LastPass warned of an active phishing campaign impersonating the service with fake “infrastructure maintenance” notifications that pressure users to “back up” their password vaults within 24 hours. The emails are crafted to create urgency and direct recipients to click a “Create Backup Now” link, with the apparent goal of hijacking accounts and stealing vault master passwords; LastPass emphasized it will never ask customers to provide their master password or demand immediate action under a tight deadline.
LastPass’ Threat Intelligence, Mitigation, and Escalation (TIME) team assessed the campaign as starting around January 19, 2026, and observed messages sent from addresses including support@lastpass[.]server8 and support@sr22vegas[.]com (with additional reported senders support@lastpass[.]server7 and support@lastpass[.]server3). Reported infrastructure used in the lure included an Amazon S3 URL group-content-gen2.s3.eu-west-3.amazonaws[.]com/5yaVgx51ZzGf that redirected to mail-lastpass[.]com; LastPass said it is working with third-party partners to take down the malicious infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting on 2026-01-21 and 2026-01-22 said the lookalike domain mail-lastpass[.]com was offline or had been taken down. This followed LastPass's stated efforts with third-party partners to remove the campaign's infrastructure.
As part of its public warning, LastPass disclosed known indicators associated with the campaign, including sender addresses, subject lines, domains, URLs, and IP addresses. These details were provided to help defenders identify and block the phishing activity.
On 2026-01-20, LastPass published a blog post warning customers that it was not requesting vault backups and would never ask for a master password. The company advised users to report suspicious emails to abuse@lastpass.com and said it was working with partners to disrupt the malicious infrastructure.
Observed phishing emails sent users through an Amazon S3-hosted URL before redirecting them to the lookalike domain mail-lastpass[.]com, where credentials could be harvested. Example lures and reporting indicate this infrastructure was active by 2026-01-20.
LastPass said its TIME team observed a phishing campaign starting around 2026-01-19, with emails impersonating LastPass maintenance notices and urging users to back up their vaults within 24 hours. The campaign used urgency, spoofed or lookalike sender addresses, and links intended to steal customers' master passwords.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcetechrepublic.com
Open sourcesecpod.com
Open sourcescworld.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceblog.lastpass.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.