Fake password-manager alerts could put your vault at risk
LastPass has warned users about a new phishing campaign that uses lookalike domains and a fake DocuSign page to trick people into downloading malicious software, potentially putting their password vaults at risk. The company has confirmed its own systems were not compromised, but the scam relies on convincing, official-looking emails that prompt recipients to click through before scrutinising the sender's actual web address, making it easy to fall for.
The attackers reportedly send polished emails about supposed security policy updates, directing recipients to a fraudulent DocuSign-style page rather than a genuine LastPass site. From there, victims are lured into downloading suspicious software. LastPass is urging users to check web addresses carefully, avoid clicking links in unsolicited emails, and remain cautious of messages that create a sense of urgency around account security.
- LastPass warns of phishing scam using fake DocuSign pages.
- LastPass's own systems were not affected.
- Scam relies on convincing emails to bypass user caution.
Americas Business Cybersecurity Elections Markets Politics Software Technology World