<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Cybercriminals Launch Sophisticated Phishing Attack Targeting LastPass Users

Beware of new phishing scams targeting LastPass users. Learn how to protect your vault during this ongoing threat.
Content Team

LastPass customers are being targeted in an ongoing phishing campaign that began around January 19, strategically timed during the Martin Luther King Jr. Day holiday weekend when security teams have reduced staffing.

The attackers are sending convincing emails from addresses like support@lastpass[.]server8, urging users to "back up their vaults" due to fake scheduled maintenance. Subject lines include "LastPass Infrastructure Update: Secure Your Vault Now" and "Protect Your Passwords: Backup Your Vault (24-Hour Window)."

These emails lead to phishing sites designed to steal login credentials, potentially giving criminals access to entire password vaults. LastPass emphasizes they never ask for master passwords and advises customers to report suspicious emails to abuse@lastpass.com. While no accounts appear compromised yet, the company recommends enabling multifactor authentication for added protection.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo