https://krebsonsecurity.com/2015/06/password-manager-lastpass-warns-of-breach/ has the details. They didn't get the files, but they got account info like the password hints. And here are 2 interesting comments about lastpass's 2FA:
Hans
June 17, 2015 at 4:28 am
Keep in mind that 2-factor only protects against unauthorized access of the LP infrastructure (website etc). In case your vault is stolen and they are able to crack your master password, the 2-factor will not help you.
AFAIK, your vault is not encrypted with the 2nd factor. At least, I cannot reason how they would do this, as the 2nd factor is a changing number.
LP claims that there is no evidence that the vaults have been copied. (but a very good hacker is able to remove his traces…right? ), so you (and me) will be ok….
-
Matt
June 18, 2015 at 12:11 am
+1
So many lastpass users (of which I am one for my low to medium security passwords) do not understand this. And lastpass marketing doesn’t really do a lot to clear this up. The only protection on your encrypted password list is your passphrase. The second factor just controls whether lastpass gives you the encrypted list.
If the attackers get your encrypted list (which it doesn’t look like they did in this case), then the second factor provides zero extra protection.