Skip to content

Beware: LastPass phishing campaign highlights why you should verify before you click

If you rely on a password manager, a new phishing campaign is a reminder that attackers still go after the human factor.

What happened

LastPass recently warned users about a new phishing campaign designed to trick people into handing over their master password. The emails pretend to come from LastPass, using a spoofed display name and urgent language about unauthorized access or password changes. The campaign urges recipients to revoke devices, disconnect their vault, or report suspicious activity. LastPass has said it’s working with Forta Brand Protection to takedown the malicious sites and with hosting providers to remove the impersonation pages.

Why it matters

Phishing remains one of the easiest ways for attackers to get into a password vault. If a user reveals the master password, attackers can attempt to access stored credentials across sites. This kind of campaign targets individuals and teams that rely on LastPass for daily operations, so even small businesses and creators can be affected.

Practical steps you can take

  • Be skeptical of emails that claim to require you to change or verify your password. When in doubt, don’t click. Go to LastPass by typing the URL into your browser or opening a bookmark.
  • Turn on multi-factor authentication for your LastPass account and use an authenticator app or security key where possible.
  • Check your LastPass account activity and active sessions regularly. Revoke any device you don’t recognize.
  • Enable phishing protections in your email client and consider adding a reputable anti-phishing extension or service.
  • Use a hardware security key (FIDO2) for critical accounts to reduce reliance on passwords alone.
  • For teams and organizations: run quick security awareness checks and simulated phishing to reinforce safe habits.
  • If you suspect your vault was compromised, change your LastPass master password immediately, re-authenticate, and re-seal your vault. Consider re-exporting and re-importing credentials to reset encryption keys.

For more details, see SecurityWeek’s coverage of the LastPass phishing campaign: LastPass Warns of New Phishing Campaign.

Final thought

Phishing won’t disappear, but you can reduce its effectiveness with simple, consistent habits. Take a moment to verify, enable MFA, and stay vigilant—your password vault will thank you.

Leave a Reply

Your email address will not be published. Required fields are marked *