Lastpass have just provided an update on the recent security breach.
Here is the update.
blog.lastpass.com
I am seriously impressed with this company. They have been open and honest about the situation and have given enough details to be able to make an informed decision on how to proceed.
This is an example of how companies SHOULD handle breaches.
Providing your master password is decent, then you should have nothing to worry about on this one.
Your data is encrypted and that encryption is password secured. So. each vault has a different encryption key. What this means is that the hackers CANNOT run a common dictionary attack or other standard bulk decryption technique.
Each account would have to be hacked individually.
It is unlikely that you or I will be targeted for this treatment. However if you are a famous or notable person, then they may put resources into decrypting your account.
So my takes from this are.
1) Great transparency from Lastpass. It shows they are serious about this and will now take steps to prevent the same thing happening again. Do not move to another company based on this breach as the next company won't have this real experience and you may find the same thing happening again. Lastpass are not likely to fall for this again.
2) I am not concerned about the security of my data. Although the fact they have Personally identifiable data in the clear is a concern as it may lead to an increase in phishing attempts.
3) I won't be changing providers due to this. Although I may be changing due to their pricing in the future once my current contract expires.
Here is the update.

Notice of Recent Security Incident - The LastPass Blog
We are working diligently to understand the scope of the incident and identify what specific information has been accessed.

I am seriously impressed with this company. They have been open and honest about the situation and have given enough details to be able to make an informed decision on how to proceed.
This is an example of how companies SHOULD handle breaches.
Providing your master password is decent, then you should have nothing to worry about on this one.
Your data is encrypted and that encryption is password secured. So. each vault has a different encryption key. What this means is that the hackers CANNOT run a common dictionary attack or other standard bulk decryption technique.
Each account would have to be hacked individually.
It is unlikely that you or I will be targeted for this treatment. However if you are a famous or notable person, then they may put resources into decrypting your account.
So my takes from this are.
1) Great transparency from Lastpass. It shows they are serious about this and will now take steps to prevent the same thing happening again. Do not move to another company based on this breach as the next company won't have this real experience and you may find the same thing happening again. Lastpass are not likely to fall for this again.
2) I am not concerned about the security of my data. Although the fact they have Personally identifiable data in the clear is a concern as it may lead to an increase in phishing attempts.
3) I won't be changing providers due to this. Although I may be changing due to their pricing in the future once my current contract expires.