Latest NewsSCI/EDU

Fake password-manager alerts could put your vault at risk

NEWYou can now listen to Fox News articles!

You open your inbox and see a message about updated security policies. Nothing about it screams scam. The email looks polished, the wording sounds official and the button promises a quick way to review the changes. That is exactly what makes it dangerous.

LastPass is warning users about a newly identified phishing campaign that uses lookalike domains and a fake DocuSign page to lure people into downloading suspicious software.

The good news is that LastPass says its systems were not affected. The bad news is that scammers are counting on you to trust the logo, overlook the web address and click before taking a closer look. Here is what to watch for before one routine-looking email puts your entire password vault at risk.

Free live CyberGuy class: Sick of Spam? Join us July 22

Join us TODAY, Wednesday, July 22, at 1 PM ET for a free CyberGuy Live class that will help you cut down on robocalls, spam texts, junk email and other unwanted messages. Kurt “CyberGuy” Knutsson will walk you step by step through simple ways to filter spam, clean up your inbox and recognize the messages that could put your personal information at risk. No technical experience is needed. You’ll also receive our spam-stopping checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

FBI HELPS TAKE DOWN AI PHISHING RING

Scammers are impersonating LastPass with fake policy emails that lead users to a fraudulent DocuSign page and suspicious software download. (Kurt “CyberGuy” Knutsson)

LastPass phishing scam starts with a routine policy email

The phishing email comes from hello@lastpassnewsletter.com. Its known subject line reads, “Action Required: Review Updated LastPass Security Policies.” Inside, the message claims LastPass has made service policy changes. It mentions enhanced SaaS monitoring. It also claims administrators can reset master passwords and that the admin console has improved.

Those details make the email sound like a real company notice. However, the sending domain belongs to the attackers. LastPass says lastpassnewsletter[.]com has no affiliation with the company. The email includes a Review & Access Terms button. That button creates the next layer of the trap.

Fake LastPass page sends you to a DocuSign lookalike

Clicking the button sends you to lastpasscompliance[.]com. The landing page copies the look of DocuSign and claims a document is ready for review. That choice makes sense from a scammer’s perspective. Many people receive electronic signature requests at work or while handling personal paperwork. A familiar layout can lower your guard before you inspect the web address.

We have seen the same trust trick in other fake DocuSign email scams. The brand name gives the request a sense of legitimacy, even when the sender and domain do not match. LastPass says Microsoft Defender for Office 365 and Cloudflare classified the phishing site as malicious. The page also prompted visitors to download software that claimed to work on Windows and macOS.

LastPass was still investigating the download when it published its warning. Therefore, you should treat the file as dangerous and avoid opening it. The site also displayed a live support chat box, although it was unclear whether the chat worked. The malicious page had gone offline by the time the campaign was reported. However, attackers can quickly replace blocked domains with new ones.

Similar Bitwarden emails widen the warning

LastPass users are not the only targets. Bitwarden customers have received similar messages from hello@bitwardennewsletter.com. Those emails directed recipients to bitwardencompliance[.]com. The matching format suggests attackers may be reusing the same campaign structure across password manager brands.

That matters because password manager customers present an attractive target. One stolen master password could put many saved accounts at risk. Multi-factor authentication may still block access, depending on your security settings.

A password manager remains valuable protection. In fact, autofill can help expose a fake website because the manager should recognize the legitimate domain. You can compare current options in our guide to the best password managers for 2026 at cyberguy.com

LastPass users have faced several phishing lures in 2026

This campaign follows other LastPass-themed phishing attempts from earlier this year. In January, fake messages warned that users had only 24 hours to back up their vaults before maintenance. Then, a March campaign used fabricated email threads about unauthorized account access.

Both approaches relied on urgency to push people into acting before they verified the message. The new compliance notice uses a calmer approach. It looks like paperwork rather than a crisis. That may make it especially effective because policy updates feel normal and boring.

REDHOOK ANDROID MALWARE CAN QUIETLY HIJACK YOUR PHONE

Ways to stay safe from the LastPass phishing scam

A fraudulent DocuSign page is shown.

The fraudulent page impersonates DocuSign and prompts visitors to download suspicious software for Windows or macOS. (LastPass)

A few careful steps can keep one convincing email from turning into a much larger problem.

1) Do not click the policy review button

Delete the message or report it as phishing. Do not reply. Avoid opening its links or downloading the file it offers.

2) Open LastPass on your own

Use the official LastPass app or type lastpass.com into your browser. Check for account notices after you sign in through the trusted route.

3) Read the full domain before entering anything

Lookalike domains often add a trusted brand name to words such as “newsletter” or “compliance.” Check the website address before the first slash. A legitimate LastPass address should end in lastpass.com, such as support.lastpass.com, rather than merely containing the word “LastPass.”

4) Pay attention when autofill stays silent

A password manager may refuse to fill your credentials on a fake domain. Treat that as a warning. Do not copy and paste the password to get around it. Instead, close the page and access your account through the official app or website.

5) Change your master password if you entered it

Use a trusted device and go directly to LastPass. Change the master password immediately. Then review your vault for unexpected activity, as LastPass recommends. Next, change passwords for sensitive accounts stored in the vault if you see signs of access. Start with email, financial accounts, cloud storage and social media. Use a different password for every account.

AMAZON RECALL TEXT SCAM COMES WITH RED FLAGS

Person typing on a Samsung phone.

The scam relies on polished security notices, familiar branding and misleading web addresses to lower users’ defenses. (Kurt “CyberGuy” Knutsson)

6) Treat the download as dangerous

Do not open software offered by a security notice you reached through email. If you already opened the file, disconnect the affected device from the internet. Then use strong antivirus software to inspect it. Our current best antivirus protection guide at cyberguy.com can help you compare tools that block malicious websites and dangerous downloads. It also covers protection against malware. You can also follow these steps after you clicked a suspicious email and entered information.

7) Turn on multi-factor authentication

Enable multi-factor authentication for your password manager and other important accounts. An authenticator app or security key can add a barrier if someone steals your password. However, never approve a login request you did not initiate. A second security step only helps when you treat unexpected prompts as a warning.

8) Reduce the personal information scammers can find

Scammers often use information from data broker sites to make phishing emails feel more personal. That could include your phone number, home address, relatives or past employers. A data removal service can help find and remove some of that information from people-search websites. It will not secure a compromised password manager, but it may give scammers fewer details to use in future attacks. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

9) Report suspicious LastPass messages

Forward questionable LastPass-branded emails to abuse@lastpass.com. LastPass says no one from the company will ever ask for your master password.

Kurt’s key takeaways

What makes this scam dangerous is how normal the email looks. Most people expect password manager alerts to sound urgent. This one arrives dressed up as a boring policy update, which may make you less likely to question it. The biggest red flag is the web address. A company name inside a domain does not mean the company owns it. Before entering a master password or downloading anything, close the email and open the password manager directly. Your master password protects everything stored in your vault. Treat any request for it like someone asking for the keys to your house.

Have you ever received a security email that looked so real you almost clicked? What made you stop and take a closer look? Let us know by writing to us at Cyberguy.com

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com trusted by millions who watch CyberGuy on TV daily.
  • Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.

Copyright 2026 CyberGuy.com. All rights reserved.


Source link

Related Articles

Back to top button