LastPass Warns of Phishing Campaign Targeting Master Passwords
Active phishing campaign uses spoofed email chains to trick LastPass users into revealing master passwords. Attackers generate thousands of URL variants leading to fake SSO pages.
LastPass is warning customers of an active phishing campaign that began around March 1, 2026, with attackers sending fabricated email chains designed to appear as internal communications about unauthorized account access. The goal: stealing master passwords that unlock entire password vaults.
The company's Threat Intelligence, Mitigation, and Escalation (TIME) team issued an advisory on March 3 detailing the campaign, which exploits how mobile email clients often display only the sender's name while concealing the actual email address unless expanded.
Attack Technique
Attackers use display name spoofing to make emails appear to come from LastPass while using unrelated sender addresses. The phishing emails are being sent from several addresses including [email protected], [email protected], [email protected], [email protected], and [email protected].
Subject lines like "Re: the details," "Re: pending approval," and "RE: sign-in — TRZ-2302300" are designed to look like forwarded internal messages about unauthorized account activity. The emails claim someone is trying to take unauthorized action on the recipient's LastPass account—exporting vault data, performing full account recovery, or registering a new trusted device.
At the center of the phishing infrastructure is the domain verify-lastpass.com. The attackers generate many slightly modified versions of URLs by adding different trailing numbers, allowing them to produce a large set of addresses that all resolve to the same fake single sign-on login page.
Password Managers as High-Value Targets
The messages contain links pointing to fake LastPass login pages designed to harvest master passwords. For threat actors, password manager credentials represent extremely high-value targets. A single compromised master password unlocks access to every credential stored in the vault—banking sites, corporate accounts, cryptocurrency exchanges, email providers.
This campaign follows similar tactics seen in the MetaMask fake incident report phishing operation that used spoofed security alerts to steal cryptocurrency wallet credentials. Social engineering attacks that leverage trust in security providers tend to be more effective because victims already associate the brand with protection.
Users who fall for these phishing attempts may not realize they've been compromised until unauthorized access occurs across multiple accounts. The cascading effect of a password manager breach can be devastating.
Indicators of Compromise
LastPass provided several indicators to help users identify malicious emails:
Known sender addresses:
Malicious domain:
- verify-lastpass.com (and variants with appended numbers)
The emails pass SPF, DKIM, and DMARC authentication checks, which means standard email security controls won't catch them. This is because the attackers use legitimate email sending infrastructure—they're not spoofing the sending domain itself, only the display name.
How to Protect Yourself
LastPass emphasized that no one at the company will ever ask for your master password. If you receive a suspicious email requesting account action:
- Never click links in unsolicited emails about your LastPass account
- Verify sender addresses by expanding email headers, especially on mobile devices
- Navigate directly to lastpass.com if you need to check account status
- Report suspicious emails to [email protected]
- Enable additional authentication if not already using hardware keys or authenticator apps
For organizations using LastPass Enterprise, security teams should alert employees to this campaign and consider implementing additional email filtering rules targeting the known malicious domains.
This marks the second major phishing campaign targeting LastPass customers in 2026. Given the 2022 breach that exposed customer vault data (albeit encrypted), users of the service remain attractive targets for credential theft operations.
Related Articles
LastPass Warns of Phishing Campaign Targeting Master Passwords
Fake maintenance emails urge users to backup their vaults before a deadline, redirecting victims to credential-harvesting sites. The campaign launched over MLK weekend.
Jan 22, 2026Phishers Hide Behind Google Slides Publish Feature
Attackers exploit Google Presentations' publish mode to host phishing pages that bypass Google's own security warnings, targeting Vivaldi Webmail users.
Jan 30, 2026ConsentFix v3 Automates OAuth Phishing Against Azure Tenants
New ConsentFix v3 attack automates Microsoft Azure OAuth credential theft using Pipedream webhooks and Cloudflare phishing pages. Pre-trusted apps bypass MFA entirely.
May 3, 2026Vietnamese Phishing Op Hijacks 30K Facebook Accounts via AppSheet
A Vietnamese threat actor dubbed AccountDumpling compromised 30,000 Facebook Business accounts using Google AppSheet emails to bypass spam filters.
May 2, 2026