Skip to main content
Mallory
Back to intelligence
enforcement-actionbreach-disclosure-notificationmass-credential-exposurecloud-service-vulnerability

UK Fines LastPass for Major Data Breach Impacting 1.6 Million Users

Updated 3mo agoFirst seen Dec 11, 20256 sources

The UK Information Commissioner's Office (ICO) has fined LastPass £1.2 million ($1.6 million) following a significant data breach in 2022 that compromised the personal information of up to 1.6 million UK users. The breach occurred in two stages: initially, an attacker compromised a company developer's work-issued laptop, exfiltrating source code and technical documentation, including unencrypted and encrypted credentials. This access was later leveraged to target a senior engineer's personal laptop, allowing the attacker to obtain credentials and keys used to access and decrypt storage volumes within LastPass's cloud-based storage service. The ICO determined that LastPass failed to implement sufficiently robust technical and security measures to protect customer data, leading to the substantial penalty.

Although the attackers obtained encrypted versions of sensitive data, including website names and passwords, the ICO noted there was no evidence that customer passwords were decrypted, as these are stored locally on user devices. However, security experts have raised concerns about the potential for brute-force attacks on the stolen vaults, with reports linking the breach to cryptocurrency thefts. The ICO emphasized the importance of strong security practices for password management services and urged all UK businesses to take steps to protect customer data in light of this incident.

Share:
UK Fines LastPass for Major Data Breach Impacting 1.6 Million Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 11, 20256mo ago

ICO fines LastPass £1.2 million over the 2022 breach

On 2025-12-11, the UK Information Commissioner's Office announced a £1.2 million fine against LastPass UK Ltd for failing to implement adequate technical and organizational security measures. The ICO said the 2022 breach affected up to 1.6 million people in the UK and cited shortcomings in device security, credential policy, alerting, and incident response.

Jan 1, 20224y ago

Customer data and encrypted vaults are exfiltrated from LastPass

Following the two-stage intrusion, attackers stole customer information and encrypted password vault data, including names, email addresses, phone numbers, physical addresses, and website URLs. Reports said there was no evidence that master passwords themselves were decrypted, though weak vault passwords remained at risk of brute-force attacks.

Attackers exploit Plex flaw on senior engineer's personal device

Later in 2022, attackers targeted a US-based senior DevOps engineer's personal desktop by exploiting CVE-2020-5741 in Plex Media Server. The compromise gave them access to additional credentials and decryption-related material needed to reach customer data.

Attackers compromise a LastPass developer's laptop and steal source code

In 2022, attackers breached a LastPass developer's work-issued MacBook Pro and development environment, exfiltrating source code and company credentials. This initial intrusion became the first phase of the wider LastPass breach.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.