TL;DR: The UK ICO fined LastPass £1.2 million for breach-related security failures after attackers compromised a developer account, moved laterally, and reached sensitive backups, according to Polymer. The case shows that encryption and incident response do not offset weak internal access control, visibility, and secure development hygiene when regulators assess accountability.
NHIMG editorial — based on content published by Polymer covering the LastPass ICO fine: LastPass fined £1.2 million over 2022 breach-related security failures
By the numbers:
- The UK Information Commissioner’s Office fined LastPass £1.2 million for security failures tied to its 2022 breach.
Questions worth separating out
Q: What breaks when internal access is too broad after a developer account is compromised?
A: A single compromised account can become a bridge into systems, backups, and collaboration tools that were never meant to be reachable together.
Q: Why do encryption and data-at-rest protections not eliminate breach liability?
A: Encryption protects data content, but it does not excuse weak identity controls around who can reach the data, the keys, or adjacent systems.
Q: How do identity teams know whether internal permissions are becoming a compliance risk?
A: Look for broad inheritance, shared credentials, stale entitlements, and unclear ownership over backups or sensitive storage.
Practitioner guidance
- Audit internal access paths end to end Trace how developer accounts, service accounts, backups, and collaboration tools connect to one another.
- Tighten backup and cloud storage reachability Confirm that backup repositories, snapshots, and cloud storage buckets are segmented from everyday operational identities.
- Review standing access and legacy permissions Identify accounts that retain access long after their original task ended.
What's in the full article
Polymer's full article covers the operational detail this post intentionally leaves for the source:
- The specific ICO reasoning behind the £1.2 million penalty and how it maps to internal control expectations
- The broader discussion of how encryption, monitoring, and secure development were assessed together rather than in isolation
- The source article’s practical framing of what security leaders should re-evaluate after a breach like this
- The narrative context around why this case is still relevant nearly three years after the original incident
👉 Read Polymer’s analysis of the LastPass ICO fine and breach accountability →
LastPass’s ICO fine: what identity teams need to learn now?
Explore further
Standing internal access is the control failure this case exposes. LastPass was not penalised because encryption was absent, but because access, monitoring, and secure development safeguards did not contain what compromised identities could reach. The discipline problem is simple: if internal access can drift beyond its intended purpose, regulators will treat the result as a governance failure, not an isolated breach.
A few things that frame the scale:
- The average organisation believes more than 1 in 5 of their non-human identities are insufficiently secured, according to The 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the same report.
A question worth separating out:
Q: Who is accountable when poor security controls lead to a major breach fine?
A: Accountability sits with the organisation that failed to maintain reasonable security controls, but it also extends to governance leaders who accepted weak containment, poor access oversight, or slow response as normal. Regulators increasingly assess whether security measures were adequate before the incident, not only what happened afterward.
👉 Read our full editorial: LastPass fine shows how internal access failures become regulatory risk