LastPass warned of an active phishing campaign using spoofed “security alert” and “support thread” emails that claim unauthorized access, master password changes, vault export attempts, account recovery, or new device registration. The messages abuse display-name spoofing (e.g., “LastPass Support”) to hide unrelated sender addresses—often from compromised sites or abandoned domains—and use urgent calls to action such as “report suspicious activity,” “disconnect and lock vault,” and “revoke device” to drive clicks.
Victims who follow the links are directed to a fake LastPass SSO/login page hosted primarily on verify-lastpass[.]com, with additional lookalike/modified URLs redirecting to the same credential-harvesting site, aiming to steal users’ master passwords and account credentials. LastPass stated its own infrastructure was not compromised, is working with partners to take down the phishing domains, and reiterated it will never ask users for their master password; users are advised to report suspicious LastPass-branded emails to abuse@lastpass.com.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-03, LastPass's TIME team publicly warned customers about the campaign, stating that LastPass infrastructure had not been compromised and that the main risk was credential theft through fake login pages. The company said it would never ask for a master password, shared indicators such as malicious domains including verify-lastpass[.]com, and said it was working with partners to take down the phishing infrastructure.
Around 2026-03-01, attackers began sending spoofed LastPass security-alert emails designed to trick users into disclosing their master passwords. The messages used display-name spoofing and fake forwarded support threads claiming suspicious actions such as vault exports, account recovery, or new device registration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.