Fake LastPass support email threads try to steal vault passwords
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户的要求很明确,不需要特定的开头,直接写文章描述即可。 首先,我仔细阅读了文章。这篇文章主要讲的是LastPass公司警告用户他们正在遭受钓鱼攻击。攻击者伪造了LastPass的代表,发送虚假的未经授权账户访问警告邮件。邮件内容看起来像是公司内部转发的对话,目的是让用户感到紧急,点击链接进入伪造的登录页面,从而收集用户的凭证。 接下来,我需要提取关键信息:LastPass警告钓鱼攻击、邮件伪装成公司内部对话、链接指向伪造登录页面、收集用户凭证、攻击者使用多个发送地址和主题来增加可信度、LastPass强调自身基础设施未被攻破,并提醒用户不要泄露主密码。 然后,我需要将这些信息浓缩到100字以内。确保涵盖主要事件:警告、钓鱼手段、目标、后果以及公司的应对措施。 最后,检查语言是否简洁明了,避免使用复杂的句子结构。确保信息准确无误,并且符合用户的要求。 </think> LastPass警告用户正遭遇钓鱼攻击,攻击者伪装成公司代表发送虚假未经授权账户访问通知邮件。邮件内容模仿内部对话,诱导用户点击链接进入伪造登录页面以窃取凭证。攻击者使用多个发送地址和主题增加可信度。LastPass强调其基础设施未受影响,并提醒用户切勿泄露主密码。 2026-3-4 20:45:15 Author: www.bleepingcomputer.com(查看原文) 阅读量:10 收藏

Fake LastPass support email threads try to steal vault passwords

Password management software provider LastPass is warning users of a phishing campaign targeting its users with fake unauthorized account access alerts.

The emails impersonate a LastPass representative by spoofing the display name and use subject lines crafted to mimic forwarded internal conversations between attackers and the company’s customer support team about a request to change the account’s primary email address.

The email chains are forwarded to the target in an attempt to prompt them to respond to the suspicious activity with urgency and click on links named “report suspicious activity,” “disconnect and lock vault,” and “revoke device.”

Example email thread
Example email thread
Source: LastPass

In doing so, users are directed to a fake LastPass login page hosted on the domain “verify-lastpass[.]com” that collects LastPass user credentials.

The LastPass Threat Intelligence, Mitigation, and Escalation (TIME) notes in a report that apart from this primary domain, the attacker also uses slightly modified URLs that redirect to the same phishing page.

LastPass notes that multiple sender addresses and subject lines are used in the campaign to increase credibility and make tracing more difficult.

Most sender addresses are completely unrelated to the LastPass brand, set up from compromised websites or abandoned domains, but the attackers try to hide them by using the ‘LastPass Support’ display name.

The company underlined that its infrastructure has not been compromised in any way, and there’s no impact on its systems.

Moreover, it reminded customers that its support agents will never ask for their master password and that users should never disclose it to anyone.

LastPass is working with third-party partners to take down the fake websites as soon as possible, while urging users who receive suspicious communications to report them to ‘[email protected].’

LastPass’s popularity makes the service a frequent target of phishing campaigns. Earlier this year, in January, LastPass warned of another phishing campaign that distributed fake maintenance notifications, asking users to back up their vaults within 24 hours and redirecting them to phishing pages.

In late 2025, two more campaigns targeting LastPass occurred: one leveraging fake user death claims, and the other claiming the company had been hacked and urging users to download a new version of the client app.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/fake-lastpass-support-email-threads-try-to-steal-vault-passwords/
如有侵权请联系:admin#unsafe.sh