LastPass Gets a £1.2 Million Slap from ICO Over 2022 Security Snafu
LastPass UK Ltd has been slapped with a £1.2 million fine by the ICO due to a security breach that exposed personal data and encrypted vaults of 1.6 million UK users. Apparently, the promise of better password protection was as secure as a chocolate teapot! LastPass customers expected more, and the ICO agreed.

Hot Take:
Looks like LastPass needs a new master password: ‘WeWon’tGetHackedAgain123’. The very company meant to protect your passwords just proved that even the gatekeeper can drop the keys once in a while. Perhaps LastPass should change their tagline to ‘We’re Only Human’.
Key Points:
- The UK’s Information Commissioner’s Office fined LastPass UK Ltd £1.2 million due to a security breach affecting 1.6 million UK users.
- The breach involved a chain of human and technical failures, starting with a compromised developer laptop in Europe.
- Phase two of the attack involved exploiting a senior engineer’s device in the US, leading to access to sensitive customer data.
- The ICO found that LastPass failed to implement adequate security safeguards, particularly concerning employee personal devices.
- Despite the breach, customer passwords remained secure due to LastPass’s ‘zero-knowledge encryption’ system.
Already a member? Log in here
