LastPass Phishing Campaign is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 6, 2025; most recent activity November 6, 2025.
The LastPass phishing campaign is a social-engineering operation targeting LastPass users, leveraging phony death notifications to prompt recipients to click malicious links and reveal credentials. Attackers impersonate LastPass branding and use urgent framing to harvest usernames, passwords, and potentially MFA tokens, highlighting a risk to password-manager users and the broader credential ecosystem.
A phishing campaign is targeting LastPass users by sending emails that falsely claim someone has reported the user's death. The emails, titled 'Legacy Request Opened (URGENT IF YOU ARE NOT DECEASED),' aim to deceive…
A phishing campaign is targeting LastPass users by sending emails that falsely claim someone has reported the user's death, attempting to gain access to their accounts. The emails feature a subject line stating, 'Legacy…