LastPass says there is no evidence of a data breach after users reported being notified of unauthorized login attempts, as reported by AppleInsider. The password manager maintains that it has never been breached and that user accounts are not accessible to malicious actors.

See also: Phishing incident causes data breach at West Virginia hospitals
Nikolett Bacso-Albaum, senior director of LogMeIn Global PR, initially told The Verge that the notifications users received were related to “fairly common bot-related activity,” including malicious attempts to log into LastPass accounts using email addresses and passwords that hackers had in their possession from previous breaches of third-party services (i.e., not LastPass).
“It is important to note that we have no indication that accounts were successfully accessed or that the LastPass service was otherwise compromised by an unauthorized party,” Basco-Albaum said. “We regularly monitor for this type of activity and will continue to take measures designed to ensure that LastPass, its users, and their data remain protected and secure.”
See also: Frontier Software hack: Data breach affects thousands of Australian government employees
However, late Tuesday night, LastPass VP of Product Management Dan DeMichele released a statement to The Verge with a more detailed explanation, saying that at least some of the notifications were “likely triggered accidentally,” due to an issue that LastPass has now resolved.
As previously mentioned, LastPass is aware of and investigating recent reports of users receiving emails notifying them of blocked login attempts.

Reports began appearing on the Hacker News forum after a LastPass user created a post to highlight the issue. He claims that LastPass alerted him to a login attempt from Brazil using his master password. Other users quickly responded to the post, noting that they had experienced something similar. As the original poster (@technology_greg) points out in a tweet, some were alerted to a login attempt from Brazil, while other attempts were detected in different countries. This, understandably, raised concerns that a breach had taken place.
See also: Cox reveals it is a victim of a data breach
Even if LastPass wasn't actually hacked, it's a good idea to strengthen your account with multi-factor authentication, which uses external sources to verify identity before you log in to your account.
Source of information: theverge.com
