LastPass phishing scam targets users, seeks master passwords

Phishing campaign targets LastPass users with fake maintenance emails urging master passwords and redirecting to spoofed domains

  • LastPass customers are being targeted by a new phishing campaign that asks for master passwords under the guise of urgent maintenance.
  • The emails include specific subject lines and direct recipients to a phishing URL that then redirects to a fake domain.
  • The messages originate from several illegitimate addresses; LastPass says it will never ask for master passwords and is working to remove the malicious infrastructure.

LastPass warned customers on Jan. 19, 2026, about an active phishing campaign that attempts to steal master passwords, according to LastPass. Attackers send emails claiming upcoming maintenance and urging recipients to create a local backup within 24 hours.

- Advertisement -

The phishing messages use subject lines such as “LastPass Infrastructure Update: Secure Your Vault Now” and “Protect Your Passwords: Backup Your Vault (24-Hour Window).” Recipients are steered to a phishing site at group-content-gen2.s3.eu-west-3.amazonaws[.]com/5yaVgx51ZzGf, which then redirects to the fake domain mail-lastpass[.]com.

LastPass provided the sender addresses used in the campaign: support@sr22vegas[.]com, support@lastpass[.]server8, support@lastpass[.]server7, and support@lastpass[.]server3. The company emphasized that it will never ask users for their master passwords and is collaborating with third parties to take down the malicious infrastructure.

A spokesperson for the Threat Intelligence, Mitigation, and Escalation (TIME) team at LastPass said: “This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks.” The company asked customers to remain vigilant and continue reporting suspicious activity.

This incident follows a previous warning from LastPass about an information-stealing campaign that targeted macOS users with fake GitHub repositories distributing Malware disguised as the password manager and other applications.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

SEC’s Paul Atkins, CFTC’s Michael Selig to Discuss US Crypto

SEC Chair Paul Atkins and CFTC Chair Michael Selig will hold an event on...

Tesla market share falls to 9.9% in California; Toyota grows

Tesla registrations in California fell to 179,656 in 2025, down from 202,865 the prior...

Capital One to Buy Brex for $5.15B Boosting Business Crypto.

Capital One agreed to buy San Francisco-based Brex in a $5.15 billion stock-and-cash deal.The...

Nasdaq Removes Options Limits on Spot Bitcoin and Ether ETFs

Nasdaq removed 25,000-contract limits on options tied to spot Bitcoin and Ether ETFs.The rule...

AMD rallies on AI one-click bundle, partnerships to $275 Jan

AMD stock has climbed recently and is being positioned to reach $275 by the...
- Advertisement -

Must Read

9 DePIN Programs For Passive Income

Here’s something most people don’t realize: your smartphone and PC can generate passive income with almost no effort.I’m not talking about clicking ads for...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!