LastPass, Bitwarden users targeted with fake security alerts

A sophisticated phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to trick them into divulging sensitive information. The attackers are using email notifications that appear to be from the password management services, but actually lead to malicious websites that prompt victims to download files or enter their credentials.

LastPass has issued a warning about the phishing campaign, which involves emails sent from addresses resembling legitimate company communications. These messages notify recipients of alleged service policy changes and direct them to review terms on a landing page impersonating DocuSign. However, clicking on the “Review & Access Terms” button leads users to a website with a domain flagged as malicious by security software providers Microsoft Defender for Office 365 and Cloudflare.

The fake sites prompt victims to download files claiming to support both Windows and macOS, while also offering live support through a chat box. It’s unclear whether this feature is functional, but the malicious website has been taken offline at the time of writing. BleepingComputer has discovered that similar emails are being sent to Bitwarden users, redirecting them to bitwardencompliance[.]com.

This phishing campaign bears resemblance to previous attacks on LastPass users in March and January, where fake unauthorized account access alerts and warnings about backing up vaults within 24 hours were used to create a sense of urgency. LastPass has cautioned users that it will never ask for their master password and advised them to report any suspicious communications to abuse@lastpass.com.

The security implications are significant, as the attackers’ goal is likely to obtain sensitive information from victims. Users who enter their credentials on phishing sites are urged to change their master passwords immediately from a trusted device and review their vaults for suspicious activity. This incident serves as a reminder that even reputable password management services can be targeted by sophisticated attacks.

To protect themselves, users should remain vigilant when receiving email notifications about service policy changes or other urgent matters. They should always verify the authenticity of such communications by contacting the company directly using known contact information and not through links in suspicious emails. Additionally, it’s essential to keep software up-to-date and use robust security measures, including multi-factor authentication, to minimize the risk of falling victim to phishing attacks.


Source: Bleeping Computer — 2026-07-14