HomeSecurityNew phishing campaign targets LastPass users

New phishing campaign targets LastPass users

LastPass has issued a warning to its customers about a new, highly convincing phishingthat attempts to steal passwords and passkeys through fake “account inheritance process” requests.

 LastPass phishing

The campaign, which began in mid-October 2025, is attributed to the CryptoChameleon (UNC5356) — a financially motivated scheme known for attacks against cryptocurrency users and security services.

How the “inheritance” trick works

The inheritance process is an emergency access feature of LastPass that allows users to designate trusted individuals who can request access to their vault in the event of death or incapacity. Cybercriminals are exploiting this very feature by creating fake access requests that appear to come from relatives or estate administrators.

See also: Firefox: New extensions must declare data collection practices

The fraudulent emails state that “a family member has submitted a death certificate” and urge the recipient to “cancel” the process if they are alive by clicking on a link. The link leads to a well-crafted imitation of the recovery page (lastpassrecovery[.]com), where the victim is asked to enter their master password — effectively handing it over to the perpetrators.

Social engineering and phone scams

In several cases, attackers didn't limit themselves to emails. LastPass reported incidents where victims received phone calls from people pretending to be the company's support staff, encouraging them to enter their credentials on a "recovery page."

New phishing campaign targets LastPass users

The use of voice communication (vishing) adds additional credibility, while combined with legitimate message templates and request codes, makes the fraud particularly difficult to detect.

From LastPass to crypto wallets

The CryptoChameleon group has a long history of stealing digital assets. The phishing kit it uses includes fake login pages for well-known platforms like Binance, Coinbase, Kraken, and Gemini , as well as identity services like Okta, Gmail, iCloud, and Outlook .

See also: Evolution of phishing attacks to bypass defenses

This year’s campaign shows a clear technological upgrade: in addition to passwords, it now targets passkeys – the new passwordless authentication credentials. Threat actors have begun to construct fake domains like mypasskey[.]info and passkeysetup[.]com, to steal users’ passkeys.

Why passkeys became a target

Passkeys are considered the future of secure logins, replacing traditional passwords with public-private key pairs. Services like LastPass, 1Password, and Bitwarden already support them, storing them in sync across all of a user's devices .

It is precisely this collection of critical credentials that makes password managers an attractive target. With a successful attack, attackers can gain access not only to the victim’s accounts, but also to their digital wallets — leading to irreparable losses.

Flashback: The 2022 incident

This isn't the first time LastPass has been targeted. In 2022, the company suffered a major breach in which attackers gained access to encrypted vault backups . Despite the passwords being encrypted, subsequent attacks targeted specific users, causing losses estimated at $4.4 million in cryptocurrency.

The new wave of phishing appears to utilize the same victim identification techniques, but with significantly more sophisticated social engineering and an emphasis on passkeys.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: 40% of victims who pay for ransomware lose their data

New phishing campaign targets LastPass users

What users can do

The company urges its customers to ignore any “legacy requests” if they have not enabled the feature. Users should carefully check the URL of any login page and never enter their master password into links in emails.

LastPass also recommends using multi-factor authentication (MFA) and adding security alerts through the app to detect suspicious login attempts in a timely manner.

This case confirms that cybercriminals are evolving faster than ever, adapting their techniques to new security standards. With the shift from traditional passwords to passkeys, “digital phishing” is taking on a new form — smarter, more targeted, and just as dangerous.

User security now depends on their knowledge and vigilance. Every email, every link, and every “support request” can be the new trap.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS