• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords

You are here: Home / General Cyber Security News / LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
January 21, 2026

LastPass is alerting users to a new active phishing campaign that’s impersonating the password management service, which aims to trick users into giving up their master passwords.

The campaign, which began on or around January 19, 2026, involves sending phishing emails claiming upcoming maintenance and urging them to create a local backup of their password vaults in the next 24 hours. The messages, LastPass said, come with the following subject lines –

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


  • LastPass Infrastructure Update: Secure Your Vault Now
  • Your Data, Your Protection: Create a Backup Before Maintenance
  • Don’t Miss Out: Backup Your Vault Before Maintenance
  • Important: LastPass Maintenance & Your Vault Security
  • Protect Your Passwords: Backup Your Vault (24-Hour Window)

Cybersecurity

The emails are designed to steer unsuspecting users to a phishing site (“group-content-gen2.s3.eu-west-3.amazonaws[.]com/5yaVgx51ZzGf”) that then redirects to the domain “mail-lastpass[.]com.”

The company emphasized that it will never ask users for their master passwords and that it’s working with third-party partners to take the malicious infrastructure down. It has also shared the email addresses from which the messages originate –

  • support@sr22vegas[.]com
  • support@lastpass[.]server8
  • support@lastpass[.]server7
  • support@lastpass[.]server3

“This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks, a spokesperson for the Threat Intelligence, Mitigation, and Escalation (TIME) team at LastPass told The Hacker News in a statement.

“We want customers and the broader security community to be aware that LastPass will never ask for their master password or demand immediate action under a tight deadline. We thank our customers for staying vigilant and continuing to report suspicious activity.”

The development comes months after LastPass cautioned users of an information-stealing campaign targeting Apple macOS users through fake GitHub repositories that distribute malware-laced programs masquerading as the password manager and other popular software.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «cert/cc warns binary parser bug allows node.js privilege level code execution CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
  • CERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
  • North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
  • Three Flaws in Anthropic MCP Git Server Enable File Access and Code Execution
  • Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading
  • The Hidden Risk of Orphan Accounts
  • Evelyn Stealer Malware Abuses VS Code Extensions to Steal Developer Credentials and Crypto
  • Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
  • Why Secrets in JavaScript Bundles are Still Being Missed
  • Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion

Copyright © TheCyberSecurity.News, All Rights Reserved.