Latest News

LastPass phishing campaign used fake DocuSign pages


LastPass is warning users about a new LastPass phishing campaign that begins with an email titled “Action Required: Review Updated LastPass Security Policies” and redirects victims to a fake DocuSign page. The email appears to come from addresses like hello@lastpassnewsletter.com and urges recipients to review an updated policy — a social-engineering lure designed to prompt immediate clicks.

LastPass phishing campaign

What happened

Security teams say attackers sent messages using the subject line “Action Required: Review Updated LastPass Security Policies” and spoofed sender names and addresses such as hello@lastpassnewsletter.com. The message claimed there was an important policy update and included a button that did not go to LastPass but instead redirected through lookalike domains.

Investigators traced the redirect to lastpasscompliance[.]com, a lookalike domain that presented a page styled to resemble DocuSign. That fake landing page then pushed a prompt to download a file described as compatible with Windows and macOS. LastPass told users the sending domains were not affiliated with the company and that its systems were not affected.

By the time defenders responded the specific page was taken offline, but analysts warn the attackers used easily recreated lookalike domains and page templates. The campaign’s subject line and sender display names were designed to look routine and trustworthy to increase click-through rates among busy users.

How the LastPass phishing campaign worked

Attackers combined familiar brand language with domain impersonation and a fake DocuSign interface to reduce suspicion. Once a user clicked the link, the chain redirected through lastpasscompliance[.]com (a lookalike domain) and displayed a counterfeit DocuSign-style page that requested a download. The download prompt — described by defenders as a malicious download — is the primary delivery mechanism for whatever payload the attackers intended.

Security services, including Microsoft Defender for Office 365 and Cloudflare, classified the phishing site as malicious after reports, and LastPass reported the pages for takedown. Security reporting also shows the same approach targeted other password managers; Bitwarden users were targeted with messages from hello@bitwardennewsletter.com and redirects to bitwardencompliance[.]com, indicating attackers are reusing a campaign structure across multiple brands.

How to spot the scam and immediate steps

  1. Delete or report the email. Forward suspicious LastPass-branded messages to abuse@lastpass.com and report phishing to your email provider.
  2. Do not click links or download files from unexpected messages. Treat any attached software as potentially malicious.
  3. Type lastpass.com directly into your browser or open the official LastPass app to check account notices.
  4. Do not reply to the sender, and never enter your master password or one-time codes into unfamiliar pages.
  5. If you opened or downloaded the file, disconnect the device from the internet, run a full antivirus scan with up-to-date definitions, and investigate from a known-good device before changing sensitive passwords.

What LastPass and others say

LastPass told users its systems were not affected and that the sending domains used in the campaign were unaffiliated. According to reporting and LastPass notices, Microsoft Defender for Office 365 and Cloudflare classified the phishing site as malicious and helped with mitigation efforts.

Independent security reporting also identified a parallel against Bitwarden customers using identical social-engineering themes and lookalike domains. That cross-targeting suggests attackers are reusing infrastructure, page templates and mailing lists to scale the scam quickly across multiple password-manager brands.

What to watch next

Because attackers can register new lookalike domains quickly, defenders expect similar pages and subject lines to reappear under different domain names. Blocking a single domain often only provides a brief respite; attackers can swap to new domains or slightly modified sender addresses and relaunch.

Longer-term protections include enabling multi-factor authentication (MFA) on all accounts tied to your password manager and preferring authenticator apps or hardware security keys over SMS-based codes. Authenticator apps (TOTP) or FIDO2 hardware keys significantly reduce the risk of account takeover when credentials are phished.

Avoid relying on autofill on unfamiliar pages: if your password manager refuses to autofill credentials on a page claiming to be LastPass, treat that as a red flag and close the tab. Disallowing browser or extension autofill for unknown domains and checking the address bar carefully before entering any credentials are simple habits that can prevent exploitation.

Finally, watch for reuse of templates: the same fake-DocuSign look can be adapted to other brands, so maintain skepticism for any unexpected policy notices that ask you to download files or enter credentials.

Quick verification steps

If you suspect you interacted with the scam, change your master password from a trusted device using the official LastPass app or lastpass.com, review your vault for unexpected entries, and prioritize changing passwords for email, financial accounts and cloud storage. If you downloaded a file, isolate the device, run antivirus and malware scans, and consider professional incident response if you handle sensitive data.

FAQ

Is the LastPass phishing campaign real?

Yes. Security teams and LastPass confirmed a campaign using lookalike domains and a fake DocuSign page. LastPass said its systems were not affected, but users should remain cautious.

What do I do if I clicked the link or downloaded the file?

Disconnect the device from the internet, run a full antivirus scan with updated definitions, and avoid logging into sensitive accounts until you confirm the device is clean. Change your master password from a known-good device and review your vault for suspicious entries.

How can I tell a fake DocuSign page from the real one?

Check the URL closely: legitimate DocuSign or LastPass pages use official domains. Lookalike domains that merely contain a brand name are not owned by the company. A password manager that refuses to autofill credentials can also signal a fake site.

Source attribution: reporting and statements from LastPass, classification by Microsoft Defender for Office 365 and Cloudflare, security reporting on parallel Bitwarden-targeted messages, and coverage by Fox News: Fake password-manager alerts could put your vault at risk. For suspected phishing affecting LastPass accounts, forward suspicious messages to abuse@lastpass.com.