bleeping-computer · Crawled Jul 14, 2026

LastPass, Bitwarden users targeted with fake security alerts

2 IoCs
Read original article ↗

AI Summary

An ongoing phishing campaign is targeting LastPass and Bitwarden users with fake security alerts designed to mimic legitimate corporate communications. The emails direct recipients to fraudulent websites impersonating DocuSign, hosted on malicious domains, where users are prompted to download malicious files. Despite the use of domains resembling official services, LastPass confirms no compromise of its systems and warns users not to provide master passwords via email.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Domain lastpasscompliance[[.]]com Details →
Domain bitwardencompliance[[.]]com Details →