LastPass warns of spoofed alerts aimed at stealing master passwords
ID: dfe97c64-3e03-5e3d-a625-f7bff9eea1eb
STIX ID: report--dfe97c64-3e03-5e3d-a625-f7bff9eea1eb
Feed Name: Security Affairs
Threat Score
LastPass alerted customers to an active phishing campaign (starting ~1 March 2026) that spoofs LastPass display names and forwards fake internal threads to coerce users into entering their master password on a fake SSO page (verify-lastpass.com); LastPass provided IoCs, warned it will never ask for master passwords, and urged users to report suspicious LastPass-branded emails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
