Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Why AI’s Rise Makes Protecting Personal Data More Critical Than Ever

February 6, 2026

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026
Facebook X (Twitter) Instagram
Friday, February 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»LastPass Warns of Phishing Campaign Attempting to Steal Master Passwords
News

LastPass Warns of Phishing Campaign Attempting to Steal Master Passwords

Team-CWDBy Team-CWDJanuary 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


LastPass has urged users to be vigilant about an email phishing campaign which is posing as the password manager application provider in attempt to steal master passwords to takeover accounts.

The LastPass Threat Intelligence, Mitigation, and Escalation (TIME) team issued the warning after they became aware of an active phishing campaign which started on January 19.

The phoney emails claim to be from LastPass and warn users that they need to take urgent action by clicking the link in the message within 24 hours to backup their password vaults ahead of planned maintenance.

This link is malicious and redirects users to fake LastPass login screen. If the user enters their username and password, they unwittingly provide the attackers with the master password for their LastPass account.

As a password manager tool, this means that the victim doesn’t just have their LastPass password stolen, but it’s likely that the login credentials for any accounts they use the application for will also be compromised.

Figures from the company suggest that LastPass has 33 million users and over 100,000 business customers.

LastPass described the impersonation campaign as “circulating widely” and has urged users to be vigilant, especially given the 24-hour warning is designed to spook people into clicking on the malicious link.

Subject lines used in this LastPass phishing campaign include:

  • LastPass Infrastructure Update: Secure Your Vault Now
  • Your Data, Your Protection: Create a Backup Before Maintenance
  • Don’t Miss Out: Backup Your Vault Before Maintenance
  • Important: LastPass Maintenance & Your Vault Security
  • Protect Your Passwords: Backup Your Vault (24-Hour Window)

In a statement, LastPass said it was actively working with third-party partners to have the domain that is sending these emails taken down as soon as possible.

“This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks,” said the LastPass TIME team.

“We want customers and the broader security community to be aware that LastPass will never ask for their master password or demand immediate action under a tight deadline. We thank our customers for staying vigilant and continuing to report suspicious activity.” 

LastPass and other password managers are regularly targeted by cybercriminals as they look for the most effective way to steal login credentials.

Hackers have also targeted LastPass itself. A cyber-attack in 2022 saw attackers steal parts of LastPass source code, along with proprietary technical information.

Last year, the company was issued with a fine of £1.2m ($1.6m) by the UK’s data protection watchdog. The Information Commissioner’s Office said that LastPass failed its customers by not putting sufficiently robust technical and security measures in place.

Image credit: T. Schneider / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFive Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
Next Article GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Team-CWD
  • Website

Related Posts

News

New RCEs, Darknet Busts, Kernel Bugs & 25+ More Stories

February 6, 2026
News

Survey of 100+ Energy Systems Reveals Critical OT Cybersecurity Gaps

February 6, 2026
News

SolarWinds Web Help Desk Vulnerability Actively Exploited

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

What are brushing scams and how do I stay safe?

December 24, 2025

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

What’s at stake if your employees post too much online

December 1, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.