected and contained it. The investigation found no evidence that the first incident directly accessed customer vaults.
- On Aug. 25, 2022, LastPass publicly disclosed the development-environment incident, roughly two weeks after it initially detected the unusual activity.
- By Sept. 15, 2022, forensic investigators had completed their review of the first incident and confirmed that the attacker used a compromised developer endpoint.
- The attacker later used information obtained during the first breach to target another employee, ultimately acquiring credentials and keys that provided access to cloud-based backup storage.
- On Nov. 30, 2022, LastPass announced that it had detected unusual activity in a third-party cloud storage service and confirmed that information from the August attack had contributed to the new compromise.
- On Dec. 22, 2022, the company disclosed that the second attack exposed both encrypted vault backups and unencrypted customer-account information.
- The later forensic investigation traced the broader incident window from August through November 2022. That same period now defines the incident covered by the 2026 U.S. settlement.
- The litigation that followed ultimately consolidated 14 named class representatives into one federal action in Massachusetts.
- By 2026, the breach had produced separate U.S. and Canadian settlements, extending the financial and legal consequences almost four years after the original intrusion.
LastPass Customer Impact and Compensation
- The proposed U.S. settlement created an $8.2 million fund for eligible people and organizations affected by the 2022 incident.
- Eligible U.S. class members could claim up to $300 for documented ordinary losses, including qualifying expenses related to identity protection, monitoring, and security services.
- People who could document qualifying extraordinary losses tied to the breach could seek as much as $10,000 under the settlement.
- Alternatively, qualifying account holders could elect a $25 statutory cash payment instead of seeking reimbursement for documented losses.
- California residents who qualified could receive an additional $100 statutory payment under provisions associated with California privacy law.
- Consumer Free users covered by the settlement could receive a complimentary six-month Premium upgrade, while the agreement also provides dark web monitoring services for users.
- The U.S. claim deadline was July 2, 2026. The settlement portal now states that claim submissions have closed.
- Canada reached a separate settlement worth $3 million in U.S. dollars, covering eligible Canadian residents affected by the breach.
- A Canadian court granted final settlement approval on Feb. 18, 2026, and the claims period ran from March 25 through June 23.
- Combined, the publicly announced U.S. and Canadian settlement funds total $11.2 million, before considering noncash benefits offered through the U.S. agreement.
LastPass Revenue Drivers by Subscription Tier
- LastPass Business / Enterprise is the highest-priced tier at $6 per user per month, targeting large IT deployments and organizations requiring Identity and Access Management (IAM).
- LastPass Teams costs $4 per user per month, positioning it as a lower-cost business option for SMBs and Managed Service Providers (MSPs).
- LastPass Families is priced at $4 per month, offering a household-focused subscription rather than a per-user business pricing model.
- LastPass Premium is the lowest-priced paid tier at $3 per month, primarily targeting individual power users seeking additional password-management features.
- The pricing structure ranges from $3 to $6 per month, with business-oriented plans commanding higher per-user rates than consumer subscriptions.
- Business and Teams subscriptions can generate progressively more revenue as organizations add users, while Families and Premium rely primarily on fixed consumer subscription fees.

LastPass Password Manager Usage Trends
- A nationally representative May 2025 survey of 2,333 U.S. adults found that 42% used a password manager that creates and stores strong passwords.
- Password-manager adoption rose from 36% in 2024 to 42% in 2025, a gain of six percentage points in one year.
- Despite that increase, password managers remained the least commonly reported security practice among the six password-related measures tracked in the 2025 survey.
- 81% of Americans surveyed in 2025 said they used multifactor authentication on at least one online account, up from 80% in 2024 and 76% in 2023.
- 65% of U.S. adults reported using unique passwords across different accounts in 2025, unchanged from 2024 and below the 67% measured in 2023.
- Another U.S. survey found 44% of respondents using a password manager, broadly consistent with the 42% figure from the nationally representative 2025 research.
- In that survey, 49% of U.S. respondents still relied on memory to manage passwords, showing why dedicated password-manager adoption has room to grow.
- About 41% of Americans in the same research managed passwords across 10 to 25 websites, creating a sizable credential-management burden for many users.
- 33% of U.S. respondents reported reusing passwords across five to 10 sites, despite widespread awareness of credential-security risks.
- In a 2026 U.S. survey, only 16% said they used a unique password for every account; 20% reused the same password across most or all accounts, while another 32% reused passwords with slight variations.
LastPass Geographic User Distribution
- Approximately two-thirds of LastPass B2B customers are in North America, making the region its largest disclosed commercial market.
- The U.S. accounts for most of that North American footprint, while Canada and Mexico also represent notable commercial markets.
- Europe represents another major LastPass market, with the U.K., Switzerland and France identified as particularly important countries in company briefing material.
- In Asia-Pacific, Australia, New Zealand, India and Japan have been identified as key markets, while the company’s APAC workforce has continued to expand.
- Brazil stands out as an important LastPass market in South America, giving the company’s business footprint reach across at least four major geographic regions.
- Historical enterprise telemetry found that 14.2% of U.S. businesses in the dataset had employees using LastPass on iOS, the highest iOS share among the countries reported.
- New Zealand led Android adoption in that enterprise dataset at 11.1%, compared with 7% for the U.S.
- Sweden recorded 13.3% iOS and 9.5% Android usage, while Switzerland recorded 13.8% and 8.8%, respectively, demonstrating meaningful mobile use outside North America.
- Australia recorded 12.4% iOS and 8.5% Android usage in the enterprise dataset; a 2026 Australian accounting-firm case study separately documented 100% LastPass adoption among roughly 20 employees.
- Mobile onboarding correlated with approximately 30% higher user retention on average in the historical enterprise analysis, suggesting that geographic markets with stronger mobile adoption can also benefit from higher continuing usage.
LastPass Adoption by Business Size
- Enterprise businesses lead LastPass adoption at 35%, showing that larger organizations are the most prominent users of the password manager across the four business segments analyzed.
- Mid-market companies report a 24% adoption rate, placing them second and 11 percentage points behind enterprises, while still maintaining substantially higher adoption than smaller businesses.
- SMBs have a 14% LastPass adoption rate, which is 21 percentage points below enterprise adoption, highlighting a sizable adoption gap between small businesses and large organizations.
- Micro-SMBs record the lowest LastPass adoption rate at 11%, although they trail the broader SMB segment by only 3 percentage points.
- Overall, the figures reveal a clear business-size trend, with LastPass adoption rising from 11% among micro-SMBs to 35% among enterprises, a difference of 24 percentage points.

LastPass Feature Adoption Statistics
- Passkey support reached general availability on Aug. 20, 2025, allowing customers to create, store, and manage passkeys alongside traditional passwords across supported devices and browsers.
- Mobile Smart Scanner entered early access on May 5, 2026, for Free, Premium, and Families customers before expanding further.
- By June 17, 2026, Mobile Smart Scanner had become generally available to all customers, including business users, expanding the feature beyond its initial consumer rollout.
- Smart Scanner currently imports one credential per scan. It converts either typed or handwritten password information into a vault entry without retaining the photographed image.
- Each Smart Scanner capture can extract three core fields: the website URL, username and password, and prepare them for autofill.
- Business customers can configure more than 100 advanced security policies, covering password behavior, access controls, administration, and related security settings.
- The standard Business plan includes three SSO applications, while Business Max supports an unlimited number of SSO applications.
- In July 2026, SaaS Monitoring gained persistent monitoring, allowing administrators to track application usage even while an employee is logged out of the browser extension. The same release also added editable usage rules for SaaS Protect.
- The July 2026 release also added a bulk onboarding workflow in which administrators can generate one sign-up link for multiple users and then approve or decline individual responses from the Admin Console.
LastPass Trust and Reputation Metrics
- A major business-software review dataset listed 2,087 LastPass reviews in September 2026, providing one of the larger structured samples of current business-user sentiment.
- Across those reviews, LastPass held an average rating of 4.5 out of 5, indicating strong overall satisfaction among that platform’s respondents.
- Approximately 75% of ratings in that dataset awarded LastPass five stars.
- Another 17% awarded four stars, meaning about 92% of recorded ratings fell into the four- or five-star categories.
- Three-star reviews accounted for roughly 3%, while two-star ratings represented about 1%.
- One-star ratings accounted for approximately 2% of the business-software review dataset.
- In contrast, an open consumer-review channel showed an overall score of only 1.4 out of 5 from about 930 reviews in September 2026, demonstrating a substantial gap between review populations.
- On that consumer-review channel, 80% of reviews were one-star, compared with 7% at five stars, 2% at four stars, 3% at three stars, and 8% at two stars.
- LastPass also collected 72 software-review badges in Summer 2026, including recognition in password management, passwordless authentication, and biometric authentication categories.
LastPass Customer Satisfaction Highlights
- 93% of customers said LastPass meets their requirements, making it the strongest satisfaction metric and indicating a high level of alignment with user needs.
- 89% of users reported they are likely to recommend LastPass, suggesting that nearly nine in 10 customers have a positive enough experience to endorse the service.
- Ease of use also scored 89%, showing that LastPass performs strongly on usability alongside its recommendation rating.
- Quality of support received an 85% rating, indicating generally strong customer satisfaction with the assistance and support provided by LastPass.
- 83% of respondents believed LastPass is heading in the right direction, the lowest of the five metrics but still representing more than four in five respondents.
- Overall, every measured satisfaction indicator was above 80%, while the gap between the highest and lowest ratings was only 10 percentage points.

LastPass Regulatory Fines and Penalties
- On Nov. 20, 2025, a U.K. privacy regulator issued LastPass UK Ltd. a monetary penalty of £1,228,283 over security failures linked to the 2022 breach.
- The regulator said the security failures contributed to the exfiltration of personal information associated with approximately 1.6 million U.K. customers.
- Based on those figures, the penalty equated to roughly £0.77 per affected U.K. customer, although the fine itself was based on regulatory findings rather than a per-person compensation formula.
- The enforcement action cited violations of two UK GDPR provisions: Article 5(1)(f), concerning integrity and confidentiality, and Article 32(1), concerning security of processing.
- The regulator concluded that inadequate technical and organizational measures allowed attackers to access a backup database containing customer information.
- The enforcement findings traced the compromise to two connected 2022 incidents, an initial attack involving a corporate laptop and a subsequent compromise involving a U.S.-based employee’s personal computer.
- Despite the regulatory violation, investigators found no evidence that encrypted customer passwords were decrypted, because sensitive vault contents remained protected by the zero-knowledge encryption design.
- At approximately £1.23 million, the penalty was far below the U.K. GDPR’s maximum fixed statutory level of £17.5 million, though actual maximum penalties can also depend on worldwide turnover.
- The fine arrived more than three years after the August 2022 intrusion, showing how regulatory exposure from a major cybersecurity incident can continue long after technical containment.
LastPass Security and Encryption Statistics
- Vault data currently uses AES-256 encryption, a 256-bit symmetric encryption standard widely used for protecting sensitive digital data.
- LastPass now applies at least 600,000 PBKDF2-SHA-256 iterations to derive the user’s encryption key for new accounts and accounts updated to the current setting.
- After deriving the encryption key, the system performs one additional hashing iteration to create a separate authentication construct used during login.
- Current account creation rules require a master password of at least 12 characters, including at least one uppercase letter, one lowercase letter, one number, and one special character.
- Encryption and decryption take place locally on the user’s device, meaning the plaintext master password is not stored on company servers under the zero-knowledge architecture.
- Current security disclosures list at least six major third-party compliance or assurance frameworks, including ISO 27001, SOC 2 Type II, SOC 3, BSI C5, TRUSTe, and FIDO2-related certification.
- The company also holds ISO 27701 certification for privacy information management, supplementing its broader information-security certification program.
- Post-breach security restructuring included the creation of eight security-focused teams, alongside a move toward a redesigned cloud-native security infrastructure.
- Its secure software development program reports compliance across all three levels of its stated SLSA implementation, combined with software bill of materials tracking.
LastPass vs. Competitors: Global Password Manager User Share
- LastPass holds an 11% global user share among individual consumers, making it the second-most-used password manager in this comparison.
- Apple iCloud Keychain leads the market with a 23% user share, more than double LastPass’s 11% share.
- LastPass narrowly outpaces Bitwarden, which accounts for 10% of global password manager users.
- The gap between LastPass and Bitwarden is just 1 percentage point, indicating close competition between the two services.
- LastPass has more than twice the user share of 1Password, which represents 5% of individual password manager users.
- Compared with Keeper’s 3% share, LastPass has nearly four times the user share, highlighting its stronger consumer adoption.
- The five password managers shown collectively account for 52% of global user share, with Apple iCloud Keychain and LastPass together representing 34%.

LastPass Future Outlook and Projections
- An estimated 5 billion passkeys were in active use worldwide by May 2026, indicating that passwordless authentication has moved beyond early adoption.
- Global consumer awareness of passkeys reached 90% in 2026, compared with 74% in a 2025 international survey.
- About 75% of consumers surveyed in 2026 had enabled a passkey on at least one account, up from 69% among respondents in the 2025 research.
- Regular usage still trails setup: 49% of consumers said they regularly use passkeys when the option is available, leaving a 26-percentage-point gap between enabling and routine use.
- Enterprise deployment is also scaling. About 68% of organizations surveyed in 2026 had deployed, were deploying, or were piloting passkeys for employee authentication.
- 82% of organizations identified fully passwordless workforce authentication as an ultimate goal, although only 28% reported that they had already achieved it.
- Organizations that had implemented passkeys reported several measurable benefits: 47% cited stronger security confidence, 45% faster employee logins, 43% better employee satisfaction with IT, 35% fewer password-reset tickets, and 32% fewer phishing-related incidents.
- However, 57% of organizations still relied on phishable authentication methods for employees’ primary daily sign-ins in 2026, suggesting that password managers will continue serving as a bridge between password-based and passwordless environments.
- The broader threat environment strengthens the case for that transition: a major 2025 breach study found credential abuse accounted for 22% of initial attack vectors, while roughly 60% of confirmed breaches involved a human element.
- LastPass’s move into SaaS and AI governance also aligns with wider decentralization of technology ownership. Current research indicates an average of 15.3% of technology solutions already originate outside centralized IT, while 80% of technology executives expect AI to increase business-developed solutions by 2030.
Frequently Asked Questions (FAQs)
More than 100,000 businesses use LastPass, while the company describes its overall customer base as numbering in the millions.
LastPass Business costs $7 per user per month after a 14-day free trial.
The U.S. settlement includes an $8.2 million settlement fund, with eligible extraordinary-loss claims reaching $10,000 per person and validated cryptocurrency-loss claims reaching as much as $900,000 per claimant, subject to a separate aggregate cap.
A U.K. regulator imposed a £1,228,283 penalty in November 2025 after finding security failures associated with personal data relating to approximately 1.6 million U.K. customers.
LastPass earned 72 badges in the Summer 2026 software grid reports and ranked No. 1 for Small-Business Password Management in the reported category.
Conclusion
LastPass enters late in the year as a large password-management provider that is gradually evolving into a broader secure-access platform. Its continued presence among millions of users and more than 100,000 business customers gives it meaningful scale, while new capabilities such as passkeys, SaaS monitoring, SSO, and centralized administrative controls show how the product is adapting to changing authentication needs. Technical measures including AES-256 encryption, 600,000 PBKDF2-SHA-256 iterations, and expanded security programs also reflect the company’s effort to strengthen its security architecture after the 2022 breach.
However, LastPass still faces significant reputational and regulatory challenges. The breach settlements, the £1.23 million U.K. penalty, and sharply different customer-review scores show that rebuilding trust remains an important part of its long-term outlook. At the same time, the wider authentication market is moving quickly toward passkeys and passwordless access, with billions of passkeys already in use and a growing share of organizations deploying them for employees. LastPass’s future performance will therefore depend on how effectively it balances traditional password management with stronger security, improved customer confidence, and the broader shift toward passwordless authentication.