What is happening with LastPass and Bitwarden users?
Are user passwords at risk due to breaches?
Importantly, these attacks do not involve breaches or compromises of LastPass or Bitwarden infrastructures. No password databases have been accessed by the attackers. Instead, this is a classic example of domain spoofing and phishing — where the criminal actors create deceptive emails and web pages mimicking the legitimate brands in order to dupe users into providing sensitive information.
The fraudulent compliance domains involved have been flagged as malicious by security providers such as Microsoft Defender for Office 365 and Cloudflare, and some have already been taken offline.
How can users protect themselves from such phishing attempts?
Users of password managers must maintain a high level of vigilance when receiving emails about account security, especially unexpected ones requesting personal information or credentials. To defend against these attacks, consider the following steps:
- Verify email sender addresses: Check if the domain matches the official company domain. For example, LastPass's official domain is lastpass.com, not lastpassnewsletter.com.
- Avoid clicking on links in suspicious emails: Hover over links to inspect URLs and do not enter credentials on any site that does not have the exact official domain.
- Cross-reference communications: Compare suspicious messages with previous authentic correspondence to spot inconsistencies.
- Use multi-factor authentication (MFA): Enable MFA on password manager accounts to add an additional layer of security even if credentials are compromised.
- Stay updated on alerts directly from the official sources: Always check announcements via official company websites or trusted communication channels.
What are the practical implications for password manager users?
While the passwords themselves remain secure given the lack of breaches, falling victim to these phishing attacks could result in unauthorized account access. This would undermine the primary purpose of using password managers — safeguarding credentials across multiple sites.
Users should never rely solely on emails claiming urgent policy changes or requesting immediate action without verification. Proactive scrutiny and cautious behavior are essential to avoid becoming victims of such schemes.
Overall, this phishing campaign is a reminder that even well-protected passwords can be compromised if users are tricked into revealing them through social engineering. Vigilance in verifying email sources and links is a fundamental defense for anyone using password management services.
