LastPass (ICO, 20/11/2025): £1.23M for an exfiltrated backup
The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Why to move to immutable, isolated backups (DORA Art. 12) and how to evidence compliance.
Summary. The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Here is how immutable, isolated backups required by DORA Art. 12 prevent a similar incident from crippling your business — and how to evidence it.
What happened
On 20 November 2025, the UK Information Commissioner’s Office (ICO) fined LastPass UK Ltd £1,228,283 for infringements of Articles 5(1)(f) and 32(1)(f) of the UK GDPR. Central issue: a threat actor exfiltrated personal data of about 1.6 million UK customers from a backup repository. The ICO notes that while the “zero‑knowledge” system protected encrypted vault contents, access to the backup store itself was not sufficiently secured — exposing a common blind spot: backups as the last line of defense becoming the first target. Source: ICO – LastPass UK Ltd. (ico.org.uk)
For executives and CIOs in Luxembourg (notably in finance), the lesson is direct: if attackers reach your backups, your recovery capability is compromised. In 2026, resilience guides (CISA, ENISA) emphasize keeping backups out of reach and immutable (write‑once, deletion prevented during retention) as the foundation for safe ransomware recovery. See for example the CISA Ransomware Guide. (cisa.gov)
The applicable legal framework
Since 17 January 2025, Regulation (EU) 2022/2554 on Digital Operational Resilience (DORA Regulation) applies to EU financial entities. Its Article 12 mandates backup policies and procedures and documented restoration and recovery methods under the financial entity’s control. Official references: EUR‑Lex – DORA and EBA – Article 12 (Interactive Single Rulebook). (eur-lex.europa.eu)
DORA Art. 12, as clarified by sectoral supervisors (EIOPA/EBA in Q&A), is clear: restore from backups under your control, on managed systems, and prove recoverability via periodic tests. In practice this includes backup integrity, logical and/or physical separation from production, protection against deletion/modification, and tooled, auditable restoration exercises. See e.g. EIOPA Q&A DORA038‑2991. (eiopa.europa.eu)
Beyond finance, GDPR Article 32 requires “appropriate” measures to ensure confidentiality, integrity, availability and resilience — explicitly covering backups and their restoration. Authorities (including the ICO in LastPass) rely on this article to sanction security failures on backup stores. Reference: CNIL – GDPR Art. 32. (cnil.fr)
The technical approach to implement
Immutable backups + network isolation (plus restoration tests): this triptych meets DORA Art. 12 and GDPR 32 while sharply reducing ransomware impact.
- Immutability/WORM: write‑once/read‑many storage or object locking (e.g., S3 Object Lock, Immutable Blob) preventing changes/deletion during retention. This control neutralizes mass backup wiping by attackers. Best practice reference: CISA. (cisa.gov)
- Isolation (logical/physical air‑gap): separate the backup plane from the “prod” admin domain (accounts, networks, secret stores, KMS), limit exposure to common attack protocols, log and monitor repository access. DORA supervisors expect restoration from an environment under the entity’s control. Ref.: EIOPA Q&A. (eiopa.europa.eu)
- Encryption at rest and in transit + key management: systematic backup encryption, keys isolated from the compromised domain, rotation and minimal delegation. Encryption complements immutability but does not replace it (GDPR Art. 32). Ref.: CNIL – Art. 32. (cnil.fr)
- Regular, auditable restoration tests: DORA evidence that target RPO/RTO are achievable and that restores do not re‑introduce malware. ENISA/CISA recommend frequent, varied restorations. Ref.: CISA. (cisa.gov)
- Security monitoring of the backup plane: real‑time alerts on mass deletions, abnormal lock expiry, or out‑of‑window access; retain logs for forensics and compliance evidence (DORA, GDPR 32). Ref.: EUR‑Lex DORA. (eur-lex.europa.eu)
Standards alignment: ISO/IEC 27001:2022 Annex A (5.29 backup), ISO/IEC 27031 (ICT continuity), NIST CSF 2.0 (PR.DS‑08, RS.MI‑01), CIS Controls v8 (Control 11, 12).
How Luxgap delivers this
- Our ISO 27001 governance: we frame DORA Art. 12 policy (roles, RPO/RTO, criticality matrices), map critical datasets, define the 3‑2‑1‑1‑0 strategy and restoration test plan. We document required evidence for CSSF/ILR audits and your business continuity and disaster recovery plan.
- Our 24/7 managed SOC: we ingest logs from backup and storage solutions (WORM locks, admin access, deletion attempts, retention changes) into your SIEM. Dedicated “anti‑backup‑destruction” correlations and SOAR playbooks freeze accounts and cut targeted network access during attacks.
- Our externalized DPOs and CISOs: we align GDPR 32 and DORA 12, run documented restoration exercises, build the evidence pack (DORA register, test reports, gaps/PLAN DO CHECK ACT) and prepare regulatory communications. For the general legal framework, see our GDPR page.
Case in Luxembourg or EU
A Luxembourg management company (subject to DORA) switched in six weeks from a shared backup depot to a dual‑vault architecture: immutable WORM copies on object storage with 30‑day retention locks, a logical air‑gap via separate admin accounts and encrypted transit, plus a restoration runbook tested monthly. Result: during a 2026 extortion‑without‑encryption incident, SOC detection stopped a deletion attempt on the primary repository; immutable copies remained intact and recovery completed in 6 hours, with logs and reports provided to internal control and the supervisor.
First concrete steps
- Map your backups: what, where, who accesses them, and retention periods. Identify repositories exposed to the same admin domain as production.
- Enable immutability on at least one set of critical backups (WORM/Object Lock) with non‑reducible retention and admin log copies stored outside the prod domain.
- Isolate the backup plane: dedicated accounts, network segmentation, admin firewalls, strong MFA for backup consoles, KMS keys in a separate vault.
- Test and evidence restore: one cold restore per month and one targeted hot restore per quarter; record achieved RTO/RPO and gaps.
- Monitor: alert on mass deletions, retention downgrades, immutability disablement; retain proof for DORA Art. 12/GDPR 32.
Official sources
- ICO – LastPass UK Ltd (20/11/2025): £1,228,283 for security failures, backup repository exfiltration. (ico.org.uk)
- EUR‑Lex – Regulation (EU) 2022/2554 (DORA), Art. 12 “backup policies and procedures”. (eur-lex.europa.eu)
- EBA – DORA Article 12 (Interactive Single Rulebook). (eba.europa.eu)
- EIOPA – Q&A DORA038‑2991 (restoration from systems under the entity’s control). (eiopa.europa.eu)
- CISA – Ransomware Guide (isolated, immutable and tested backups). (cisa.gov)
- CNIL – GDPR Article 32 (security of processing, resilience). (cnil.fr)
Need assistance? Reach out via our contact page.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →