Users of the password manager LastPass have been experiencing significant login issues since early May, after being asked to reset their authenticator apps.

The company first announced that users may need to log back into their LastPass accounts and reset their multi-factor authentication preferences due to planned security upgrades on May 9th.
However, since then, many users have been locked out of their accounts and unable to access their LastPass vault, even after successfully resetting their MFA apps (e.g. LastPass Authenticator, Microsoft Authenticator, Google Authenticator).
Compounding the problem, affected customers are unable to request assistance from support, as contacting LastPass support requires logging into their accounts, which they are unable to do because they are locked in an endless loop being asked to reset their MFA authenticator.
“Forcing MFA resync is now preventing me from logging in because LastPass doesn't recognize the new MFA password,” one user said.
“After resetting my MFA, I completely lost access to my Vault. MasterPW is not working and the reset, as well as the reset eMail is never delivered to me. I am unable to contact “Premium” Support as it requires a login,” added another.
“I was asked to re-enter my master password and then had to update MFA, which I did successfully and now I can’t log in at all,” said one user, asking for help on the LastPass community website.
LastPass says that MFA resets were announced via in-app messages for “several weeks” before the initial announcement.
The company has released several advisories regarding the security upgrades, explaining that it is increasing password attempts to the new default of 600,000 rounds.
“To increase the security of your master password, LastPass uses a stronger-than-standard version of the Password-Based Key Derivation Function (PBKDF2),” as explained in a LastPass support ticket sent to affected users.
In its most basic form, PBKDF2 is a “password strengthening algorithm” that makes it difficult for a computer to verify that any password is the correct master password during a brute-force attack.
In another advisory, the company says that users are being asked to re-enroll in multi-factor authentication for their security when logging into LastPass.
“You must log in to the LastPass website in your browser and re-enroll in the MFA app before you can access LastPass again from your mobile device. You cannot re-enroll using the LastPass browser extension or the LastPass Password Manager app,” the company explains
The detailed process required to reset the pairing between LastPass and your authenticator app (LastPass Authenticator, Microsoft Authenticator, or Google Authenticator) is detailed in this support document.
The next time you log in to a website or app using LastPass, you will be asked to verify your location. When you log in to a website or app where you used LastPass to log in, you will need to re-enter your credentials and verify your identity using the authenticator app .
Users will also be prompted to verify their location the next time they log in to a website or app that uses LastPass as an added security measure.
As part of the same process, users will need to re-enter their login credentials and authenticate themselves once again using the authenticator app.
Information source: bleepingcomputer.com
