{"id":7029434,"date":"2026-08-06T02:13:22","date_gmt":"2026-08-06T02:13:22","guid":{"rendered":"https:\/\/peraltafinancing.com\/business\/investing\/what-happens-if-my-password-manager-gets-hacked-oblivious-investor\/"},"modified":"2026-08-06T02:13:22","modified_gmt":"2026-08-06T02:13:22","slug":"what-happens-if-my-password-manager-gets-hacked-oblivious-investor","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=7029434","title":{"rendered":"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Password manager providers are naturally attractive targets for hackers. So a critical question to ask is: what happens if an attacker manages to access the servers of the company that provides your password manager software? And the answer to that question will depend on both your own practices as well as the policies and practices of the password manager provider.<\/p>\n<p>Here it\u2019s worth backing up a step and looking at historical security breaches in general. For instance, there have been many cases in which some company (e.g., an insurance company, a credit bureau, a hospital system, or a large retailer) gets hacked, and the attacker is ultimately able to access customer\/patient information, such as contact info and Social Security numbers.<\/p>\n<p>But wouldn\u2019t that data have been encrypted on the company\u2019s servers? In other words, even if the attacker was able to download the data, why weren\u2019t they stuck with unusable encrypted data? Sadly, in some cases, the answer is that no, the data in fact was not encrypted on the company\u2019s servers. But even in many cases in which the data <em>was<\/em> encrypted, the attacker was ultimately able to decrypt the data. Generally, that\u2019s not because the attacker was able to defeat the encryption. (Modern best-practice encryption is quite secure.) Rather, the explanation is a simpler one: the attacker was able to access the decryption keys.<\/p>\n<p>In most cases, when a company is storing encrypted data, they also need to be able to <em>decrypt<\/em> that data themselves, so that they can use the data when needed. So the decryption keys must be accessible in some way by systems (and sometimes people) at the company. And that is where the security often fails. In the major data breaches that you\u2019ve heard about, what has generally been the case is that the decryption keys were stored in some way that was itself insecure, or the attackers were able to access an application that has access to the keys. The details vary, but the result is typically that the attacker is able to download the encrypted data <em>and<\/em> access the decryption keys, thereby allowing them to simply decrypt the data.<\/p>\n<p>Now back to our discussion of password manager software specifically. The details vary by provider, but many password managers (including Bitwarden or 1Password) use what is known as <strong>zero-knowledge architecture<\/strong>. The idea of zero-knowledge architecture is that the password manager provider itself never has your master password, the key necessary to decrypt your data, or a decrypted version of your usernames, passwords, etc. Your encrypted vault is stored on their servers, and when the vault needs to be decrypted (in order for you to access saved information) that decryption happens entirely on <em>your<\/em> device. Your device uses your master password to derive the decryption key and then uses that decryption key to decrypt the requested data. To reiterate: with zero-knowledge architecture, the password manager provider never has your master password, the decryption key, or a decrypted version of your vault.<\/p>\n<p>What this means is that, if your password manager is using zero-knowledge architecture with strong encryption practices, and you are using a strong master password, then even if an attacker were able to breach the password manager\u2019s servers and download your encrypted vault, they would almost certainly not be able to decrypt the information. There\u2019s a fundamental difference here between this sort of setup and a setup in which the company is saving not only your encrypted data but also the means to decrypt that data.<\/p>\n<p>Of course, it would still be preferable for your password manager provider <em>not<\/em> to be hacked at any point. And if you ever learn that your password manager provider <em>has<\/em> suffered a breach involving customer vaults, you should promptly change the passwords of your most important accounts, and then change the remaining passwords as soon as practical. But if you and your password manager are both following best practices, you don\u2019t need to worry that a data breach would mean that an attacker would immediately have access to all of your passwords.<\/p>\n<p>There are also options for offline password managers. For instance, KeePassXC is a dedicated offline password manager. Alternatively, Bitwarden can be self-hosted on your own server. In these cases, your vault would not be stored on the vendor\u2019s servers and thus would not be accessible at all if the vendor\u2019s servers were breached. One downside is that syncing your passwords across devices or sharing with other family members becomes something you must set up and manage yourself. Also, now <em>you<\/em> would be fully responsible for security (including backups and other security-related policies). Whether that\u2019s a good thing or a bad thing depends on your skills and how much time you want to spend on the endeavor.<\/p>\n<p>Finally, on the topic of password manager breaches, we have to talk about LastPass. In 2022, LastPass was the subject of a major breach. In addition to being breached, it became clear that they were not following certain other best practices. For one, they were not encrypting the URLs of the websites for which users were saving usernames and passwords. That made it easier for the attacker to pick specific vaults to target for brute-force decryption attacks. (Specifically, the attacker appears to have gone after vaults that had cryptocurrency assets.) Secondly, the vaults of LastPass users with older accounts were not as securely encrypted as they should have been. In 2018, LastPass had upgraded its default for new users, but <a href=\"https:\/\/palant.info\/2022\/12\/28\/lastpass-breach-the-significance-of-these-password-iterations\/\">older users were still on older encryption policies unless they explicitly adjusted the setting themselves<\/a>. That made it easier for the attacker to effectively use brute-force attacks on customer vaults. (Weaker encryption settings meant that the attacker could make many more password guesses per second against those vaults.) We know that some people <a href=\"https:\/\/krebsonsecurity.com\/2023\/09\/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach\/\"><em>did<\/em> have money stolen as a result<\/a>. Finally, LastPass customers were not informed that their encrypted vaults had been accessed <a href=\"https:\/\/www.upguard.com\/blog\/lastpass-vulnerability-and-future-of-password-security\">until months after it had occurred<\/a>. A more timely notification could have allowed customers to update all of their passwords promptly and avoid any actual losses. For the above reasons, many experts in the field simply no longer feel comfortable using or recommending LastPass. Regardless, the event illustrates the importance of a password manager provider following best practices.<\/p>\n<\/div>\n<div>\n<p>Among people who read personal finance books, many save a high percentage of their income through most of their careers. One thing that eventually happens for some such people is that they reach a point at which they realize they have not only saved &#8220;enough,&#8221; they have saved &#8220;more than enough.&#8221; Their desired standard of living in retirement is well secured, and it\u2019s likely that a major part of the portfolio is eventually going to be left to loved ones and\/or charity. And that realization raises a whole list of new questions and concerns.<\/p>\n<p>This book\u2019s goal is to help you answer those questions.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Password manager providers are naturally attractive targets for hackers. So a critical question to ask is: what happens if an attacker manages to access the servers of the company that provides your password manager software? And the answer to that question will depend on both your own practices as well as the policies and practices [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[96],"tags":[26368,13177,14495,14955,9600],"dealstore":[],"offerexpiration":[],"class_list":["post-7029434","post","type-post","status-publish","format-standard","hentry","category-investing","tag-hacked","tag-investor","tag-manager","tag-oblivious","tag-password"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=7029434\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"Password manager providers are naturally attractive targets for hackers. So a critical question to ask is: what happens if an attacker manages to access the servers of the company that provides your password manager software? And the answer to that question will depend on both your own practices as well as the policies and practices [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=7029434\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-06T02:13:22+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=7029434#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=7029434\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor\",\"datePublished\":\"2026-08-06T02:13:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=7029434\"},\"wordCount\":1174,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"keywords\":[\"hacked\",\"Investor\",\"Manager\",\"Oblivious\",\"Password\"],\"articleSection\":[\"Investing\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=7029434#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=7029434\",\"url\":\"https:\/\/fivemor.com\/?p=7029434\",\"name\":\"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"datePublished\":\"2026-08-06T02:13:22+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=7029434#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=7029434\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=7029434#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=7029434","og_locale":"en_US","og_type":"article","og_title":"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor - Som2ny Network","og_description":"Password manager providers are naturally attractive targets for hackers. So a critical question to ask is: what happens if an attacker manages to access the servers of the company that provides your password manager software? And the answer to that question will depend on both your own practices as well as the policies and practices [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=7029434","og_site_name":"Som2ny Network","article_published_time":"2026-08-06T02:13:22+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=7029434#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=7029434"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor","datePublished":"2026-08-06T02:13:22+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=7029434"},"wordCount":1174,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"keywords":["hacked","Investor","Manager","Oblivious","Password"],"articleSection":["Investing"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=7029434#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=7029434","url":"https:\/\/fivemor.com\/?p=7029434","name":"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"datePublished":"2026-08-06T02:13:22+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=7029434#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=7029434"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=7029434#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"What Happens if My Password Manager Gets Hacked? \u2014 Oblivious Investor"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7029434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7029434"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/7029434\/revisions"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7029434"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7029434"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7029434"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=7029434"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=7029434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}