Particle.news
Download on the App Store

Phishing Campaign Impersonates LastPass and Bitwarden to Steal Master Passwords

Security providers have taken down flagged fake compliance sites to disrupt the credential‑harvesting campaign.

Overview

  • Attackers send emails that mimic official newsletter notices and link victims to DocuSign‑style “compliance” pages that ask for logins or offer malicious downloads.
  • Fraudulent domains such as lastpasscompliance[.]com and bitwardencompliance[.]com were flagged by Microsoft Defender for Office 365 and Cloudflare and have been taken offline while monitoring continues.
  • LastPass and Bitwarden say their systems were not breached and LastPass’s TIME team confirmed the campaign, warning the company will never request a master password.
  • The emails use urgency and fake policy changes, including claims of short acceptance windows, to pressure users into clicking and surrendering credentials.
  • Users who clicked or entered data should change master passwords from a trusted device, review vault activity, and report suspicious messages to abuse@lastpass.com.