BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

LastPass phishing scam targets users, seeks master passwords

Phishing campaign targets LastPass users with fake maintenance emails urging master passwords and redirecting to spoofed domains

  • LastPass customers are being targeted by a new phishing campaign that asks for master passwords under the guise of urgent maintenance.
  • The emails include specific subject lines and direct recipients to a phishing URL that then redirects to a fake domain.
  • The messages originate from several illegitimate addresses; LastPass says it will never ask for master passwords and is working to remove the malicious infrastructure.

LastPass warned customers on Jan. 19, 2026, about an active phishing campaign that attempts to steal master passwords, according to LastPass. Attackers send emails claiming upcoming maintenance and urging recipients to create a local backup within 24 hours.

- Advertisement -

The phishing messages use subject lines such as “LastPass Infrastructure Update: Secure Your Vault Now” and “Protect Your Passwords: Backup Your Vault (24-Hour Window).” Recipients are steered to a phishing site at group-content-gen2.s3.eu-west-3.amazonaws[.]com/5yaVgx51ZzGf, which then redirects to the fake domain mail-lastpass[.]com.

LastPass provided the sender addresses used in the campaign: support@sr22vegas[.]com, support@lastpass[.]server8, support@lastpass[.]server7, and support@lastpass[.]server3. The company emphasized that it will never ask users for their master passwords and is collaborating with third parties to take down the malicious infrastructure.

A spokesperson for the Threat Intelligence, Mitigation, and Escalation (TIME) team at LastPass said: “This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks.” The company asked customers to remain vigilant and continue reporting suspicious activity.

This incident follows a previous warning from LastPass about an information-stealing campaign that targeted macOS users with fake GitHub repositories distributing Malware disguised as the password manager and other applications.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AMD vs Nvidia in 2026: Momentum vs Value Showdown

AMD has surged over 190% in 2026 to a $1.03 trillion market cap, fueled...

Bitcoin ETF Inflows Near $3B Mark Extending Seven-Day Streak

Bitcoin ETFs Extend Seven-Day Inflow Streak to $2.98B as Sentiment ReboundsU.S. spot Bitcoin ETFs...

Tom Lee: Rate Cuts and Neutral Policy Are Bullish for Crypto

Fundstrat's Tom Lee said a new PCE calculation set for Sept. 30 could reduce...

Kalshi loses appeal, setting up potential Supreme Court case

The 6th US Circuit Court of Appeals ruled against prediction market Kalshi, upholding state...

ShinyHunters renew Oracle PeopleSoft attacks via WAF bypass

Google warns of renewed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft by ShinyHunters-linked group...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading