The UK Information Commissioner's Office (ICO) has fined LastPass £1.2 million ($1.6 million) following a significant data breach in 2022 that compromised the personal information of up to 1.6 million UK users. The breach occurred in two stages: initially, an attacker compromised a company developer's work-issued laptop, exfiltrating source code and technical documentation, including unencrypted and encrypted credentials. This access was later leveraged to target a senior engineer's personal laptop, allowing the attacker to obtain credentials and keys used to access and decrypt storage volumes within LastPass's cloud-based storage service. The ICO determined that LastPass failed to implement sufficiently robust technical and security measures to protect customer data, leading to the substantial penalty.
Although the attackers obtained encrypted versions of sensitive data, including website names and passwords, the ICO noted there was no evidence that customer passwords were decrypted, as these are stored locally on user devices. However, security experts have raised concerns about the potential for brute-force attacks on the stolen vaults, with reports linking the breach to cryptocurrency thefts. The ICO emphasized the importance of strong security practices for password management services and urged all UK businesses to take steps to protect customer data in light of this incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-11, the UK Information Commissioner's Office announced a £1.2 million fine against LastPass UK Ltd for failing to implement adequate technical and organizational security measures. The ICO said the 2022 breach affected up to 1.6 million people in the UK and cited shortcomings in device security, credential policy, alerting, and incident response.
Following the two-stage intrusion, attackers stole customer information and encrypted password vault data, including names, email addresses, phone numbers, physical addresses, and website URLs. Reports said there was no evidence that master passwords themselves were decrypted, though weak vault passwords remained at risk of brute-force attacks.
Later in 2022, attackers targeted a US-based senior DevOps engineer's personal desktop by exploiting CVE-2020-5741 in Plex Media Server. The compromise gave them access to additional credentials and decryption-related material needed to reach customer data.
In 2022, attackers breached a LastPass developer's work-issued MacBook Pro and development environment, exfiltrating source code and company credentials. This initial intrusion became the first phase of the wider LastPass breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourceico.org.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.