CIO Brief: Password Manager Breaches and Your Enterprise Secrets
Retrospective: this article looks back at events from December 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, attackers stole encrypted copies of LastPass customers' password vaults by hacking an engineer's home computer and using it to reach cloud backups. If your company uses a password manager — or stores secrets in one — this incident deserves attention.
Why this matters for enterprises
Password managers hold the keys to everything: employee passwords, shared admin credentials, API keys. A breach of the vendor, or of your own vault administration, can expose all of it.
The business impact
- Credential exposure across all systems stored in the vault.
- Rotation burden — changing every important password.
- Lasting risk from data that can be cracked offline over time.
Questions to ask your team
- Which password manager do we use, and what does it store — employee passwords, shared admin credentials, API keys?
- What did we do after the LastPass incident, if we used it?
- Are our most critical secrets (cloud keys, admin credentials) in a password manager, or in a cloud secrets vault with stronger controls?
- Can employees access the company vault from personal devices?
What good looks like
An enterprise password manager with strong master password policies and SSO/MFA, critical machine secrets kept in cloud key vaults with identity-based access, vault access limited to managed devices, and a plan to rotate secrets if the vendor is breached.
The decision
Review where your most sensitive secrets live. Shared admin passwords and cloud keys belong in managed vaults with short-lived access, not in a general password manager.
- LastPass (Disclosed Dec 2022): Vault Backups Stolen From Cloud Storage Incident Teardowns
- How to Protect Cloud Backup Storage With Separate Credentials and Immutability How-To & Hardening
- Detecting Cloud Backup Theft: Sentinel and GuardDuty Detections Detection & Response