LastPass hammered with £1.2M fine for 2022 breach fiasco
ID: d37ae811-eeb3-5a6a-8060-8c05a52b0722
STIX ID: report--d37ae811-eeb3-5a6a-8060-8c05a52b0722
Feed Name: The Register (Security)
The ICO fined LastPass £1.2M following a two-stage 2022 breach in which attackers first accessed developer source code and credentials and then, by exploiting CVE-2020-5741 on a senior engineer's desktop, installed a keylogger and stole a session cookie to bypass MFA and obtain AWS/decryption keys. The attackers downloaded backup databases containing customer personal data (emails, phone numbers, names, addresses) affecting up to 1.6 million UK users; there is no evidence passwords were decrypted. The report highlights technical failures (unencrypted credentials in code, exposed SSE-C-related keys) and organizational issues (linking personal/business vaults, outdated AWS alert distro, SOC transition failures) that contributed to the breach and delayed detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
