Crooks impersonate LastPass in campaign to harvest master passwords
ID: 100d19fd-6ef5-5015-9aa1-f947a9699480
STIX ID: report--100d19fd-6ef5-5015-9aa1-f947a9699480
Feed Name: Security Affairs
LastPass warns of an active phishing campaign (from ~19 Jan 2026) impersonating the service and urging users to back up their vaults within 24 hours; emails link to an Amazon S3–hosted phishing page that redirects to a fake LastPass site to capture master passwords. The company says it will never request master passwords, shared IOCs and takedown efforts, and noted the risk is compounded by previously stolen encrypted vault backups being cracked when weak master passwords are used.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
