UK fines LastPass £1.2 million for data breach affecting 1.6 million people

The British subsidiary of password management company LastPass was fined £1.2 million ($1.6 million) on Thursday by the United Kingdom’s privacy regulator for a data breach in 2022.

LastPass confirmed in December of that year that it had suffered two hacks, the first in August when “some source code and technical information were stolen from our development environment” from the corporate laptop of an employee based in Europe.

The data was then exploited by the attackers in a second attack on the personal laptop of a senior engineer based in the United States. The hacker obtained “credentials and keys” from the LastPass staffer “which were used to access and decrypt some storage volumes within the cloud-based storage service.”

Up to 1.6 million of the company’s British users had their personal information compromised in this incident. Issuing its fine on Thursday, the Information Commissioner’s Office (ICO), said LastPass had “failed to implement sufficiently robust technical and security measures” to protect this data.

The attacker also managed to obtain encrypted versions of sensitive data kept in the password manager, including website names and the passwords themselves, although these breaches are generally considered low-risk due to the expectation it would take an impossibly long time to brute force 256-bit AES encryption.

The ICO stressed there was “no evidence that hackers were able to unencrypt customer passwords as these are stored locally on customer devices and not by LastPass.”

Despite this, some experts fear that hackers have been cracking the passwords from stolen vaults. Independent journalist Brian Krebs reported that “a steady trickle of six-figure cryptocurrency heists” has been tied to the breach.

John Edwards, the Information Commissioner, stated: “Password managers are a safe and effective tool for businesses and the public to manage their numerous login details and we continue to encourage their use. However, as is clear from this incident, businesses offering these services should ensure that system access and use is restricted to ensure risks of attack are significantly reduced.

“LastPass customers had a right to expect the personal information they entrusted to the company would be kept safe and secure,” Edwards added. “However, the company fell short of this expectation, resulting in the proportionate fine being announced today.”

LastPass has faced ongoing fallout since the 2022 breach and was spun off into an independent entity last year under new ownership. A spokesperson did not immediately respond to a request for comment following the fine.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.

 

Total
0
Shares
Previous Post

ThreatsDay Bulletin: Spyware Alerts, Mirai Strikes, Docker Leaks, ValleyRAT Rootkit — and 20 More Stories

Next Post

Hackers reportedly breach developer involved with Russia’s military draft database

Related Posts

ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories

This week’s ThreatsDay Bulletin tracks how attackers keep reshaping old tools and finding new angles in familiar systems. Small changes in tactics are stacking up fast, and each one hints at where the next big breach could come from. From shifting infrastructures to clever social hooks, the week’s activity shows just how fluid the threat landscape has become. Here’s the full rundown of what
Read More

Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t)

As organizations plan for 2026, cybersecurity predictions are everywhere. Yet many strategies are still shaped by headlines and speculation rather than evidence. The real challenge isn’t a lack of forecasts—it’s identifying which predictions reflect real, emerging risks and which can safely be ignored. An upcoming webinar hosted by Bitdefender aims to cut through the noise with a data-driven
Read More

Warning: WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a security flaw impacting the WinRAR file archiver and compression utility to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-6218 (CVSS score: 7.8), is a path traversal bug that could enable code execution. However, for exploitation
Read More