Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»LastPass Warns Customers It Has Not Been Hacked Amid Phishing Emails
News

LastPass Warns Customers It Has Not Been Hacked Amid Phishing Emails

Team-CWDBy Team-CWDOctober 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Password manager LastPass has warned customers that is has “NOT been hacked” after it identified a phishing campaign leveraging the firm’s branding.

The phishing emails used the subject line “We Have Been Hacked – Update Your LastPass Desktop App to Maintain Vault Security” and was sent from the email addresses hello@lastpasspulse[.]blog or hello@lastpassgazette[.]blog.

“This is an attempt on the part of a malicious actor to draw attention and generate urgency in the mind of the recipient, a common tactic for social engineering and phishing emails,” the firm said in a blog post.  

The link in the email purports to take potential victims to a new desktop app site, which will instead direct victims to a phishing site hosted at lastpassdesktop[.]com or lastpassgazette[.]blog.

Another URL had been registered by the threat actor, (“lastpassdesktop[.]app”), which LastPass said could be used in future iterations of this campaign.

It appears that the threat actor has used NiceNIC to host the phishing site.

The security firm said it was working to have the domain taken down as soon as possible and Cloudflare has posted warning pages in front of the site advising visitors that these sites are phishing pages.

1Password Phishing Scam Threatens to Steal Secret Key

Earlier this month, Malwarebytes reported that a “well-targeted” phishing campaign saw scammers attempt to get hold of the 1Password credentials belonging to a Malwarebytes’ employee.

Pieter Arntz, a malware intelligence researcher at Malwarebytes Labs, commented in a blog post, “Stealing someone’s 1Password login would be like hitting the jackpot for cybercriminals, because they potentially export all the saved logins the target stored in the password manager.”

In September, Brett Christensen, author of the Substack Hoax-Slayer, reported on a phishing campaign purporting to be from 1Password warning customers that their account had been compromised and urging users to rest passwords via a malicious link.

The malicious web page also encouraged users to share their secret key.

1Password secret keys allow access to a user’s password vault, which could provide a trove of information to cybercriminals.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave
Next Article Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks
Team-CWD
  • Website

Related Posts

News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

‘What happens online stays online’ and other cyberbullying myths, debunked

September 11, 2025

When ‘hacking’ your game becomes a security risk

October 17, 2025

How cybercriminals are targeting content creators

November 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.