LastPass Warns of Phishing Campaign Using 2 Fake Domains and DocuSign Lures
Updated
Updated · Fox News · Jul 22
LastPass Warns of Phishing Campaign Using 2 Fake Domains and DocuSign Lures
3 articles · Updated · Fox News · Jul 22
Summary
LastPass said attackers sent policy-update emails from lastpassnewsletter.com that pushed users to click a “Review & Access Terms” button and trust a fake compliance notice.
The link led to lastpasscompliance.com, a bogus DocuSign-style page that prompted Windows and macOS software downloads; LastPass said its own systems were unaffected and the file should be treated as dangerous.
Bitwarden users received near-identical emails from bitwardennewsletter.com directing them to bitwardencompliance.com, suggesting the same playbook is being reused across password-manager brands.
Microsoft Defender for Office 365 and Cloudflare flagged the LastPass phishing site as malicious, and although it was offline by the time of reporting, LastPass warned attackers can quickly rotate to new domains.
The campaign follows earlier 2026 LastPass-themed phishing waves in January and March, underscoring how password-manager users remain high-value targets because one stolen master password can expose many accounts.