Total Tests:

AI Autopsy: Why the ICO fined LastPass £1.2m

Assured
By Danny Bradbury for Assured
Wednesday, January 21, 2026

Old data breaches never die. Especially when regulators shine a light on them. Last month, the UK’s Information Commissioner’s Office (ICO) put a 2022 incident at password management company LastPass back in the news cycle, after fining it £1.2m for GDPR infringements.

Ilia Kolochenko, data protection lawyer and founder of ImmuniWeb, also raises an eyebrow. “They should have had some foundational security controls – namely, incident response – in their cloud environment,” he tells Assured Intelligence. “I believe that in 2022 it was perfectly doable, and AWS had native tools on its platform.”

LastPass did get alerts from AWS in October that something was afoot. It followed procedure and contacted a cloud infrastructure email distribution list. However, only one person on the list (an engineer) was from LastPass. The remainder were GoTo employees, and miscommunication between the two parties resulted in an 18-day delay in the subsequent investigation. Read Full Article


Ask a Question