LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords
On January 19, 2026, a phishing campaign targeting LastPass users was identified. Attackers are sending fraudulent emails impersonating LastPass support, claiming that there is an urgent need for vault backups. These emails are designed to trick users…
On January 19, 2026, a phishing campaign targeting LastPass users was identified. Attackers are sending fraudulent emails impersonating LastPass support, claiming that there is an urgent need for vault backups. These emails are designed to trick users into revealing their master passwords.
The phishing emails leverage social engineering tactics by falsely asserting that users need to back up their vaults within 24 hours due to maintenance. LastPass assures that it does not request master passwords or immediate vault backups via email.
The campaign was strategically initiated during the U.S. holiday weekend to exploit reduced security staffing. Attackers use compromised AWS S3 infrastructure for redirects and a spoofed domain to mimic LastPass services.
On January 19, 2026, a phishing campaign targeting LastPass users was identified.
Delete any emails claiming to require LastPass maintenance. Implement email security measures to block messages from known malicious addresses. Educate staff on phishing indicators, such as urgent language and requests for sensitive credentials.
LastPass is actively collaborating with partners to dismantle the malicious infrastructure. Users receiving such emails should report them to abuse@lastpass.com for further analysis.
Based on reporting by Cyber Security News.
