Skip to main content
See every side of every news story
Published loading...Updated

Don’t click the LastPass 'create backup' link

The phishing campaign began Jan. 19, exploiting holiday staffing gaps to steal master passwords and access users' stored credentials, LastPass said.

  • LastPass on Tuesday warned users about phishing emails falsely claiming scheduled maintenance and urging vault backups within 24 hours; the campaign began around January 19, with a January 20 screenshot showing a 'Create Backup Now' link.
  • The campaign used urgency to prompt immediate action, as threat actors timed messages over the Martin Luther King Jr. holiday weekend to exploit reduced staffing and target password managers.
  • Messages carried subject lines like the ones LastPass listed and came from spoofed addresses such as support@lastpassserver8, redirecting first to group-content-gen2.s3.eu-west-3.amazonawscom/5yaVgx51ZzGf and then to mail-lastpasscom.
  • LastPass reiterated that 'no one at LastPass will ever ask for your master password' and urged users to report suspicious emails to abuse@lastpass.com while working with third-party partners to take down fake domains soon.
  • This episode follows earlier phishing campaigns against LastPass, including an October last year phishing campaign and recent campaigns, as the company published indicators and overhauled security after a 2022 breach.
Insights by Ground AI

12 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 83% of the sources are Center
83% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news in on Wednesday, January 21, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal