logo

LastPass hammered with £1.2M fine for 2022 breach fiasco

ID: d37ae811-eeb3-5a6a-8060-8c05a52b0722

STIX ID: report--d37ae811-eeb3-5a6a-8060-8c05a52b0722

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-12-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The ICO fined LastPass £1.2M following a two-stage 2022 breach in which attackers first accessed developer source code and credentials and then, by exploiting CVE-2020-5741 on a senior engineer's desktop, installed a keylogger and stole a session cookie to bypass MFA and obtain AWS/decryption keys. The attackers downloaded backup databases containing customer personal data (emails, phone numbers, names, addresses) affecting up to 1.6 million UK users; there is no evidence passwords were decrypted. The report highlights technical failures (unencrypted credentials in code, exposed SSE-C-related keys) and organizational issues (linking personal/business vaults, outdated AWS alert distro, SOC transition failures) that contributed to the breach and delayed detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.