LastPass published an update on their breach, which some speculate was timed to minimize news coverage. The company's statement is criticized for containing omissions, half-truths, and lies, and for trying to shift blame to customers. The breach is attributed to LastPass's failure to contain the initial breach in August 2022. The company's security practices, such as not encrypting website URLs and using insufficient password protection, are also called into question.