← All news

phishing

LastPass and Bitwarden Users Hit by Fake Compliance Phish

2026-07-15

LastPass is warning customers about a phishing campaign built to look like a boring policy update. The emails arrive from [email protected], mention enhanced SaaS monitoring and admin console tweaks, and invite the recipient to click a neat little button labelled Review & Access Terms.

That button leads to lastpasscompliance[.]com, a page pretending to be DocuSign and offering a file to download for both Windows and macOS. Microsoft Defender and Cloudflare have flagged the domain as malicious and it has since been pulled offline. LastPass has been clear that its own systems were not breached and the emails did not come from its infrastructure.

Bitwarden users are getting the same treatment

BleepingComputer spotted near-identical emails aimed at Bitwarden customers, this time from [email protected] and pointing to bitwardencompliance[.]com. Same template, same fake DocuSign flow, different logo swapped in at the top.

Whoever is running this has clearly built a reusable kit and is working through the password manager market brand by brand. It would not be a surprise to see 1Password, Dashlane or Keeper users get the same treatment next week.

LastPass has been here before

This is at least the third round of the same basic con this year:

  • January: emails telling users to back up their vaults within 24 hours or lose access.
  • March: fake unauthorised access alerts urging an immediate login.
  • Now: fake compliance updates dressed up in DocuSign clothing.

The urgency script changes. The target never does. Get the master password, get into the vault, get everything inside it: banking logins, email recovery codes, crypto seed phrases, the lot. A password manager is a single point of trust, which is exactly what makes it worth attacking.

What the fake looks like up close

The emails are polished. The sender domain looks plausible if you are skim-reading. The button copy is corporate and dull, which is the point. Nothing in the message screams "phish" the way a badly translated Nigerian prince once did. The only tell, really, is the ask itself. A password manager vendor sending you to a DocuSign page to download a client is not a normal thing to do, and neither is any legitimate service asking you to re-enter your master password on a linked page.

LastPass has repeated the line it has been repeating for years: it will never ask for a master password. Anyone who has typed theirs into one of these pages should change it from a device they trust, check their vault history for unfamiliar logins, and rotate anything sensitive that lives inside.

The bit worth sitting with

The interesting thing here is not the malware or the domains, both of which are already dead. It is the industrialisation. One template, swap the branding, fire it at the next vendor's userbase, move on. The attackers are treating password managers as a category, not individual targets, and the people receiving these emails are the exact users who already believed they were doing the right thing by using one.

That is a harder problem to fix with filters. It is a problem of what people are trained to notice in a hurry.

LastPass and Bitwarden Users Hit by Fake Compliance Phish | RiskSense