• Hello and welcome! Register to enjoy full access and benefits:

    • Advertise in the Marketplace section for free.
    • Get more visibility with a signature link.
    • Company/website listings.
    • Ask & answer queries.
    • Much more...

    Register here or log in if you're already a member.

  • 🎉 WHV has crossed 72000 (72k) monthly views (unique) and 272000 clicks per month, as per Google Analytics! Thank you for your support! 🎉

UK Fines LastPass Over 2022 Data Breach Affecting 1.6 Million Users

johny899

New Member
Content Writer
Messages
994
Reaction score
3
Points
23
Balance
$26.4USD
Did this news come as a surprise to you? It also came as a surprise to me. LastPass was fined £1.2 million by the UK government in response to a significant amount of data that was exposed in the year 2022. It was estimated that the data breach affected 1.6 million users within the UK.

So what happened to LastPass?​

LastPass is a password manager that enables users to securely store all their login details. In 2022 a hacker gained access to an employee's laptop. The hacker, after gaining access to the employee's laptop, was able to gain further access to other company systems.

The hacker was then able to connect to a cloud backup database that contained the user data stored by the company. Overall, because of this error, a potentially serious security risk occurred.

What information did the Hackers steal?​

The hackers stole the following information from LastPass:
  • Full Names
  • Email Addresses
  • Phone Numbers
  • Website URLs stored in Vaults
Hackers did not have direct access to any passwords. However, due to LastPass’ high level of encryption, they could not have viewed them. Nonetheless, obtaining so much information about each individual is concerning. Wouldn't you be concerned about your personal information being exposed?

What were the UK’s reasons for fining LastPass?​

The UK Government stated that LastPass failed to provide adequate data security measures, especially for a company that secures people's passwords. Consequently, the government imposed a fine on LastPass.

What should users take away from this Case Study?​

A very important lesson you can learn from this case study is that no online service is fully secure (or completely safe). Personally, I still use a password manager and use good security practices, such as a strong master password, and turning on two-factor authentication (2FA), or some other security measures.

Do password managers still provide users with the ability to securely store and access passwords? Absolutely. However, cases like this one serve as a reminder to always be on guard and practice good security habits, in order to protect your accounts.
 
Top