AI Autopsy: Why the ICO fined LastPass £1.2m

Wednesday, January 21, 2026
Old data breaches never die. Especially when regulators shine a light on them. Last month, the UK’s Information Commissioner’s Office (ICO) put a 2022 incident at password management company LastPass back in the news cycle, after fining it £1.2m for GDPR infringements.
Ilia Kolochenko, data protection lawyer and founder of ImmuniWeb, also raises an eyebrow. “They should have had some foundational security controls – namely, incident response – in their cloud environment,” he tells Assured Intelligence. “I believe that in 2022 it was perfectly doable, and AWS had native tools on its platform.”
LastPass did get alerts from AWS in October that something was afoot. It followed procedure and contacted a cloud infrastructure email distribution list. However, only one person on the list (an engineer) was from LastPass. The remainder were GoTo employees, and miscommunication between the two parties resulted in an 18-day delay in the subsequent investigation. Read Full Article
SecurityWeek: Cyber Insights 2026: What CISOs Can Expect in 2026 and Beyond
ABA Journal: ChatGPT creator must turn over 20M chat logs in copyright litigation, federal judge says