Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
LECS 320x100 1
970x120 Olympous
LastPass Phishing Attack: Protect Your Master Password Now

LastPass Phishing Attack: Protect Your Master Password Now

22 January 2026 15:38

On January 21, 2026, LastPass warned its users about a new and active phishing campaign aimed at stealing customers’ master passwords through fake official communications.

According to LastPass’s Threat Intelligence, Mitigation, and Escalation (TIME) team, the attack began around January 19, 2026 , and uses social engineering tactics to induce a sense of urgency.

Fraudulent emails use the pretext of upcoming service maintenance, urging recipients to create a local backup of their password vault within 24 hours . To maximize the effectiveness of the deception, the messages feature various subject lines, including:

  • LastPass Infrastructure Update: Secure Your Vault Now
  • Your Data, Your Protection: Create a Backup Before Maintenance
  • Don’t Miss Out: Backup Your Vault Before Maintenance
  • Important: LastPass Maintenance & Your Vault Security
  • Protect Your Passwords: Backup Your Vault (24-Hour Window)

The attack mechanism involves a link that initially directs the victim to an AWS bucket (group-content-gen2.s3.eu-west-3.amazonaws[.]com/5yaVgx51ZzGf) and then redirects the victim to the malicious domain mail-lastpass[.]com , designed to mimic the original LastPass interface and capture the entered master password.

LastPass has firmly reiterated that it will never request a master password via email or force users to take immediate action under pressure. The company is working with external partners to dismantle the fraudulent infrastructure and has confirmed that the emails originate from the following suspicious addresses:

  • support@sr22vegas[.]com
  • support@lastpass[.]server8
  • support@lastpass[.]server7
  • support@lastpass[.]server3

The company invites all users to pay maximum attention, not to click on suspicious links and to report any anomalies through official channels.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.