Full-Time
Updated on 9/3/2026
Password management and secure vault solutions
No salary listed
Remote in Canada
Remote
See people who can refer or advise you
LastPass provides password management and secure vaults for individuals and businesses. Its core product is a password manager that securely stores passwords and auto-fills them, reducing breach risk and improving convenience. It also offers secure notes, form filling, and multi-factor authentication to protect data. The service runs on a subscription model with free and premium plans for individuals and customizable enterprise plans with advanced security, administrative controls, and compliance tools. LastPass differentiates itself through ease of use, strong security measures, and a reliable reputation, serving a broad customer base from individuals to large enterprises with robust security features and administrative capabilities. The company aims to simplify protecting online credentials and sensitive information while improving security and user productivity across personal and organizational use.
Company Size
501-1,000
Company Stage
Acquired
Total Funding
$110M
Headquarters
Boston, Massachusetts
Founded
2008
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Generous parental leave
Flexible Paid Time Off
Home Office Stipend
Remote Work Options
Continuous learning and development opportunities
Employee Assistance Program
Remote-first culture
High-growth, collaborative environment with inclusive teams
Market-leading password manager
Peer-to-peer recognition
Short-Term or Remote-Centric Work Arrangements
LastPass enhancements improve visibility, governance, and control. LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company's continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landscape. Highlights include new tools that simplify access management, enhancements that help customers get more value from LastPass, and milestones that demonstrate the company's continued growth and industry leadership. The LastPass commitment to visibility, governance, and control comes at a pivotal moment. According to IBM's 2026 Cost of a Data Breach Report, the average data breach now costs organizations $4.99 million, a record high and 12% increase over last year. The report also found AI-driven attacks increased 56%, adding an average of $1 million to breach costs, and 92% of organizations experiencing AI-related breaches lacked appropriate AI access controls. "As threat actors continue to automate and accelerate their attack tactics, strong identity, credential, and access management have become foundational security requirements, particularly for small and midsize businesses with limited resources," said Karim Toubba, CEO of LastPass. "To address these evolving challenges, LastPass is dedicated to delivering the innovations that help organizations and individuals reduce risk while making security easier to manage." LastPass introduced numerous enhancements across SaaS Monitoring and SaaS Protect within its flagship Business Max offering to help businesses navigate increasingly complex SaaS landscapes with greater visibility, oversight, and confidence. This includes: Always-on SaaS Monitoring: Persistent Monitoring maintains continuous visibility through a permanent connection to the LastPass browser extension, ensuring monitoring remains active even when users are signed out of LastPass. More flexible SaaS Protect controls: Expanded usage rules allow administrators to create more granular policies for specific users or groups, enabling organizations to apply security controls based on their unique needs. Together, these enhancements help organizations accelerate adoption, reduce manual workloads, improve security coverage, and strengthen policy enforcement by giving administrators more control over how and where security policies are applied. As of July, all enhancements have been fully released, including Persistent Monitoring across all browser extensions. LastPass launches Mobile Smart Scanner. With the launch of Mobile Smart Scanner, LastPass empowers businesses and individuals across all product offerings to: * Use the LastPass Mobile app to scan passwords from printed lists, screenshots, handwritten notes, and other physical sources and turn them directly into editable, autofill-ready credentials. * Reduce manual data entry, saving time and minimizing errors. * Simplify password management, keeping credentials secure in encrypted vaults rather than vulnerable on notes or memory. LastPass transforms user experience with enhanced, high-efficiency community platform. Building on its commitment to customer success, LastPass introduced a redesigned Community experience that streamlines how customers discover trusted information, connect with peers, and get more value from the platform. With a more intuitive interface and expanded self-service resources, including topical portals and AI-powered search, the enhanced LastPass Community helps users across all product offerings quickly access the knowledge they need to strengthen security and resolve questions faster. The LastPass Community is part of a broader, integrated self-service strategy designed to meet customers at their point of need - whether that's through the company's branded community or across social platforms like Reddit and LinkedIn. LastPass security and UX improvements. Security and compliance milestone. For the second consecutive year, LastPass successfully completed independent SOC 2 and ISO 27001/27701 audits with zero findings, reinforcing the company's commitment to security and providing customers with assurance that LastPass controls meet globally recognized standards. Dark web monitoring (DWM) auto-enrollment. LastPass has enacted a phased rollout to automatically enroll all consumer accounts in DWM, transitioning the service from a historically opt-in experience to a more proactive protection model. This update helps ensure more customers can benefit from credential exposure monitoring without requiring additional setup, helping users identify potential risks and take action to protect their accounts. Dark web monitoring from LastPass consistently checks user information against databases of compromised credentials, and issues immediate alerts if any personal data is found on dark web sites. With 24/7 monitoring, users can take near real-time action, such as changing their password, to protect themselves. LastPass DWM also notifies users of potential threats like weak passwords, helping them stay ahead of threat actors. Admin console consolidation. LastPass officially completed the transition from its Legacy Admin Console to a single Unified Admin Console, creating a more consistent and streamlined experience for administrators across business offerings. By consolidating management capabilities into one centralized platform, LastPass enables faster product improvements while simplifying how admins manage users, security controls, and access policies. Simplified organization-wide onboarding for all business customers. A new company-wide sign-up link allows Teams, Business, and Business Max customers to onboard their entire organization to LastPass through a single shareable link, reducing administrative effort and accelerating deployment. More about
LastPass expands SaaS security tools with Smart Scanner and Admin updates. LastPass announced a series of product and customer experience updates that expand SaaS visibility, simplify credential management and streamline administration. Aug. 31, 2026 LastPass announced a series of product updates and customer experience enhancements focused on access management, visibility and security as organizations face an increasingly AI-driven threat landscape. The company pointed to findings from IBM's 2026 Cost of a Data Breach Report, which found the average data breach costs organizations $4.99 million. The report also found AI-driven attacks increased 56% and added an average of $1 million to breach costs, while 92% of organizations experiencing AI-related breaches lacked appropriate AI access controls. "As threat actors continue to automate and accelerate their attack tactics, strong identity, credential, and access management have become foundational security requirements, particularly for small and midsize businesses with limited resources," said Karim Toubba, CEO of LastPass. "To address these evolving challenges, LastPass is dedicated to delivering the innovations that help organizations and individuals reduce risk while making security easier to manage." Expanded SaaS Monitoring and SaaS Protect. LastPass expanded its SaaS Monitoring and SaaS Protect capabilities within its Business Max offering. The updates are designed to provide businesses with greater visibility and control over their SaaS environments. Persistent Monitoring maintains continuous visibility through a permanent connection to the LastPass browser extension. This allows monitoring to remain active even when users are signed out of LastPass. The company also expanded SaaS Protect usage rules, allowing administrators to establish more granular policies for specific users or groups. According to LastPass, the enhancements are intended to help organizations accelerate adoption, reduce manual workloads, improve security coverage and strengthen policy enforcement. The company said all of the enhancements had been fully released as of July, including Persistent Monitoring across all browser extensions. Mobile Smart Scanner converts passwords into credentials. LastPass also launched what it describes as the industry's first Mobile Smart Scanner. The feature allows users to scan passwords from printed lists, screenshots, handwritten notes and other physical sources using the LastPass Mobile app. The scanned passwords can then be converted into editable credentials that are ready for autofill. LastPass said the feature is designed to reduce manual data entry, save time and minimize errors while moving credentials into encrypted vaults. Redesigned LastPass Community. The company introduced a redesigned LastPass Community experience intended to make it easier for customers to find information, connect with peers and get more value from the platform. The updated Community includes a more intuitive interface, expanded self-service resources, topical portals and AI-powered search. LastPass said the platform is part of a broader self-service strategy that also includes social platforms such as Reddit and LinkedIn. Security and administration updates. LastPass said it completed independent SOC 2 and ISO 27001/27701 audits for the second consecutive year with zero findings. The company is also rolling out automatic enrollment for Dark Web Monitoring across consumer accounts. The change moves the service from a historically opt-in model toward a more proactive protection approach. Dark Web Monitoring checks user information against databases of compromised credentials and alerts users when personal data is found on dark web sites. The service also notifies users about potential threats such as weak passwords. LastPass has additionally completed its transition from the Legacy Admin Console to a single Unified Admin Console. The consolidated platform brings management capabilities into one centralized environment for administrators across business offerings. For Teams, Business and Business Max customers, LastPass has introduced a company-wide sign-up link that allows organizations to onboard their entire workforce through a single shareable link. The company said the change is intended to reduce administrative effort and accelerate deployment. Enterprise businesses generate large amounts of visual data from their video surveillance systems. Unfortunately, much of this data goes unused. Find out how businesses can optimize workflows by using AI video security to uncover hidden insights. Security frontline. The source of news, analysis and information specifically for security executives. Subscribe Today!
LastPass hit again: what users need to know about the latest breach. By: Jim Stickley and Tina Davis August 2, 2026 Password management company LastPass is once again notifying customers about a security incident involving exposed user information. According to the company, the latest breach did not occur directly on LastPass systems. Instead, attackers reportedly gained access to customer information through a compromise at Klue, a third-party software provider used by LastPass. The stolen data is believed to include customer support case information and certain personal details submitted by users while seeking assistance. At the time of disclosure, LastPass said there was no evidence that encrypted password vaults, master passwords, or stored credentials were accessed during the incident. However, security experts warn that even limited personal information can be valuable to cybercriminals. For users, the biggest concern is the increased risk of phishing attacks. Criminals may use information obtained from support tickets to create convincing phishing emails, text messages, (smishing) or phone calls (vishing) that appear to come from LastPass. If you use LastPass, be especially cautious of unexpected communications requesting login credentials, multi-factor authentication codes, or account information. You should never give these out to anyone. Never click links in unsolicited emails claiming your account needs immediate attention. Instead, visit the LastPass website directly through your browser. Remember that using a password manager, no matter which one it is, comes with a risk of your information being used to steal all of your passwords stored in them. That said, if there really is no other way you can keep track of using one password per website, proceed with caution. Whatever you do, make sure your master password is most definitely unique. Users should also enable multi-factor authentication, review account activity regularly, and ensure their master password remains unique and strong. Staying alert may be the best defense against criminals looking to turn stolen support data into a much larger security problem. The identity of the attackers has not been officially confirmed, some believe it was the group Icarus, a newly established extortion group. They also claim to have stolen information from several other companies. Investigators are still examining the incident, and no public attribution has been announced. However, the breach follows a series of security incidents that have kept LastPass under intense scrutiny since its major 2022 compromise.
LastPass Authenticator adds Face ID, Apple Watch, cloud backup for 2FA. Post Views: 7 LastPass Authenticator is a free application designed to deliver two-factor authentication (2FA) for user accounts and services that utilize time-based one-time passwords (TOTP). Enrollment process. The setup for new accounts is streamlined, allowing users to scan a QR code, import one from a saved image in the device's photo library, or manually input a secret key. To simplify configuration, the application provides preconfigured templates for numerous online services, such as Amazon, Amazon Web Services, Binance, Coinbase, Discord, Dropbox, Evernote, GitHub, PayPal, Slack, Twitch, and X. Custom entries can also be created for any service that employs TOTP authentication. * Amazon * Amazon Web Services * Binance * Coinbase * Discord * Dropbox * Evernote * GitHub * PayPal * Slack * Twitch * X The interface displays accounts in a searchable format, featuring service icons, account names, and a timer indicating when the current verification code will expire. Users can modify account details, categorize entries into groups, and manage multiple authenticators through a unified dashboard. The app supports transferring accounts between devices and exporting them as QR codes for backup purposes. Security measures. To safeguard locally stored authentication data, the application offers multiple protective features. Users can secure the app using biometric authentication via Face ID or a personal identification number (PIN). The Tap to Reveal function ensures verification codes remain concealed until accessed. Cloud backup capabilities allow users to restore accounts after replacing or resetting a device. A built-in Security Checkup feature reviews account settings to ensure optimal protection. Additional functionalities. Verification codes can be extracted directly from screenshots stored on the device, eliminating the need to switch between devices during setup. Users can preview the next authentication code before the current one expires, customize the display location of upcoming codes, and group digits for improved readability. * Extract verification codes from screenshots * Preview next authentication code * Customize display location of upcoming codes * Group digits for improved readability Conclusion. The integration of standard TOTP authentication with push-based approvals, biometric security, cloud backup, Apple Watch compatibility, and flexible import options positions LastPass Authenticator as a comprehensive tool for managing two-factor authentication across multiple online services through a centralized application.
LastPass has disclosed another data breach, this time affecting customer contact information and support data. The breach resulted from a compromise at AI business intelligence firm Klue, where attackers stole access tokens for Klue customers, including LastPass, and used them to extract data from Salesforce and other platforms. The stolen information includes names, phone numbers, email addresses, physical addresses, support case data and sales-related information. LastPass emphasised that its own infrastructure was not breached and password vaults remain secure. The company warned customers to remain vigilant against potential phishing attacks leveraging the exposed contact details. This incident adds to LastPass's series of significant data breaches in recent years. The company advised users to exercise caution regarding unsolicited communications requesting sensitive information.