UK fines LastPass over 2022 data breach impacting 1.6 million users
ID: 8698a41d-67b7-5144-a046-ca848e399666
STIX ID: report--8698a41d-67b7-5144-a046-ca848e399666
Feed Name: Bleeping Computer
The UK ICO fined LastPass £1.2M after attackers in August 2022 compromised a developer laptop and, by exploiting a vulnerability in a third‑party streaming app on a senior employee's personal device, deployed malware and a keylogger to capture a master password and bypass MFA; stolen AWS credentials and a decryption key were then used to access cloud backups at a third‑party provider and exfiltrate customer account metadata and encrypted password vaults. LastPass maintains vaults remained encrypted but warned users to strengthen master passwords (preferably long passphrases) because weak passwords can be brute-forced offline; the report includes recommendations to harden device security and access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
