A new phishing attack targeting LastPass users has emerged, starting around March 1, 2026. The campaign, identified by LastPass Threat Intelligence, Mitigation, and Escalation (TIME), involves malicious actors impersonating LastPass support staff via fraudulent emails.
These emails seek to trick recipients into revealing sensitive credentials by mimicking internal messages about unauthorized account actions.
This is a classic example of a social engineering attack that relies on urgency to persuade users into acting hastily.
Attack Overview and Methods
The phishing emails are designed to appear as if they have been forwarded from another individual, warning of unauthorized actions such as exporting the vault, initiating full account recovery, or registering a new trusted device.
The attackers use display-name spoofing, where the sender’s name appears to be from LastPass, but the actual email address is unrelated.
Many email clients, especially mobile ones, display only the display name, concealing the true sender’s address, which attackers exploit.
The emails instruct the recipients to take urgent actions such as reporting suspicious activity, locking their vault, or revoking a device.
These instructions include links that redirect users to a fake Single Sign-On (SSO) login page hosted. This phishing site is designed to look like LastPass’s genuine login page, tricking users into entering their credentials.

LastPass reminds all users that the company will never ask for your master password through email or other communications.
If you receive any email that seems suspicious, you are advised to submit it to for verification.
While LastPass works with its third-party partners to shut down the phishing sites as quickly as possible, users should remain cautious and follow best practices to protect their credentials.
If in doubt, do not click on any links or provide any information through unsolicited emails. Always navigate directly to the LastPass website to log in securely.
.webp)
Indicators Of Compromise (IOCs)
Several malicious URLs and associated IP addresses have been identified, which are crucial for detecting and blocking the phishing campaign:
- Malicious URLs:
- http://verify-lastpass[.]com/login?13 (Primary URL used for phishing)
- Other variations of this URL are generated with different trailing numbers (e.g., login? 14, login?12) that lead to the same phishing page.
- Malicious IP addresses:
- 172.67.200[.]82
- 104.21.21[.]204
- 52.102.103[.]4
.webp)
These URLs and IP addresses are central to the attack’s infrastructure, redirecting victims to the phishing pages.
LastPass customers who encounter these phishing attempts should remain alert and report any suspicious activities. The company is actively monitoring the situation to ensure that the phishing sites are removed promptly.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.