Cyberattack Alert: Hackers Impersonate LastPass Support to Steal Vault Passwords
A recent phishing campaign has been identified, targeting users by impersonating LastPass support emails. The objective is to steal vault passwords and account credentials.
A recent phishing campaign has been identified, targeting users by impersonating LastPass support emails. The objective is to steal vault passwords and account credentials.
The campaign utilizes fake email chains that appear to be internal communications about suspicious account activities. Messages are crafted to suggest unauthorized actions such as exporting vault data, recovering accounts, or registering new devices.
The LastPass Threat Intelligence, Mitigation, and Escalation team issued a security alert on Mon, Mar 1, 2026, informing customers about this ongoing threat.
To enhance credibility, attackers employ display name spoofing , making emails appear as though they are sent from LastPass Support, despite originating from unrelated domains. This method can be particularly deceptive on mobile devices where only the sender's name is displayed.
Recipients are urged to "secure" or "verify" their accounts via links in the emails, directing them to malicious URLs such as:
This domain hosts a counterfeit LastPass Single Sign-On (SSO) login page, closely resembling the official site. Users who input their credentials are at risk of exposure to their master passwords and stored vault data.
A recent phishing campaign has been identified, targeting users by impersonating LastPass support emails.
The fraudulent emails often incorporate LastPass branding, fake timestamps, and conversational threads to appear legitimate. Common subject lines include:
"Re: Account recovery verification request." "Unauthorized vault export attempt detected" "New trusted device registered to your account"
The emails exploit urgency and fear, prompting users to act hastily without verifying the source, a common tactic in social engineering.
According to the advisory, LastPass is working with third-party partners and domain registrars to dismantle these malicious sites swiftly. Customers are encouraged to report suspicious communications to LastPass's abuse mailbox.
LastPass emphasizes that no employee or representative will request a user's master password. Users are advised to:
Verify the full email address in any LastPass communication. Avoid clicking on email links; instead, access accounts directly via the official LastPass website or app. Enable multi-factor authentication (MFA) for enhanced security. Report suspicious messages to support@lastpass.com for verification.
This incident underscores the sophistication of phishing scams and the necessity for continuous user vigilance. As password managers are prime targets for cybercriminals, employing cautious email practices, verifying URLs, and being skeptical of urgent security alerts are crucial strategies for maintaining security.
Based on reporting by GBHackers.
