EN·DE
IT Security

Phishing Campaign Targets LastPass and Bitwarden Users With Fake DocuSign Alerts

A new phishing wave impersonates LastPass and Bitwarden, using fake DocuSign landing pages to steal credentials. The malicious sites have been taken down as of July 14.

This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.

A phishing campaign is targeting users of password managers LastPass and Bitwarden with fraudulent security alerts that mimic official corporate communications. The emails inform recipients of supposed policy updates and direct them to a page that looks like DocuSign, where they are prompted to download a file or enter credentials.

LastPass warned users about the ongoing campaign, noting that the phishing emails are sent from hello@lastpassnewsletter.com. The messages claim there have been changes to service policies, including enhanced monitoring of SaaS applications, options for administrators to reset master passwords, and improvements to the admin console. Recipients are asked to click a button labeled 'Review & Access Terms,' which leads to a website impersonating DocuSign hosted at lastpasscompliance[.]com. Security tools from Microsoft and Cloudflare have marked this domain as malicious.

Once on the fake site, users see a prompt to download a file that supposedly works on Windows and macOS. A live support chat option is also available, though it is unclear whether it functions. As of July 14, 2026, the malicious website had been taken offline.

LastPass has stated that its own systems were not breached and that the phishing messages did not originate from its infrastructure. The company reiterated that it never asks users for their master password and urged anyone who receives suspicious emails to forward them to abuse@lastpass.com.

Bitwarden users are also being targeted with similar emails from hello@bitwardennewsletter.com, which redirect to bitwardencompliance[.]com.

This is not the first time LastPass users have been targeted. In March 2026, the company warned about a campaign that used fake alerts about unauthorized account access. Earlier, in January 2026, another wave of phishing emails falsely claimed that users needed to back up their vaults within 24 hours due to maintenance.

Anyone who may have entered their credentials on these phishing sites should change their master password immediately from a trusted device and review their vaults for any unauthorized changes.

Sources

  1. BleepingComputer – LastPass, Bitwarden users targeted with fake security alerts