LastPass Lapse: UK Slaps Password Manager with £1.2M Fine for Security Snafu
LastPass received a £1.2 million fine from the ICO for security blunders that led to a data breach affecting 1.6 million UK users. Turns out, even in the digital age, all it takes for chaos is a dodgy laptop and a hacker with a knack for multitasking. Password security tips, anyone?

Hot Take:
Well, LastPass has certainly lived up to its name—hopefully, this fine is the “last pass” they’ll need to make through the courtroom revolving door. But hey, if you’re going to lose £1.2 million, you might as well make it memorable by letting a hacker take a shot at your password vaults. Who knew a Plex streaming app could be the Achilles’ heel of a password management service? Maybe it’s time LastPass bought a dictionary and looked up the word “irony.”
Key Points:
- LastPass fined £1.2 million by the ICO for security lapses in a 2022 breach.
- Hackers gained access through an employee’s compromised laptop and a Plex vulnerability.
- Personal data and encrypted vaults of 1.6 million UK users were affected.
- The breach involved theft of AWS and decryption keys, escalating the damage.
- Weak master passwords remain a risk, and the ICO advises stronger security measures.
Already a member? Log in here
