Credential stuffing are attacks where hackers attempt to access an account by trying out username and password pairs sourced from data leaks on various websites.This type of attack relies on an automated approach with bots running lists of credentials to "stuff" into login portals for various services.The company detected and mitigated it at the time but also started an internal investigation to find out how the hackers obtained access to the accounts.During the two days, hackers had access to account holders' full names, dates of birth, postal addresses, social security numbers, and individual tax identification numbers.I switched away from LastPass when they started charging but obviously I haven't and can't foresee manually changing the 7.5k passwords I had stored in my vault."