Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On
Delta CEO blasts Congress over unpaid TSA agents as airport chaos continues: ‘Inexcusable’

Delta CEO blasts Congress over unpaid TSA agents as airport chaos continues: ‘Inexcusable’

March 19, 2026

OpenAI’s Pivot To Enterprise Is Likely A Race Against Anthropic, And The IPO Clock

March 19, 2026
Oil jumps above 9 a barrel after Iran attacked energy facilities across Middle East

Oil jumps above $119 a barrel after Iran attacked energy facilities across Middle East

March 19, 2026
Apple News blasted after boosting coverage by conservative outlets from 0% to 2% in February: ‘Damage control’

Apple News blasted after boosting coverage by conservative outlets from 0% to 2% in February: ‘Damage control’

March 19, 2026
What legit actually looks like

What legit actually looks like

March 19, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » LastPass Issues Critical Warning For Users — Password Attacks Underway

LastPass Issues Critical Warning For Users — Password Attacks Underway

By News RoomJanuary 23, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
LastPass Issues Critical Warning For Users — Password Attacks Underway
Share
Facebook Twitter LinkedIn Pinterest Email

Updated January 23 with further analysis from the LastPass Threat Intelligence, Mitigation, and Escalation team as the suspected actors behind the ongoing master password attacks evolve the campaign.

As password hacking attacks continue to compromise accounts across multiple platforms and services, the most repeated advice is to use a password manager to create and store credentials more securely. But what if the password manager comes under attack? Millions of users of one of the biggest password managers, LastPass, have been warned that an ongoing attack that began on January 19 is targeting them. Here’s what you need to know and do.

LastPass Threat Intelligence, Mitigation, And Escalation Team Issues Critical Security Warning For All Users

Threats to your account credentials come in many forms, from a myriad of info-stealing malware, to barely credible but hugely dangerous hack-your-own-password attacks. The most commonplace and the most concerning, as a consequence, come by way of phishing campaigns.

It is one such new and ongoing campaign that has prompted the LastPass Threat Intelligence, Mitigation, and Escalation team to issue a critical security alert that millions of password manager users would be well-advised to take note of.

The TIME team, which doesn’t include Baldrick of Blackadder fame before readers of a certain age ask, has warned that the attacks, that started on January 19, make a claim “that LastPass is about to conduct maintenance and urging users to backup their vaults in the next 24 hours.” This displays the typical tactic of bringing time-based pressure to leverage action from the recipient, in this case, to click a backup now button that would actually kickstart a process of stealing account credentials.

“Please remember that no one at LastPass will ever ask for your master password,” the LastPass warning stated, before advising any users who are unsure if a LastPass-branded email is legitimate or not to “submit it to [email protected].”

Updated: The Latest LastPass Threat Intelligence Concerning The Master Password Attack Campaign

The LastPass Threat Intelligence, Mitigation, and Escalation team is doing a first-class job of keeping on top of the master password compromise attack campaign, and has now updated its intel. The update, published January 22, confirmed: “The suspected threat actors behind this campaign have sent another wave of phishing emails using similar tactics. The body of the email remains the same, but the links have been changed following LastPass’ disruption of their initial infrastructure in conjunction with our partners. We also found other domains registered, likely by this threat actor given the use of similar procedures, that indicate a broader infrastructure that may be used or have been used in this and/or other phishing campaigns.” The updated list of indicators of compromise, along with URLs and associated IPs, can be found in the report as linked above.

“While this is always a best practice,” a LastPass TIME spokesperson said, “we recommend you confirm any email claiming to be from LastPass are coming from legitimate LastPass email domains as this campaign is ongoing.”

LastPass Master Password Targeted In New Attack Campaign

“This attack is very similar to your average Credential Phishing attack,” Chance Caldwell, senior director of the Phishing Defense Center at Cofense, said, “but unlike many phishing scams that target single accounts, this one focuses on a password manager’s master login.” If attackers collect this, they could gain access to virtually every login and secret stored in the vault, Caldwell warned, adding that attacks such as these can be very successful due to the use of legitimate branding, look-alike domains, having a task with a time limit, and exploiting what could be a real feature in the request to backup data. “Users should be trained to never enter their master password into a site reached via an emailed link and to contact a company through a separate source to verify the authenticity of a request if needed.”

The Cofense cyber intelligence manager, Max Gannon, told me that while users of any password management software need to be vigilant for attacks spoofing their provider, “this goes doubly for LastPass users who have been targeted several times by particularly well-developed phishing campaigns.”

“This campaign is designed to create a false sense of urgency, which is one of the most common and effective tactics we see in phishing attacks,” a LastPass Threat Intelligence, Mitigation, and Escalation team spokesperson said. “We want customers and the broader security community to be aware that LastPass will never ask for their master password or demand immediate action under a tight deadline. We thank our customers for staying vigilant and continuing to report suspicious activity.”

LastPass attack LastPass backup LastPass hack LastPass password LastPass phishing attack LastPass security warning password hack
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

OpenAI’s Pivot To Enterprise Is Likely A Race Against Anthropic, And The IPO Clock

March 19, 2026

The New Chief AI Officers In The Enterprise Org Chart

March 17, 2026

“85% Of What I Do Basically Can Be Done By AI,” Says Top Tech Investor

March 16, 2026

NYT Strands Hints Today: Tuesday, March 17 Clues And Answers (Happy Saint Patrick’s Day!)

March 16, 2026

How AI Is Tracking Illegal Wildlife Trade Hidden In Online Marketplaces

March 15, 2026

Naval Ravikant’s AI Thesis Is Playing Out In Public Markets

March 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

OpenAI’s Pivot To Enterprise Is Likely A Race Against Anthropic, And The IPO Clock

Tech March 19, 2026

On March 16, Fidji Simo, OpenAI’s chief of applications, held an all-hands meeting with employees…

Oil jumps above 9 a barrel after Iran attacked energy facilities across Middle East

Oil jumps above $119 a barrel after Iran attacked energy facilities across Middle East

March 19, 2026
Apple News blasted after boosting coverage by conservative outlets from 0% to 2% in February: ‘Damage control’

Apple News blasted after boosting coverage by conservative outlets from 0% to 2% in February: ‘Damage control’

March 19, 2026
What legit actually looks like

What legit actually looks like

March 19, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks
X — formerly known as Twitter — is experiencing outages, users reporting social media site is down

X — formerly known as Twitter — is experiencing outages, users reporting social media site is down

March 19, 2026
Meta locks in Fifth Avenue flagship retail store with 10-year lease

Meta locks in Fifth Avenue flagship retail store with 10-year lease

March 18, 2026
What is the Jones Act and why Trump wants to waive the law

What is the Jones Act and why Trump wants to waive the law

March 18, 2026
Bombshell AI study — chatbots fueling delusions, self-harm and unhealthy emotional attachments in users: ‘Think I love you’

Bombshell AI study — chatbots fueling delusions, self-harm and unhealthy emotional attachments in users: ‘Think I love you’

March 18, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.