LastPass spent 2026 paying for a 2022 mistake, and then found a new way to get hurt. In December 2025, the UK’s Information Commissioner’s Office fined LastPass UK Ltd £1.2 million over the 2022 vault-backup breach that compromised the personal information of up to 1.6 million UK users. A US class action tied to the same incident cleared its first settlement hurdle at $24.5 million around the same time, and a Canadian privacy class action closed out at roughly $3 million in February 2026. Then, in June 2026, LastPass disclosed a second, unrelated incident: attackers used stolen OAuth tokens from a third-party vendor called Klue to pull customer names, phone numbers, emails, and support case data out of LastPass’s Salesforce environment.
None of that means LastPass is unsafe to use today, and none of it means 1Password or RoboForm are automatically the better pick. But it does mean that anyone typing “1password vs lastpass” into Google in September 2026 deserves a comparison that treats security history as data, not as a footnote. This guide puts 1Password, LastPass, and RoboForm side by side on pricing, encryption architecture, breach history, compliance paperwork, and day-to-day usability, then gives a data-backed verdict for five different types of buyers. If you’re weighing other vaults too, see how the field looks in our separate 1Password vs Bitwarden vs Dashlane and 1Password vs Keeper vs NordPass comparisons, or the open-source angle in Proton Pass vs Bitwarden vs 1Password.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
1Password vs LastPass vs RoboForm at a Glance
Before the deep dive, here’s the short version. All three managers use AES-256 encryption and a zero-knowledge design, meaning the vendor never has your unencrypted vault. Where they split is on price, on how they’ve handled security incidents, and on how much documentation they hand enterprise buyers.
| Category | 1Password | LastPass | RoboForm |
|---|---|---|---|
| Free tier | No (trial only) | Yes | Yes |
| Individual plan (billed annually) | $3.99/mo regular, $2.99/mo promo | $3/mo | $2.49/mo promo, renews higher |
| Family plan | $5.99/mo (5 users) | $4/mo (6 users) | $3.98/mo (5 users) |
| Business entry tier | $8.99/user/mo | $4/user/mo (Teams) | $3.33/user/mo |
| Encryption | AES-256 | AES-256 | AES-256 |
| Key derivation | PBKDF2-HMAC-SHA256 + Secret Key | PBKDF2-HMAC-SHA256 | PBKDF2-based KDF |
| SOC 2 Type II | Yes, on request via Trust Center | Yes, audited by RSM US LLP; SOC 3 public | Not documented by vendor directly |
| Passkey support (for sites) | Full, stable since Sept. 11, 2026 | Limited, incomplete per 2026 reviews | Full, across platforms per 2026 reviews |
| G2 rating / review count (Sept. 2026) | 4.6/5, 1,810 reviews | 4.5/5, 2,090 reviews | 4.6/5, 751 reviews |
| Publicized 2025-2026 incidents | None reported | 2022 breach fallout (ICO fine, settlements) plus a June 2026 third-party Klue exposure | None reported |
| Parent/owner | AgileBits Inc. (1Password) | LMI Parent, L.P. (Francisco Partners, Elliott Management) | Siber Systems Inc. |
| Scale claim (2025-2026) | 200,000+ businesses, 30%+ of Fortune 100 | Not publicly broken out | MSP partnership with Acronis Cyber Protect Cloud (July 2026) |
Pricing Breakdown: Individual, Family, and Business Plans
Price is the easiest lever to pull when three products all promise the same basic job: store your credentials and autofill them. In 2026, the gap between the cheapest and most expensive business tier among these three is about $67.80 per user per year, which adds up fast for a 500-seat deployment.
1Password raised prices on March 27, 2026. The official personal pricing page now lists Individual at a regular $3.99 per month billed annually ($47.88/year), with a promotional rate of $2.99/month for new signups. Families runs $5.99/month regular ($71.88/year) for up to five people, down from earlier promotional pricing of $4.49/month. On the business side, 1Password Business now lists at $8.99 per user per month billed annually, up from the $7.99 figure still floating around older comparison sites.
LastPass keeps a flatter, simpler structure. Its official pricing page lists Premium at $3/month ($36/year), Families at $4/month ($48/year) for up to six people, Teams at $4 per user per month ($48/user/year), and Business at $7 per user per month ($84/user/year). LastPass is also the only one of the three offering a genuinely usable free individual tier alongside its paid plans.
RoboForm undercuts both on the entry tiers. Its Everywhere/Premium plan starts at a promotional $2.49/month ($29.88/year for new customers), with Family running $3.98/month ($47.75/year) for up to five members. On the business side, RoboForm’s official business pricing page lists Business/Team at $3.33 per user per month billed annually ($39.95/user/year), with volume discounts kicking in at larger seat counts. That makes RoboForm’s business tier less than half the cost of 1Password’s per seat, though the two products aim at different buyers, as the feature sections below make clear.
| Plan tier | 1Password | LastPass | RoboForm |
|---|---|---|---|
| Free | Not offered | $0 | $0 |
| Individual (annual billing) | $3.99/mo ($47.88/yr) | $3/mo ($36/yr) | $2.49/mo promo ($29.88/yr) |
| Family plan | $5.99/mo, 5 users | $4/mo, 6 users | $3.98/mo, 5 users |
| Teams entry tier | Bundled into Business | $4/user/mo | Bundled into Business |
| Business tier | $8.99/user/mo | $7/user/mo | $3.33/user/mo |
| Annual cost, 100-seat team | ~$10,788 | ~$8,400 | ~$3,995 |
Security Architecture: Encryption, Zero-Knowledge, and Key Derivation
On paper, the cryptography looks nearly identical across all three vendors. Each uses AES-256 for vault encryption and derives the encryption key from your master password using a PBKDF2-based key derivation function, meaning brute-forcing your master password requires grinding through hundreds of thousands of hash iterations rather than a single guess.
1Password adds one extra layer that the other two don’t have: a Secret Key. This is a high-entropy, randomly generated string that lives only on your devices and never touches 1Password’s servers. Your vault encryption key is derived from the combination of your master password and this Secret Key, run through PBKDF2-HMAC-SHA256. Practically, that means even a perfect copy of 1Password’s servers wouldn’t hand an attacker enough material to brute-force your vault, because the Secret Key was never stored there in the first place.
LastPass’s technical whitepaper describes the same core approach: AES-256 encryption of the vault, done client-side before anything is uploaded, with keys derived from the master password via PBKDF2-HMAC-SHA256 at a configurable iteration count. There’s no separate device-bound secret comparable to 1Password’s Secret Key, which is part of why the 2022 breach became a story about master password strength rather than a cryptographic failure. RoboForm follows the same general pattern: AES-256 encryption with a PBKDF2-based KDF applied to the master password, though RoboForm publishes less technical detail about its exact iteration counts than either competitor.
The compliance paperwork is where the three genuinely diverge. 1Password states it is SOC 2 Type II certified and makes the report and a bridge letter available to customers through its Trust Center on request. LastPass has gone further on paper: the company has obtained a SOC 2 Type II attestation audited by RSM US LLP, and it publishes a public SOC 3 report in addition to the confidential SOC 2 documentation, both reviewed annually. RoboForm is the outlier. The company has published results from an independent security audit and penetration test performed by Secfault Security covering its desktop clients, mobile apps, web portal, and browser extensions, but there is no clear, vendor-published SOC 2 attestation. Third-party review sites sometimes claim RoboForm holds SOC 2 certification “for our cloud service,” but that claim doesn’t trace back to anything RoboForm itself has published, so treat it as unverified until RoboForm’s own compliance documentation says otherwise.
LastPass’s Breach History: The 2022 Fallout Still Landing in 2026
Understanding LastPass in 2026 means understanding two incidents, not one. The first is the 2022 breach, and 2026 turned out to be the year its financial and regulatory consequences actually arrived.
According to the UK Information Commissioner’s Office, the breach traced back to August 2022, when an attacker first compromised the corporate laptop of a Europe-based LastPass employee, then used that foothold to reach a US-based employee’s personal laptop, where malware captured the employee’s master password. Combining detail from both intrusions let the attacker into LastPass’s backup database, from which they copied customer names, emails, phone numbers, and stored website URLs, along with encrypted vault backups. The ICO’s investigation, published on December 11, 2025, found LastPass had failed to implement sufficiently robust technical and security measures and fined LastPass UK Ltd £1.2 million, covering personal information belonging to up to 1.6 million UK users. Notably, the ICO confirmed there is no evidence attackers were able to unencrypt customer passwords, since those are decrypted locally on the user’s own device rather than by LastPass’s servers, which is the practical payoff of zero-knowledge design even when a vendor’s perimeter fails.
The US legal track moved on a similar timeline. A federal class action tied to the same 2022 breach reached a proposed $24.5 million settlement, reported in late 2025 and moving through court approval into February 2026, according to Bloomberg Law’s coverage of the settlement. A separate Canadian consumer privacy class action reached its own settlement, approved in February 2026 for roughly $3 million. Three different jurisdictions, three different enforcement actions, one 2022 incident.
The 2026 Klue Incident: A Different Kind of Exposure
Then, in June 2026, LastPass disclosed something new. The company was notified on June 12, 2026, that a third-party vendor it uses for go-to-market intelligence, Klue, had been breached. According to TechCrunch’s reporting, an attacker had compromised a legacy credential tied to a Klue integration dating back to 2022 and used it to steal OAuth tokens Klue held for many of its customers, LastPass among them. Those tokens were then used to reach LastPass customer data sitting inside LastPass’s own Salesforce environment, exposing customer names, phone numbers, email addresses, physical addresses, and customer support case content.
LastPass was explicit that this incident was contained to systems that integrate with Klue’s application, primarily Salesforce, and that password vaults, master passwords, and LastPass’s core product infrastructure were not touched. That distinction matters. The Klue incident is a supply-chain and CRM exposure, similar in shape to the wave of Salesloft Drift and Salesforce-integration breaches that hit dozens of companies in 2025 and 2026, not a repeat of the 2022 vault-backup compromise. But for a company still absorbing an ICO fine and two class-action settlements from its last incident, a second confirmed exposure inside four years is a pattern prospective buyers are entitled to weigh, even when the blast radius (contact and support-ticket data, not vault contents) is smaller.
The Industry Backdrop: Password Manager Incidents Weren’t Isolated to LastPass in 2026
It’s worth zooming out before crowning a winner, because 2026 was a rough year for the password manager category generally, not just for LastPass. In April 2026, a malicious npm package impersonating Bitwarden’s official command-line tool, published as @bitwarden/[email protected] on April 22, 2026, sat live on the npm registry for roughly 90 minutes before Bitwarden’s security team caught and deprecated it. Bitwarden’s investigation found no evidence that end-user vault data was accessed and stated its production systems were never compromised; the company released a clean replacement build, @bitwarden/[email protected], the same day. Anyone who installed the CLI tool from npm during that narrow window was potentially exposed, but Bitwarden was explicit that users who didn’t touch the npm package during those 90 minutes were not affected.
Dashlane had its own scare a few weeks later. Starting May 31, 2026, an external attacker ran a brute-force campaign attempting to bypass two-factor authentication and register unauthorized devices on a small number of accounts. In cases where the attack succeeded, the attacker was able to generate valid tokens and download encrypted vault copies. Dashlane’s systems detected and locked the targeted accounts quickly, and the company’s June 4, 2026 update confirmed fewer than 20 personal-plan users had encrypted vaults downloaded, that those accounts were restored and directly notified, and that there was no evidence Dashlane’s broader internal systems were impacted. In both the Bitwarden and Dashlane cases, the zero-knowledge design held: vault contents stayed encrypted with a master password the vendor never possessed, even when an attacker got close.
The pattern across all three 2026 incidents (Bitwarden’s supply-chain scare, Dashlane’s brute-force attempt, and LastPass’s Klue-linked CRM exposure) is that none of them resulted in confirmed decryption of a customer’s actual password vault. That’s the architecture doing its job. But it also means the real differentiator between vendors in 2026 isn’t whether an attacker can ever get close (they periodically can, across the whole category), it’s how fast a vendor detects the attempt, how transparently it discloses it, and how much unrelated baggage (fines, settlements, repeat incidents) a company is still carrying from prior years. On that last measure specifically, LastPass carries meaningfully more than 1Password or RoboForm going into the second half of 2026.
1Password’s Clean Record and SOC 2 Trust Center
Against that backdrop, 1Password’s 2025-2026 story is comparatively uneventful, which in security is a compliment. Research turned up no publicly reported breach or significant security incident involving 1Password’s infrastructure or customer vaults in 2025 or 2026. The company has instead spent the period on growth and compliance messaging: a November 2025 press release announced 1Password had crossed $400 million in annual recurring revenue while serving 180,000 business customers, and by 2026 the company’s own site claims it serves “over 200,000 businesses,” including more than 30% of the Fortune 100 and roughly two-thirds of the Forbes AI 50.
On the compliance side, 1Password maintains a Trust Center where customers can request its SOC 2 Type II report and an accompanying bridge letter, the standard documentation enterprise security teams ask for during procurement. The company also shipped its most significant 2026 product update in this window: full, stable passkey support inside the 1Password browser extension, officially announced on September 11, 2026, after a staged rollout that reportedly began around August 14, 2026. A separate, still-beta feature lets users unlock their 1Password account itself with a passkey rather than a master password, documented as of July 28, 2026 and requiring recent OS versions (macOS Ventura or later, iOS 18+, Windows 11 22H2+, Android 12+).
RoboForm’s Security Posture: Independent Audits Without the SOC 2 Paper Trail
RoboForm is the smallest and least-discussed of the three, and its security messaging reflects that. The product, developed by Fairfax, Virginia-based Siber Systems Inc., has published results of a security audit and penetration test conducted by Secfault Security, covering its Windows and Mac desktop clients, iOS and Android apps, web portal, and browser extensions, with RoboForm stating identified vulnerabilities were fixed and re-validated. That is a legitimate, if less common, way to demonstrate security rigor. What RoboForm has not done is publish a SOC 2 Type II attestation the way 1Password and LastPass have; the SOC 2 claims that circulate about RoboForm trace back to third-party review sites rather than RoboForm’s own compliance pages, so enterprise buyers who require SOC 2 documentation as a procurement gate should confirm directly with RoboForm’s sales team rather than assume it from marketing copy.
Where RoboForm has been more active is shipping features. Company blog posts document a January 16, 2026 update that lets RoboForm autosave and generate passwords inside Safari and other iOS apps, a Windows client update (version 9.9.4, April 22, 2026) that improved Remote Desktop form-filling and added a Dashlane SafeNotes import path, and an iOS release (version 9.9.9, May 18, 2026) that lets users set RoboForm as their default browser and adds a private browsing mode. On the business side, RoboForm announced a new MSP partnership with Acronis Cyber Protect Cloud on July 13, 2026, letting managed service providers bundle RoboForm’s password management into their existing Acronis-based offerings, alongside new partner programs launched in May 2026.
Feature Comparison: Passkeys, Autofill, and Dark Web Monitoring
Passkeys are the clearest feature divide among the three in 2026. 1Password shipped full, stable passkey creation, management, and sign-in support in its browser extension on September 11, 2026, positioning it as the most passkey-forward of the group heading into the post-password transition many sites are pushing. RoboForm’s 2026 reviews describe full passkey support across its platforms as well, which is a notable jump for a smaller vendor. LastPass, by contrast, has been described in 2026 coverage as offering passkey storage that is present but incomplete, lagging the other two on this specific front even as it keeps pace elsewhere.
Autofill quality is harder to quantify with hard numbers from current research, but all three ship browser extensions for Chrome, Firefox, Edge, and Safari, plus native apps for Windows, macOS, iOS, and Android. RoboForm has historically leaned into complex form-filling scenarios (multi-page government forms, Remote Desktop sessions) as a differentiator, which shows up in its 2026 Windows release notes specifically calling out improved Remote Desktop form-filling. 1Password and LastPass both emphasize simpler, cleaner autofill flows tuned for everyday login forms rather than edge-case form complexity.
Dark web and breach monitoring exists in some form across all three, typically alerting you when a stored credential shows up in a known breach dataset. This is table stakes at this point in the category and isn’t a strong differentiator between these specific three products the way it might be against a bare-bones free tool.
Business and Enterprise Features Compared
For IT and security teams evaluating these three for a company deployment, the decision usually comes down to three things: admin controls, identity integration, and total cost at scale.
1Password Business, at $8.99 per user per month, is built around granular admin policies, activity reporting, and SSO/SCIM integration with identity providers, and its scale claims (200,000+ businesses, a significant chunk of the Fortune 100) suggest it’s the default choice for larger, security-mature organizations willing to pay a premium for polish and documentation. LastPass Business, at $7 per user per month, sits a notch below on price while still offering admin dashboards, SSO, and directory integration aimed at mid-market teams, with LastPass Teams at $4 per user per month serving as a lighter-weight option for smaller groups that don’t need the full admin console. RoboForm Business, at $3.33 per user per month with volume discounts at scale, is priced for cost-sensitive deployments and MSPs, which lines up with its July 2026 Acronis partnership aimed squarely at managed service providers reselling security tools to small and midsize clients rather than large enterprises negotiating custom SOC 2 access.
The practical takeaway: if your procurement process has a hard SOC 2 Type II requirement, 1Password and LastPass both clear that bar with documentation available on request, while RoboForm may require a direct conversation with sales to confirm what’s available. If your priority is minimizing per-seat cost across a large or price-sensitive deployment, RoboForm’s business tier is roughly 63% cheaper per seat than LastPass Business and about 63% cheaper than 1Password Business.
Identity provider integration is another line item worth checking before signing a contract, since none of the three publish a single unified feature matrix that’s easy to compare at a glance. 1Password Business and LastPass Business both support SSO and SCIM provisioning against major identity providers as part of their standard business tiers, letting IT teams automatically deprovision a departing employee’s vault access the moment that employee is removed from the company directory. RoboForm’s business tooling covers the core administrative basics (shared folders, centralized deployment, usage reporting) but its SSO and directory-sync depth is less extensively documented in public materials than either competitor’s, which tracks with its positioning toward smaller teams and MSP-resold deployments rather than large enterprises with dedicated identity teams running complex SSO policies across dozens of connected apps.
G2 Ratings and User Sentiment in 2026
Review-site sentiment in September 2026 shows all three clustered close together, which suggests day-to-day product satisfaction hasn’t been dramatically reshaped by LastPass’s headline-grabbing incidents. On G2, 1Password holds a 4.6 out of 5 rating across 1,810 reviews, LastPass holds 4.5 out of 5 across 2,090 reviews, and RoboForm holds 4.6 out of 5 across 751 reviews. LastPass’s larger review count reflects its longer track record and larger historical user base, while RoboForm’s smaller count reflects its position as the least-marketed of the three, despite matching 1Password’s rating.
What these numbers don’t fully capture is timing. LastPass’s rating held roughly steady through 2026 even as the ICO fine, settlement news, and Klue incident all became public within the same year, which suggests existing LastPass users are judging the product they use daily rather than penalizing it wholesale for corporate security history, at least so far. Whether that holds up as more people search comparisons like this one before signing up is a separate question.
5 Real-World Use Cases: Which Password Manager Fits Your Situation
Specs and breach histories matter, but most people are deciding based on a specific situation. Here’s how the three stack up against five common scenarios.
- A security-conscious solo user who wants the newest passkey tooling: 1Password is the strongest pick. Its September 2026 full passkey rollout and Secret Key architecture make it the most forward-leaning of the three on the password-to-passwordless transition, even at its higher $3.99-$5.99/month price point.
- A budget-constrained family of five: RoboForm’s $3.98/month Family plan is the cheapest of the three family tiers, and its passkey support is reportedly on par with 1Password’s despite the lower price, making it a reasonable value pick for households that don’t need enterprise admin tooling.
- A cash-strapped freelancer or student who needs a genuinely free option: LastPass’s free tier remains usable for a single user managing a modest number of logins, and its Premium tier at $3/month is the cheapest paid individual plan among the three if the free tier’s limits become a problem.
- A 500-seat company negotiating a multi-year SaaS contract: The SOC 2 Type II documentation available from both 1Password and LastPass matters more here than price. At this scale, 1Password’s $8.99/user/month premium (roughly $53,940/year more than RoboForm at 500 seats) may be justified by its admin tooling, Fortune 100 references, and passkey-unlock roadmap, but LastPass Business at $7/user/month is worth a serious look if the 2022 breach and 2026 Klue incident don’t disqualify it for your risk tolerance.
- An MSP reselling security tools to small-business clients: RoboForm’s July 2026 Acronis Cyber Protect Cloud partnership and low $3.33/user/month Business pricing make it the most MSP-friendly of the three, bundling directly into infrastructure many MSPs already resell.
NIST’s 2026 Digital Identity Guidelines and What They Mean for Your Master Password
Whichever of these three you pick, the weakest link is still the one thing none of them can encrypt for you: your master password. The National Institute of Standards and Technology’s SP 800-63B-4, the current revision of its Digital Identity Guidelines for authentication and authenticator management, published in July 2025 as part of the broader SP 800-63-4 suite, is the closest thing the industry has to an official standard for what makes a memorized secret strong enough to trust. It’s the document that underlies why every password manager on this list nudges you toward passphrases over short, complex-looking strings, and why none of them cap password length the way older, pre-2020s systems used to.
For a master password protecting your entire vault, the practical translation is straightforward: length beats complexity, a unique password you’ve never reused anywhere else beats a clever one, and a password manager’s own generator can produce something stronger than anything memorable you’d invent by hand for every account except the master password itself. All three vendors compared here support long master passwords well beyond the old 8-16 character norm, and none of them enforce the kind of awkward special-character requirements NIST’s guidelines have explicitly moved away from. Where this matters most for the comparison at hand is that 1Password’s Secret Key adds a second factor on top of NIST’s baseline password guidance, RoboForm’s push into full passkey support offers a way to sidestep the master-password question entirely for supported sites, and LastPass’s 2022 breach investigation specifically turned on an attacker capturing an employee’s master password through malware, a scenario NIST’s authenticator guidance addresses through device-bound and phishing-resistant authenticators rather than password strength alone.
How to Migrate From LastPass to 1Password or RoboForm
If the 2022 breach fallout or the 2026 Klue incident has you rethinking LastPass, migrating your vault is a same-afternoon project, not a multi-day ordeal. Here’s the general process for either destination.
- Log in to your LastPass vault through the web app, not the browser extension, so you have access to the full export tool.
- Open LastPass’s advanced settings and locate the export option, which generates a CSV file containing your saved logins, notes, and form data.
- Save that CSV file to a local, encrypted location on your device rather than cloud storage, since it will briefly contain your credentials in plain text.
- Create your new 1Password or RoboForm account and set a strong, unique master password (consider a passphrase of at least five random words per NIST SP 800-63B guidance on memorized secrets).
- In 1Password, use the built-in “Import” function inside the desktop app and select the LastPass CSV format; in RoboForm, use the Options menu’s Import/Export tool and point it at the same CSV.
- Review the imported entries for duplicates or malformed fields, which commonly happen with custom form-fill data and secure notes.
- Install the new manager’s browser extension on every browser and device you use, and disable or uninstall the LastPass extension to avoid autofill conflicts.
- Immediately and permanently delete the plain-text CSV export file, including from your operating system’s trash or recycle bin.
- Update your two-factor authentication method on the new account, ideally to a hardware security key or authenticator app rather than SMS.
- Go through your highest-value accounts (banking, email, primary cloud storage) manually and rotate those passwords now that you’re in a new vault, rather than trusting years-old passwords carried over from LastPass.
- Set up passkeys where the new manager supports them, starting with sites that offer passkey sign-in natively, like major email and cloud providers.
- Finally, log in to your old LastPass account and delete it, or at minimum disable auto-renewal, to make sure your old vault isn’t sitting active and unmonitored.
Pros and Cons of Each Password Manager
1Password
- Pros: Secret Key architecture adds a device-bound layer beyond the master password; full stable passkey support since September 2026; clean 2025-2026 security record; strong enterprise references (200,000+ businesses, Fortune 100 penetration)
- Cons: No free tier, and the most expensive of the three on both individual and business plans; recent price hike (March 2026) pushed costs higher across the board
LastPass
- Pros: Genuinely usable free tier; cheapest paid individual plan at $3/month; SOC 2 Type II plus a public SOC 3 report; broad name recognition and large review base
- Cons: Still absorbing regulatory and legal fallout from the 2022 breach (ICO fine, US and Canadian settlements) as of 2026; a second, unrelated third-party incident via Klue disclosed in June 2026; passkey support described as incomplete
RoboForm
- Pros: Cheapest business tier by a wide margin ($3.33/user/month); strong reported passkey support; independent third-party penetration testing (Secfault Security); MSP-friendly Acronis partnership
- Cons: No clearly documented SOC 2 Type II attestation direct from the vendor; smaller review base and lower brand recognition; less enterprise admin depth than 1Password or LastPass Business
The Verdict: Which Password Manager Wins in 2026
There isn’t a single winner here, because the three products are optimized for different buyers, but the data points to a clear default for each. For individuals and businesses that want the most current security architecture and are willing to pay for it, 1Password’s Secret Key design, full September 2026 passkey rollout, and clean incident record make it the safest default choice, especially at the business tier where its $8.99/user/month buys SOC 2 documentation and enterprise-grade admin controls. For budget-conscious households and small teams, RoboForm’s combination of low price, full passkey support, and independent penetration testing make it a legitimately strong value pick that punches above its smaller review count and lower brand recognition.
LastPass is the hardest of the three to recommend without a caveat in 2026, not because its underlying encryption is weak (the ICO itself confirmed no evidence that customer passwords were ever decrypted) but because it is the only one of the three carrying live regulatory and legal fallout from a 2022 breach into 2026, compounded by a fresh, if narrower, third-party data exposure in June 2026. Existing LastPass users aren’t necessarily at risk from these incidents specifically, and its free tier and $3/month Premium pricing remain genuinely competitive. But anyone starting fresh in September 2026, comparing all three from zero, has less reason to choose the one carrying the most incident history, when 1Password and RoboForm offer comparable core security at either end of the price spectrum with cleaner recent records. For more on the broader threat landscape shaping these decisions, see our ongoing cybersecurity threats 2026 coverage.
Frequently Asked Questions
Is LastPass still safe to use in 2026?
Its core encryption (AES-256, zero-knowledge, PBKDF2-derived keys) has not been shown to be broken, and the UK ICO confirmed no evidence that customer passwords were ever decrypted in the 2022 breach. The bigger risk factor is LastPass’s pattern of incidents (the 2022 vault-backup breach and the June 2026 Klue-related exposure of contact and support data), which is a trust and track-record question more than a cryptography question.
Which is cheaper, 1Password or LastPass?
LastPass is cheaper on every published tier: $3/month versus $3.99/month for individuals, $4/month versus $5.99/month for families, and $4-7/user/month versus $8.99/user/month for teams and business.
Does RoboForm have a free plan?
Yes, RoboForm offers a free tier alongside its paid Everywhere/Premium and Family plans, similar to LastPass. 1Password does not offer a permanent free tier, only a trial.
Which of the three has the best passkey support in 2026?
1Password and RoboForm both shipped full passkey support across their platforms in 2026, with 1Password’s stable browser extension support officially announced September 11, 2026. LastPass’s 2026 passkey implementation has been described in reviews as present but incomplete.
What happened in the LastPass Klue breach?
Klue, a third-party market intelligence vendor LastPass used, was compromised via a legacy credential, letting an attacker steal OAuth tokens Klue held for its customers, including LastPass. The attacker then used those tokens to access LastPass customer data inside LastPass’s own Salesforce environment, exposing names, phone numbers, emails, addresses, and support case content. LastPass has stated its password vaults and core infrastructure were not affected.
Do any of these three have SOC 2 Type II certification?
1Password and LastPass both maintain SOC 2 Type II attestations, available to customers on request; LastPass also publishes a public SOC 3 report. RoboForm has published independent penetration test results from Secfault Security but does not have a clearly vendor-documented SOC 2 attestation as of 2026.
Can I import my LastPass vault into 1Password or RoboForm?
Yes. Both 1Password and RoboForm support importing a LastPass CSV export through their respective desktop apps, though you should delete the plain-text export file immediately after a successful import since it briefly contains unencrypted credentials.
Is 1Password’s Secret Key actually more secure than LastPass or RoboForm’s approach?
It adds a meaningful extra layer. Because the Secret Key is generated on-device and never transmitted to 1Password’s servers, an attacker who fully compromised 1Password’s backend still wouldn’t have enough material to brute-force a user’s vault without also obtaining that device-bound key, a scenario LastPass’s architecture doesn’t specifically defend against in the same way.
Were Bitwarden or Dashlane also breached in 2026?
Not in the sense of a decrypted vault. Bitwarden had a roughly 90-minute npm supply-chain scare in April 2026 involving a backdoored CLI package, and Dashlane had a brute-force attempt in late May 2026 that resulted in fewer than 20 personal accounts having encrypted vaults downloaded. Neither company found evidence that actual vault contents were decrypted, and both are useful context for how widespread these attempted attacks were across the password manager category in 2026, not just at LastPass.
Should a hard SOC 2 requirement rule out RoboForm for enterprise use?
Not automatically, but it should trigger a direct question to RoboForm’s sales team. The company has published independent penetration test results from Secfault Security, which demonstrates real security diligence, but that isn’t the same document a SOC 2 Type II report is. If your organization’s procurement checklist requires SOC 2 as a non-negotiable, confirm RoboForm’s current compliance documentation before assuming it matches 1Password’s or LastPass’s Trust Center offerings.


