Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»LastPass Warns of Phishing Campaign Attempting to Steal Master Passwords
News

LastPass Warns of Phishing Campaign Attempting to Steal Master Passwords

Team-CWDBy Team-CWDJanuary 22, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


LastPass has urged users to be vigilant about an email phishing campaign which is posing as the password manager application provider in attempt to steal master passwords to takeover accounts.

The LastPass Threat Intelligence, Mitigation, and Escalation (TIME) team issued the warning after they became aware of an active phishing campaign which started on January 19.

The phoney emails claim to be from LastPass and warn users that they need to take urgent action by clicking the link in the message within 24 hours to backup their password vaults ahead of planned maintenance.

This link is malicious and redirects users to fake LastPass login screen. If the user enters their username and password, they unwittingly provide the attackers with the master password for their LastPass account.

As a password manager tool, this means that the victim doesn’t just have their LastPass password stolen, but it’s likely that the login credentials for any accounts they use the application for will also be compromised.

Figures from the company suggest that LastPass has 33 million users and over 100,000 business customers.

LastPass described the impersonation campaign as “circulating widely” and has urged users to be vigilant, especially given the 24-hour warning is designed to spook people into clicking on the malicious link.

Subject lines used in this LastPass phishing campaign include:

  • LastPass Infrastructure Update: Secure Your Vault Now
  • Your Data, Your Protection: Create a Backup Before Maintenance
  • Don’t Miss Out: Backup Your Vault Before Maintenance
  • Important: LastPass Maintenance & Your Vault Security
  • Protect Your Passwords: Backup Your Vault (24-Hour Window)

In a statement, LastPass said it was actively working with third-party partners to have the domain that is sending these emails taken down as soon as possible.

“This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks,” said the LastPass TIME team.

“We want customers and the broader security community to be aware that LastPass will never ask for their master password or demand immediate action under a tight deadline. We thank our customers for staying vigilant and continuing to report suspicious activity.” 

LastPass and other password managers are regularly targeted by cybercriminals as they look for the most effective way to steal login credentials.

Hackers have also targeted LastPass itself. A cyber-attack in 2022 saw attackers steal parts of LastPass source code, along with proprietary technical information.

Last year, the company was issued with a fine of £1.2m ($1.6m) by the UK’s data protection watchdog. The Information Commissioner’s Office said that LastPass failed its customers by not putting sufficiently robust technical and security measures in place.

Image credit: T. Schneider / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFive Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
Next Article GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Top IRS scams to look out for in 2026

February 10, 2026

In memoriam: David Harley

November 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.