Fake LastPass and Bitwarden security-policy emails send users to phishing sites posing as DocuSign

LastPass and Bitwarden users are being targeted by phishing emails that pretend to announce security-policy changes and send people to fake DocuSign-style websites. The messages came from lookalike sender addresses such as hello@lastpassnewsletter.com and hello@bitwardennewsletter.com and linked to domains including lastpasscompliance.com and bitwardencompliance.com. LastPass said its own systems were not breached; the sites reportedly offered a file download for Windows and macOS, suggesting credential theft or malware delivery.
Why it matters: Password-manager users are high-value targets because one stolen master password can expose many other accounts. Users should avoid these messages, verify any alerts directly in the official app or website, and immediately change their master password from a trusted device if they entered it on a phishing page.

Sources

LastPass, Bitwarden users targeted with fake security alerts
Bill Toulas 2026.07.14 100% relevant
This article establishes a distinct ongoing phishing campaign using fake LastPass and Bitwarden security notices and lookalike compliance domains to lure users to fraudulent sites.
← Back to all stories