UK fines LastPass £1.2 million for data breach affecting 1.6 million people
好的,我现在需要帮用户总结这篇文章的内容,控制在100个字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是LastPass的英国子公司因为2022年的数据泄露被罚款120万英镑。泄露事件是由于两次黑客攻击,第一次是从欧洲员工的笔记本电脑窃取了源代码和技术信息,第二次是从美国高级工程师的个人电脑获取了凭证和密钥,导致云存储中的数据被访问和解密。 泄露影响了160万英国用户,英国隐私监管机构ICO认为LastPass的技术和安全措施不够 robust。虽然密码是加密的,但专家担心黑客可能破解。ICO还提到没有证据显示客户密码被解密,因为这些密码存储在用户的设备上,而不是LastPass那里。 此外,文章提到自2022年以来,LastPass一直在处理这一事件,并被拆分成独立实体。公司表示与ICO合作,并采取措施加强安全。 总结时需要包括:罚款金额、原因(数据泄露)、影响用户数、监管机构的处罚理由以及公司的回应。控制在100字以内,所以要简洁明了。 </think> LastPass英国子公司因2022年数据泄露被罚款120万英镑。两次黑客攻击导致160万用户信息泄露,监管机构认为其技术和安全措施不足。尽管密码加密存储于用户设备中未被解密,但专家担忧潜在风险。公司表示已采取措施加强安全并将继续改进服务。 2025-12-11 15:16:30 Author: therecord.media(查看原文) 阅读量:3 收藏

The British subsidiary of password management company LastPass was fined £1.2 million ($1.6 million) on Thursday by the United Kingdom’s privacy regulator for a data breach in 2022.

LastPass confirmed in December of that year that it had suffered two hacks, the first in August when “some source code and technical information were stolen from our development environment” from the corporate laptop of an employee based in Europe.

The data was then exploited by the attackers in a second attack on the personal laptop of a senior engineer based in the United States. The hacker obtained “credentials and keys” from the LastPass staffer “which were used to access and decrypt some storage volumes within the cloud-based storage service.”

Up to 1.6 million of the company’s British users had their personal information compromised in this incident. Issuing its fine on Thursday, the Information Commissioner’s Office (ICO), said LastPass had “failed to implement sufficiently robust technical and security measures” to protect this data.

The attacker also managed to obtain encrypted versions of sensitive data kept in the password manager, including website names and the passwords themselves, although these breaches are generally considered low-risk due to the expectation it would take an impossibly long time to brute force 256-bit AES encryption.

The ICO stressed there was “no evidence that hackers were able to unencrypt customer passwords as these are stored locally on customer devices and not by LastPass.”

Despite this, some experts fear that hackers have been cracking the passwords from stolen vaults. Independent journalist Brian Krebs reported that “a steady trickle of six-figure cryptocurrency heists” has been tied to the breach.

John Edwards, the Information Commissioner, stated: “Password managers are a safe and effective tool for businesses and the public to manage their numerous login details and we continue to encourage their use. However, as is clear from this incident, businesses offering these services should ensure that system access and use is restricted to ensure risks of attack are significantly reduced.

“LastPass customers had a right to expect the personal information they entrusted to the company would be kept safe and secure,” Edwards added. “However, the company fell short of this expectation, resulting in the proportionate fine being announced today.”

LastPass has faced ongoing fallout since the 2022 breach and was spun off into an independent entity last year under new ownership.

“We have been cooperating with the UK ICO since we first reported this incident to them back in 2022," a spokesperson from LastPass said. "While we are disappointed with the outcome, we are pleased to see that the ICO’s decision has recognized many of the efforts we have already taken to further strengthen our platform and enhance our data security measures. Our focus remains on delivering the best possible service to the 100,000 businesses and millions of individual consumers who continue to rely on LastPass.”

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/uk-fines-lastpass-over-1-million-data-breach
如有侵权请联系:admin#unsafe.sh