
Phishing waves hit LastPass and Bitwarden with fake security alerts
A targeted phishing campaign uses fake LastPass and Bitwarden security notices, directing recipients to a DocuSign-like landing page hosted on malicious domains (lastpasscompliance[.]com and bitwardencompliance[.]com). Emails originate from [email protected] and [email protected]. LastPass and Bitwarden say their infrastructure was not compromised and they will never ask for a master password. The bogus site prompts a download and offers live chat; its goal is credential theft. Users should report suspicious messages to [email protected], change their master passwords from a trusted device, and review vault activity. Some of the malicious sites have been taken offline, and this campaign follows similar fake alerts seen earlier in the year.










