HomeSecurityPhishing campaign misuses LastPass name - Company denies breach

Phishing campaign misuses LastPass name – Company denies breach

LastPass , one of the world's most well-known password management platforms, has warned its users that it has not been the victim of any cyberattack , despite the emergence of an extensive phishing campaign attempting to exploit its brand.

LastPass phishing

The malicious emails had the subject line “We’ve been hacked – Update your LastPass desktop app to keep your Vault secure” and were sent from addresses such as hello@lastpasspulse[.]blog and hello@lastpassgazette[.]blog.

The company explained that this is a classic social engineering tactic, where attackers try to cause panic so that victims will hastily follow instructions without checking the authenticity of the message.

" It's an attempt to create a false sense of urgency – a common trick in phishing emails ," LastPass said on its official blog

How the attack works

Scammers use deceptive links that supposedly lead to an “updated” version of the LastPass desktop app. In reality, the links redirect victims to fake websites, such as lastpassdesktop[.]com and lastpassgazette[.]blog, which are designed to credentials login.

See also: US Q3: 23 million people affected by data breaches

An additional domain, lastpassdesktop[.]app, has also been detected and may be used in future versions of the same campaign. According to initial analysis, the malicious websites are hosted through the NiceNIC, while Cloudflare has already activated warning pages, preventing unsuspecting users from submitting their details.

LastPass confirmed that it is working with hosting providers and internet authorities to take down the domains as soon as possible.

Phishing campaign hijacks the name of LastPass - The company denies breach

Imitation attempts also for 1Password

LastPass isn't the only company targeted by cybercriminals. In recent weeks, Malwarebytes have uncovered a similarly targeted phishing campaign against 1Password, another popular password manager .

According to Pieter Arntz , a security researcher at Malwarebytes Labs, the scammers attempted to gain access to the credentials of a Malwarebytes employee

“Stealing someone’s 1Password login credentials would be for cybercriminals like hitting the jackpot,” Arntz commented. “It would allow them to extract all of the target’s stored passwords and personal information.”

See also: US charges Cambodian man with massive crypto fraud

A similar campaign was uncovered by Brett Christensen, who spotted fake emails pretending to be from 1Password, informing users that their accounts had been compromised. The links led to phishing websites, which asked victims to reveal their secret key – the key that grants full access to each user’s vault.

Password managers are in attackers' sights

Password managers, such as LastPass, 1Password , and other platforms, have become an attractive target for cybercriminals. The logic is simple: a successful attack on one such account can provide mass access to dozens or hundreds of user accounts, from email to banking portals.

Even if companies themselves have strong encryption and multi-layered security, the weak links remain users – especially when they are lured by convincing fake emails. Experts emphasize that such attacks rely more on deception than technology.

See also: Chinese hackers exploit Geo-Mapping Tool for prolonged presence on networks

Phishing campaign hijacks the name of LastPass - The company denies breach

How to protect yourself from phishing attacks

Experts recommend the following preventive measures:

  1. Always check the sender address – Attackers often use similar domains with slight variations.
  2. Never click on links from unexpected emails, even if they look "official".
  3. Avoid entering login details on websites that do not have a security certificate (HTTPS).
  4. Enable two-factor authentication (2FA) for each account.
  5. Visit applications only through official websites or stores (Google Play, App Store).

An increasing phenomenon that requires vigilance

Phishing attacks that mimic well-known brands like LastPass and 1Password demonstrate that cybercriminals are investing in psychological persuasion and deception more than ever. As password management platforms become a staple of our digital lives, user vigilance is now as important as technical security measures.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS