LastPass Warns of Fake Maintenance Message Tracking Users to Steal Master Passwords
ID: 6f0281d1-40cd-5094-9636-05895c02ea1f
STIX ID: report--6f0281d1-40cd-5094-9636-05895c02ea1f
Feed Name: cybersecurityNews.com
Threat Score
A phishing campaign that began on January 19, 2026 is impersonating LastPass support staff and sending urgent emails asking users to back up their vaults and provide master passwords. The actors use compromised AWS S3 redirects and spoofed domains to host phishing pages; LastPass confirms it never requests master passwords via email and advises users to delete such messages and report them to [email protected].
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
