Overview
- Attackers send emails that mimic official newsletter notices and link victims to DocuSign‑style “compliance” pages that ask for logins or offer malicious downloads.
- Fraudulent domains such as lastpasscompliance[.]com and bitwardencompliance[.]com were flagged by Microsoft Defender for Office 365 and Cloudflare and have been taken offline while monitoring continues.
- LastPass and Bitwarden say their systems were not breached and LastPass’s TIME team confirmed the campaign, warning the company will never request a master password.
- The emails use urgency and fake policy changes, including claims of short acceptance windows, to pressure users into clicking and surrendering credentials.
- Users who clicked or entered data should change master passwords from a trusted device, review vault activity, and report suspicious messages to abuse@lastpass.com.