Connect with us

Technology

Password manager fined after major data breach

Published

on

Password manager fined after major data breach

NEWYou can now listen to Fox News articles!

Any data breach affecting 1.6 million people is serious. It draws even more attention when it involves a company trusted to guard passwords. That is exactly what happened to LastPass.

The UK Information Commissioner’s Office has fined LastPass about $1.6 million for security failures tied to its 2022 breach. Regulators say those failures allowed a hacker to access a backup database and put users at risk.

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter. 

CHECK IF YOUR PASSWORDS WERE STOLEN IN HUGE LEAK

Advertisement

Why the LastPass breach still matters

LastPass is one of the most widely used password managers in the world. It serves more than 20 million individual users and around 100,000 businesses. That popularity also makes it an attractive target for cybercriminals.

The UK Information Commissioner’s Office fined LastPass for security failures tied to its 2022 breach.  (LaylaBird/Getty Images)

In 2022, LastPass confirmed that an unauthorized party accessed parts of its customer information through a third-party cloud storage service. While the incident initially raised alarms, the long-term impact has taken time to fully surface.

The ICO now says the breach affected about 1.6 million UK users alone. That scope played a major role in the size of the fine.

What regulators say went wrong

According to the ICO, LastPass failed to put strong enough technical and security controls in place. Those gaps made it possible for attackers to reach a backup database that should have been better protected.

Advertisement

The regulator added that LastPass promises to help people improve security, but failed to meet that expectation. As a result, users were left exposed even if their passwords were not directly cracked.

Were passwords exposed or decrypted?

There is still no evidence that attackers decrypted customer passwords. That point matters.

Despite the breach, security experts continue to recommend password managers for most people. Storing unique, strong passwords in an encrypted vault is still far safer than reusing weak passwords across accounts.

As one expert noted, modern breaches often succeed after identity access rather than password cracking alone. Once attackers get a foothold, the damage can spread quickly.

Although attackers accessed a backup database, there is no evidence that customer passwords were decrypted. (Kurt “CyberGuy” Knutsson)

Advertisement

Why the LastPass fine is a wake-up call for cybersecurity

The ICO called the LastPass fine a turning point. It reinforces the idea that security is about governance, staff training and supplier risk as much as software.

Users have a right to expect that companies handling sensitive data take every reasonable step to protect it.

Breaches may be inevitable, but weak safeguards are not.

LastPass on the UK data breach

We reached out to LastPass for comment on the UK fine, and a spokesperson provided CyberGuy with the following statement: 

“We have been cooperating with the UK ICO since we first reported this incident to them back in 2022. While we are disappointed with the outcome, we are pleased to see that the ICO’s decision has recognized many of the efforts we have already taken to further strengthen our platform and enhance our data security measures. Our focus remains on delivering the best possible service to the 100,000 businesses and millions of individual consumers who continue to rely on LastPass.”

Advertisement

MASSIVE DATA BREACH EXPOSES 184 MILLION PASSWORDS AND LOGINS

How to protect yourself after a password manager breach

Breaches like this are a reminder that security requires layers. No single tool can protect everything on its own.

1) Use a strong password manager correctly

Keep using a reputable password manager. Set a long, unique master password and enable two-factor authentication. Avoid reusing your master password anywhere else.

Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.

Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.

Advertisement

2) Rotate sensitive passwords

Change passwords for financial accounts, email accounts and work logins. Focus on services that could cause real damage if compromised.

3) Lock down your email

Your email account is the key to password resets. Use a strong password, two-factor authentication and recovery options you control. 

4) Reduce your exposed personal data

Data brokers collect and sell personal information that criminals use for targeting. A data removal service can help reduce what is publicly available about you. While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

Advertisement

The fine sends a warning to the entire cybersecurity industry. Companies that handle sensitive data must protect it with strong safeguards and oversight. (REUTERS/Andrew Kelly)

5) Watch for phishing attempts and use strong antivirus software 

After major breaches, scammers follow. Be cautious of emails claiming urgent account problems or asking for verification details. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

6) Keep devices updated

Install updates for your operating system, browser and security tools. Many attacks rely on known vulnerabilities that updates already fix.

Kurt’s key takeaways

The fine against LastPass is about more than one company. It highlights how much trust we place in tools that manage our digital lives. Password managers remain a smart security choice. Still, this case shows why you should stay alert even when using trusted brands. Strong settings, regular reviews and layered protection matter more than ever. In the end, security works best when companies and we share the responsibility. Tools help, but habits and awareness finish the job.

Advertisement

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Do you believe companies are doing enough to protect user data, or should regulators step in more often? Let us know by writing to us at Cyberguy.com.

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter. 

Copyright 2025 CyberGuy.com.  All rights reserved.

Advertisement
Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Technology

The AirPods Pro 3 are $50 off right now, nearly matching their best-ever price

Published

on

The AirPods Pro 3 are  off right now, nearly matching their best-ever price

Less than a week ago, Apple announced the forthcoming AirPods Max 2, a pair of over-ear headphones that leverage the company’s H2 chip for AI-powered live translation, conversation awareness, and a host of newer features. However, if you’re okay with a pair of earbuds, the AirPods Pro 3 offer access to all the same features for less — especially given they’re currently on sale at Amazon, Walmart, and Best Buy for $199.99 ($50 off), matching their second-best price to date.

For iPhone owners, nothing else really compares to the AirPods Pro 3. Apple’s latest pair of premium earbuds deliver the best active noise cancellation and richest sound of any AirPods model to date, combined with a more comfortable, angled design that fits securely and naturally in your ear canal. They also feature a new XXS ear tip size and a more robust IP57 rating for sweat and water resistance, making them better suited for long-distance runs and various gym activities.

Speaking of workouts, the Pro 3 can also pull double duty as a fitness tracker, thanks to a built-in heart rate sensor that works with Apple’s Fitness app to track calories burned across more than 50 workout types. It’s a welcome addition if you don’t use an Apple Watch; however, it may not be as useful for those who already own and rely on Apple’s wearable for its health tracking and wellness features.

Lastly, as mentioned up top, the AirPods Pro 3 also boast an H2 chip, allowing for the aforementioned real-time translation features and Apple’s newer Voice Isolation tech, which uses machine learning to isolate and enhance voice quality by removing unwanted background noise. That’s on top of their seamless integration with other Apple devices, mind you, which lets you take advantage of automatic device switching and a Find My-compatible charging case.

Continue Reading

Technology

Fake Google security page can turn your browser into a spying tool

Published

on

Fake Google security page can turn your browser into a spying tool

NEWYou can now listen to Fox News articles!

A new phishing scam is tricking people into installing malware by pretending to be a Google security check. The page looks convincing and tells you that your Google account needs additional protection. It walks you through a simple setup process that appears to strengthen your security and protect your devices.

If you follow those steps, you may end up installing what looks like a harmless security tool. In reality, security researchers say the page installs a malicious web app that can spy on your device. It can steal login verification codes, watch what you copy and paste, track your location and quietly send internet traffic through your browser. 

The most troubling part is that nothing is technically hacked. Instead of exploiting a software flaw, attackers simply trick you into granting the permissions they need. Once that happens, your own browser can start working for them without you realizing it.

Sign up for my FREE CyberGuy Report. Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.

Advertisement

THE #1 GOOGLE SEARCH SCAM EVERYONE FALLS FOR

The fake site mimics a Google security page and urges visitors to complete a quick “account protection” setup. (AP Photo/Don Ryan, File)

All about the fake Google security page

Security researchers at Malwarebytes, a cybersecurity company, recently discovered a phishing website that pretends to be part of Google’s account protection system. The site uses the domain google-prism[.]com and presents what looks like a legitimate security page asking you to complete a short verification process. Visitors are told they should complete a four-step setup to improve their account protection. The page explains that these steps will help secure your Google account and protect your devices from threats. During the process, the site asks you to approve several permissions and install what it claims is a security tool.

The tool it installs is actually a Progressive Web App. This type of application runs through your browser but behaves like a regular app on your computer. It opens in its own window, can send notifications and can run tasks in the background. Once installed, the malicious web app can collect contacts, read information you copy to your clipboard, track GPS location data and attempt to capture one-time login codes sent to your phone. These codes are commonly used when you sign in to accounts that use two-factor authentication.

The fake security page may also offer an Android companion app described as a “critical security update.” Researchers found that this app requests 33 permissions, including access to text messages, call logs, contacts, microphone recordings and accessibility features. Those permissions give attackers the ability to read messages, capture keystrokes, monitor notifications and maintain control over parts of the device. Even if the Android app is never installed, the web app alone can still collect sensitive information and quietly run activity through your browser.

Advertisement

How it works and why it matters to you

The scam works because it looks like something you would normally trust. Many people expect security alerts from the services they use, especially when it comes to protecting email or cloud accounts. Attackers take advantage of that trust by presenting the fake page as a helpful security feature. When you approve the permissions and install the web app, you are essentially giving the attackers access to certain parts of your device. One of the main things they try to capture is one-time passwords. These are the short codes you receive when logging in to accounts that require two-factor authentication.

If attackers manage to capture those codes while also knowing your password, they may be able to break into your accounts. That could include your email, financial services, or cryptocurrency wallets, depending on which accounts you use. The malware also watches what you copy and paste. Many people copy cryptocurrency wallet addresses before sending digital currency, and those addresses can be valuable to criminals. The malicious app can collect that information and send it back to the attackers.

Another feature allows attackers to route internet requests through your browser. This means they can run online activity through your device so it appears to come from your home network. The app can also send notifications that look like security alerts or system warnings. When you click those notifications, the app opens again and gains another opportunity to capture information such as login codes or clipboard data.

Google says built-in protections can block the threat

After learning about the phishing campaign, we asked Google about the malicious site and whether users are protected.

A Google spokesperson told CyberGuy that several built-in security systems are designed to stop threats like this before they cause harm.

Advertisement

“We can confirm that Safe Browsing in Chrome warns any user who tries to visit this site. Chrome also shows a confirmation dialog whenever anyone attempts to download an APK. Android users are automatically protected against known versions of this malware by Google Play Protect, which is on by default on Android devices with Google Play Services.”

Google also said that its current monitoring shows no apps containing this malware are available on the Google Play Store.

ANDROID MALWARE HIDDEN IN FAKE ANTIVIRUS APP

Even if malicious apps are installed from outside official stores, Google says Android devices still have an additional layer of protection. Google Play Protect can warn users or block apps known to exhibit malicious behavior, including apps installed from third-party sources.

However, it is important to note that Google Play Protect may not be enough. Historically, it isn’t 100% foolproof at removing all known malware from Android devices, which is why we recommend additional strong antivirus software to detect malicious downloads, suspicious browser activity and phishing attempts before they cause serious damage. It acts as an early warning system that helps block dangerous apps and websites before they gain access to your device or your data.

Advertisement

During the process, users are prompted to approve permissions and install what appears to be a security tool. (iStock)

Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com.

7 ways to protect yourself from fake security pages

If you ever come across a suspicious “security check” like this, a few simple habits can help you avoid falling into the trap and protect your accounts and devices.

1) Never run security checks from random websites

Google does not ask you to install security tools through pop-ups or unfamiliar websites. If a page claims your account needs a security check, close the tab and go directly to Google’s official account page by typing the address yourself. Visiting the real account settings page prevents attackers from redirecting you to a fake site.

2) Check website addresses carefully before trusting them

Phishing pages often use domains that look similar to real companies. Attackers rely on people clicking quickly without paying attention to the address bar. If the website address is not an official Google domain, do not trust it. Even a small change in the spelling can indicate a fake site designed to steal information.

Advertisement

3) Remove suspicious web apps from your browser

If you installed an app through a website and it opens like a standalone program, check your browser’s installed apps or extensions list. Remove anything you do not recognize or do not remember installing. Uninstalling the app immediately prevents it from collecting more information or running commands through your browser.

4) Check your Android phone for unfamiliar apps

Researchers say the malicious Android app may appear as “Security Check” or “System Service.” If you see unfamiliar apps with these names, review the permissions they request and remove them if they look suspicious. Apps asking for extensive permissions such as SMS access, accessibility features, and microphone control should always be investigated.

5) Use a password manager for your accounts

A password manager helps you create and store strong, unique passwords for every account you use online. If attackers obtain one password, they will not automatically gain access to other accounts. Password managers can also help prevent you from entering credentials on fake sites because they usually refuse to auto-fill on lookalike domains.

Check out the best expert-reviewed password managers of 2026 at Cyberguy.com

6) Enable two-factor authentication whenever possible

Two-factor authentication (2FA) adds an extra layer of protection beyond your password. Even though this attack tries to capture SMS verification codes, many services allow you to use authenticator apps instead. These apps generate login codes on your device and make it much harder for attackers to intercept them.

Advertisement

7) Monitor your accounts for unusual activity

If you think you interacted with a suspicious security page, keep a close eye on your accounts over the following days. Watch for login alerts, password reset emails, or transactions you do not recognize. Acting quickly after suspicious activity can help prevent attackers from gaining full control of your accounts.

Pro tip: Reduce how easily scammers can target you

Scammers often gather personal details from data broker sites to make phishing messages look more convincing. A data removal service can help remove your personal information from many of those databases, reducing the amount of information criminals can use to impersonate companies or craft targeted scams. 

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

Researchers say the malicious web app could collect login codes, clipboard data and other sensitive information.  (Felix Zahn/Photothek via Getty Images)

Advertisement

Kurt’s key takeaway

Attackers are changing tactics. Instead of breaking into systems through technical flaws, they are relying on convincing security messages that persuade people to install tools themselves. All of us rely on familiar brands like Google when making security decisions, and attackers know that. Preventing these scams will likely require faster action against impersonation sites and stronger safeguards around what web apps are allowed to do once installed.

Should companies like Google be required to automatically block lookalike domains that pretend to run official security checks before people fall for them? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report. Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter. 

Copyright 2026 CyberGuy.com.  All rights reserved.

Advertisement

Continue Reading

Technology

Jury finds Elon Musk’s ‘stupid tweets’ caused Twitter investors’ losses

Published

on

Jury finds Elon Musk’s ‘stupid tweets’ caused Twitter investors’ losses

A California jury determined that Elon Musk misled Twitter investors before making a $44 billion deal to buy the company in 2022, reports CNBC. The New York Times reports that Musk had testified this month that he didn’t believe his posts would spook markets, but he did say that “If this was a trial about whether I made stupid tweets, I would say I’m guilty.”

CNBC reports Musk’s attorneys are expected to file an appeal, as damages could reach as high as $2.6 billion, according to attorneys representing the plaintiffs.

While finding that Musk did not engage in a specific scheme to defraud shareholders, the jury cited two of Musk’s tweets, from May 13th and May 27th, 2022, as materially false or misleading, causing some investors to sell shares in Twitter at values below the $54.20 per share bid.

Twitter deal temporarily on hold pending details supporting calculation that spam/fake accounts do indeed represent less than 5% of users

20% fake/spam accounts, while 4 times what Twitter claims, could be *much* higher.

My offer was based on Twitter’s SEC filings being accurate.

Yesterday, Twitter’s CEO publicly refused to show proof of

Advertisement

This deal cannot move forward until he does.

Continue Reading

Trending