You trust your password manager to protect your credentials, documents, and identity data—and you probably also trust the instructions from your password manager and the steps to maintain that security. Scammers are counting on this: A new phishing campaign is targeting LastPass and Bitwarden users with fake security alerts to compromise their data and devices.
Earlier this week, Warning to LastPass users An impersonation scam in which threat actors are sending phishing emails that look like official security notifications. Messages from hello(at)lastpassnewsletter(.)com come with the subject line “Action Required: Review Updated LastPass Security Policies.”
In the email body, the attackers outlined the alleged changes to LastPass security monitoring and reporting protocols and noted that users “have 14 business days to review and accept the advanced terms” from DocuSign. The link redirected to https(:)//lastpasscompliance(.)com/, which looked like a legitimate DocuSign page, complete with a chatbot window, prompting users to “download” DocuSign to review and sign the document. It is unclear whether the goal was to spread malware or harvest user credentials, as the malicious website has since been taken down. However, Bitwarden users have been targeted with almost identical campaigns, According to the bleeping computer.
How to spot a password manager scam
On the surface, phishing emails targeting LastPass and Bitwarden users are pretty convincing. They have some technical jargon, so users can look at the specifications and trust that the information is legitimate. There’s a call to action, but the email states that users have 14 days to accept the terms or their account “may be temporarily banned”—so the urgency is a bit less than in some other scams. The email also assures users that their vaults and accounts are “fully secure” and states that the necessary steps are “strictly” administrative.
What do you think so far?
That said, both the sender and the URL should raise suspicion. Neither lastpassnewsletter(.)com nor lastpasscompliance(.)com are official LastPass domains, nor is bitwardencompliance(.)com an actual Bitwarden site. Never enter your master password or other credentials unless you navigate directly to your password manager’s website or vault—links in email, text, or social media messages are vulnerable to phishing attempts. If you have provided your credentials on a suspicious site, update them immediately from a trusted device. You also do not need to download software or use DocuSign for your password manager, and any actions on your account must occur when you are logged into a legitimate site or vault.





