logo

Crooks impersonate LastPass in campaign to harvest master passwords

ID: 100d19fd-6ef5-5015-9aa1-f947a9699480

STIX ID: report--100d19fd-6ef5-5015-9aa1-f947a9699480

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

LastPass warns of an active phishing campaign (from ~19 Jan 2026) impersonating the service and urging users to back up their vaults within 24 hours; emails link to an Amazon S3–hosted phishing page that redirects to a fake LastPass site to capture master passwords. The company says it will never request master passwords, shared IOCs and takedown efforts, and noted the risk is compounded by previously stolen encrypted vault backups being cracked when weak master passwords are used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.