Site navigation

ICO Fines LastPass UK £1.2M For 2022 Data Breach

Tom Quinn

,

ICO Lastpass fine
“LastPass customers had a right to expect the personal information they entrusted to the company would be kept safe and secure. However, the company fell short of this expectation,” said John Edwards, UK Information Commissioner.

The UK’s data watchdog has hit LastPass UK with a £1.2 million fine after two isolated incidents in 2022 resulted in a breach that exposed the personal information of up to 1.6 million British users.

The first incident occurred in August 2022 when a hacker compromised a LastPass employee’s corporate laptop and gained access to the company’s development environment.

While no personal information was taken, encrypted company credentials were. If decrypted, these could have allowed access to the company’s backup database.

The ICO said that LastPass took steps to mitigate the hacker’s activity and believed encryption keys remained safe as they were stored outside of the area accessed by the hacker in the account vaults of four senior employees.

In the second incident, the hacker then targeted a senior employee who had access to the decryption keys, breaking into their personal device via a known vulnerability in a third-party streaming service.

Using a keylogger, the employee’s master password was captured, and multi-factor authentication was bypassed using a trusted device cookie. This then gave the black hat access to the victim’s personal and business LastPass vaults, which were linked using a single master password, which also contained their Amazon Web Service (AWS) access key and decryption key.

The combined details from both incidents allowed the hacker to access LastPass’ backup database and take personal information, which included customer names, emails, phone numbers, and stored website URLs.

Following its investigation, the ICO said that LastPass failed to implement sufficiently robust technical and security measures, which ultimately allowed a hacker to gain unauthorised access to its backup database. 


Recommended reading


However, the watchdog stressed that it had found no evidence that encrypted passwords or other credentials were unencrypted due to LastPass’s use of a ‘zero-knowledge’ encryption system, where the master password required to access a vault is stored locally on a customer’s own device and not shared with LastPass.

“Password managers are a safe and effective tool for businesses and the public to manage their numerous login details, and we continue to encourage their use,” said John Edwards, UK Information Commissioner.

“However, as is clear from this incident, businesses offering these services should ensure that system access and use is restricted to ensure risks of attack are significantly reduced. 

“LastPass customers had a right to expect the personal information they entrusted to the company would be kept safe and secure. However, the company fell short of this expectation, resulting in the proportionate fine being announced today. 

“I call on all UK businesses to take note of the outcome of this investigation and urgently review their own systems and procedures to make sure, as best as possible, that they are not leaving their customers and themselves exposed to similar risks”.

Responding to the ICO’s penalty, LastPass said: “We have been cooperating with the UK ICO since we first reported this incident to them back in 2022.

“While we are disappointed with the outcome, we are pleased to see that the ICO’s decision has recognised many of the efforts we have already taken to further strengthen our platform and enhance our data security measures.

“Our focus remains on delivering the best possible service to the 100,000 businesses and millions of individual consumers who continue to rely on LastPass.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data