A new LastPass phishing campaign is targeting users with convincing security notification emails that imitate official company messages. The fraudulent emails claim to announce updated security policies before directing recipients to fake DocuSign pages designed to deceive them.
LastPass says its systems remain secure and confirms the emails were not sent from its infrastructure.
Fake LastPass Emails Mimic Official Security Updates
The phishing emails are sent from the address hello@lastpassnewsletter.com, which is designed to appear trustworthy at first glance.
Recipients are told that LastPass has introduced new security measures and updated service policies. The messages mention features such as:
- Enhanced SaaS monitoring
- Administrator password reset options
- Improvements to the admin console
To review the alleged policy changes, users are encouraged to click a “Review & Access Terms” button.
Fake DocuSign Page Delivers Malicious Downloads
Instead of opening a legitimate document, the button redirects users to a fake website impersonating DocuSign.
The phishing site uses the domain lastpasscompliance[.]com, which has already been flagged as malicious by multiple security services.
Once on the page, visitors are prompted to download a file that claims to support both Windows and macOS systems.
The fake website also displays a live chat feature, although it remains unclear whether the support function was operational. At the time of reporting, the phishing site had already been taken offline.
Similar Campaign Targets Bitwarden Users
Researchers also discovered a nearly identical campaign aimed at Bitwarden users.
Those phishing emails arrive from hello@bitwardennewsletter.com and redirect victims to bitwardencompliance[.]com, following the same strategy used against LastPass customers.
The similarities suggest attackers are targeting multiple password manager users with the same phishing template.
LastPass Warns Users to Stay Alert
This is not the first phishing campaign to abuse the LastPass brand.
In March, attackers distributed fake account compromise alerts that created a false sense of urgency. Earlier in the year, users also received fraudulent emails claiming they had just 24 hours to back up their password vaults before scheduled maintenance.
LastPass reminds users that it will never request their master password through email or other unsolicited communications.
The company also encourages anyone who receives suspicious messages to report them to abuse@lastpass.com.
What to Do If You Clicked the Link
Anyone who entered credentials on one of the phishing websites should act immediately.
LastPass recommends changing the master password from a trusted device and reviewing the password vault for any unauthorized activity. Users should also verify that no sensitive information has been modified or accessed unexpectedly.
Remaining cautious with unexpected emails and verifying domains before clicking links remains one of the best defenses against phishing attacks.


0 responses to “LastPass Phishing Campaign Uses Fake Security Notices to Target Users”