This puts it simply.

@robpomeroy Here’s the opinion of Nicolas Chaillan… remove trust in SaaS for critical infrastructure. I don’t think most orgs can responsibly manage most infrastructure. This one brings a big sigh from me. Need to discuss.
@robpomeroy As a reminder to everyone.. use a strong master password.
To @robpomeroy, does using 2fa in any way influence a hacker’s process to brute force the encrypted data? Perhaps as some sort of salt?
https://support.lastpass.com/help/what-is-the-lastpass-master-password-lp070014
The master password is the password that you are prompted to create when you initially sign up for your LastPass account. When you log in to LastPass, you need your email address and master password to access your account. It is very important that you create a very strong master password that you will not forget.
On the LastPass breach.
So threat actors made off with "company names, end-user names, billing addresses, email addresses, telephone numbers, and ... IP addresses".
They also got "customer vault data ... that contains both unencrypted data, such as website URLs, as well as fully-encrypted sensitive fields".
That's not great, whichever way you look at it.
https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/