LastPass Warns of Phishing Campaign Targeting Its Customers
ID: 31b45b8e-9450-5f90-b715-dfd6d65b4407
STIX ID: report--31b45b8e-9450-5f90-b715-dfd6d65b4407
Feed Name: TechRepublic Security
LastPass customers are being targeted by a sophisticated phishing campaign using urgent "maintenance" backup notices to trick users into submitting master passwords. The attackers used layered infrastructure (an AWS-hosted redirect to a phishing domain mail-lastpass.com), timed the campaign to exploit holiday staffing gaps, and employed multi-channel social engineering. Investigators have observed associated IPs (104.21.86.78, 172.67.216.232, 188.114.97.3) and are monitoring / neutralizing the infrastructure; defenders are urged to never provide master passwords and to verify notifications via official channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
