LastPass and Bitwarden users are being targeted by a sophisticated phishing campaign that uses fake security alerts to trick victims into handing over sensitive information. The malicious emails, which have been sent to both LastPass and Bitwarden users, appear to be legitimate corporate communications from the password management companies.
The emails claim to notify recipients of updated security policies, such as enhanced SaaS monitoring and master password reset options for administrators. However, clicking on the “Review & Access Terms” button embedded in the email takes users to a website impersonating DocuSign, a widely used service for sending, signing, and managing documents electronically. The domain used by the attackers, lastpasscompliance[.]com, has been flagged as malicious by Microsoft Defender for Office 365 and Cloudflare.
But here’s the kicker: LastPass’ systems have not been compromised, and the phishing emails did not originate from its infrastructure. The attackers are using domains designed to appear as legitimate company services in an attempt to trick users into trusting the fake sites. It’s a classic case of social engineering, where attackers use psychological manipulation to get victims to do their bidding.
This is not the first time LastPass has been targeted by phishing campaigns. In March, the company warned about fake unauthorized account access alerts impersonating the password service. And earlier in January, users were targeted with fake alerts claiming they needed to back up their vaults within 24 hours due to upcoming system maintenance. It’s clear that attackers are getting more sophisticated and brazen in their attempts to steal sensitive information.
So what does this mean for LastPass and Bitwarden users? First and foremost, it means being vigilant when receiving emails from these companies. If you receive an email claiming to be from LastPass or Bitwarden, verify the sender’s email address and check for any misspellings or typos in the domain name. And if the email is asking you to download a file or click on a link, don’t do it.
If you have already fallen victim to this phishing campaign, change your master password immediately from a trusted device and review your vaults for suspicious activity. It’s also essential to report any suspicious communications to the companies’ abuse teams, such as LastPass’ abuse@lastpass.com.
As we’ve seen time and again, security awareness is key in preventing these types of attacks. By being informed and taking simple precautions, you can significantly reduce your risk of falling victim to phishing campaigns like this one. Remember: test every layer before attackers do – and stay one step ahead of the bad guys!
Source: Bleeping Computer — 2026-07-14