LastPass warned customers about an active phishing campaign using spoofed “security alert” emails that claim unauthorized access, vault export attempts, account recovery, or new device registration to pressure users into taking action. The messages spoof the LastPass display name (relying on many clients—especially mobile—showing only the display name) and direct victims to a fake SSO login page at verify-lastpass[.]com to steal credentials; LastPass reiterated it will never ask for a user’s master password and said it is working with partners to take down the phishing infrastructure.
Separately, researchers reported a coordinated phishing operation that abuses Google Cloud Storage (GCS) to host redirector content on a legitimate Google domain (storage.googleapis.com) to help links evade email security controls. Analysis tied 25+ distinct lure emails (e.g., “storage full,” “antivirus expired,” and brand-themed reward scams) to a single GCS bucket (whilewait) hosting comessuccess.html, which functions as a gatekeeper/redirector that forwards victims to third-party malicious sites associated with credential and/or payment-card harvesting and potential malware delivery; the consistent destination across varied themes indicates centralized attacker-controlled cloud infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting described the campaign's end goal as stealing payment card details through fake shipping, service-charge, or renewal payment prompts shown after redirection. Researchers also advised inspecting redirect chains, validating suspicious sender metadata, and reporting the abusive GCS bucket to Google Cloud for takedown.
After analyzing inbox activity and SMTP headers, a threat hunter linked the emails to a single Google Cloud Storage bucket, "whilewait," hosting an attacker-controlled HTML file named comessuccess.html. The page functioned as a script-heavy redirector that silently sent victims to external malicious sites.
In early March 2026, researchers identified a coordinated phishing campaign that sent more than 25 distinct emails to a single account while routing victims through a Google Cloud Storage URL on storage.googleapis.com. The campaign used varied lures but relied on the same trusted Google-hosted delivery path to evade email security controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalwr-analysis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.