A sophisticated phishing campaign is targeting users of popular password managers, including LastPass and Bitwarden, with fake security policy update emails that could compromise their digital vaults. The emails, which appear polished and official, are designed to trick recipients into clicking a link that leads to a malicious website mimicking DocuSign, where they are prompted to download suspicious software.

LastPass has issued a warning about the campaign, emphasizing that its own systems were not breached. The phishing emails, sent from the domain lastpassnewsletter[.]com, carry the subject line “Action Required: Review Updated LastPass Security Policies.” The message references service policy changes, enhanced SaaS monitoring, and administrative console improvements, making it sound like a routine company notice. However, LastPass confirms that the sending domain has no affiliation with the company.

Clicking the “Review & Access Terms” button in the email redirects users to lastpasscompliance[.]com, a lookalike domain that copies the visual design of DocuSign, a widely used electronic signature platform. The page claims a document is ready for review, a tactic that exploits the familiarity many users have with digital signature requests. Security tools, including Microsoft Defender for Office 365 and Cloudflare, have classified the phishing site as malicious. The site also displayed a live support chat box, though its functionality remains unclear.

The malicious page prompted visitors to download software that claimed to work on both Windows and macOS. LastPass was still investigating the downloaded file when it published its warning, and users are advised to treat the file as dangerous and avoid opening it. The phishing site has since gone offline, but attackers can quickly replace blocked domains with new ones, making continued vigilance essential.

The campaign is not limited to LastPass users. Bitwarden customers have received similar emails from hello@bitwardennewsletter[.]com, which direct recipients to bitwardencompliance[.]com. The matching format suggests that attackers are reusing the same campaign structure across multiple password manager brands. This is particularly concerning because password manager customers present an attractive target: a single stolen master password could expose numerous saved accounts.

This campaign follows earlier LastPass-themed phishing attempts from earlier this year. In January, fake messages warned users that they had only 24 hours to back up their vaults before maintenance. A March campaign used fabricated email threads about unauthorized account access. Both relied on urgency to push users into acting before verifying the message. The new compliance notice takes a calmer approach, resembling routine paperwork rather than a crisis, which may make it especially effective.

Security experts recommend several steps to avoid falling victim to such scams. Users should delete suspicious emails or report them as phishing, avoid clicking links or downloading files from unverified sources, and access their password manager accounts only through the official app or by typing the correct URL directly into a browser. Lookalike domains often incorporate trusted brand names with words like “newsletter” or “compliance,” so checking the website address before the first slash is crucial. A legitimate LastPass address should end in, such as, rather than merely containing the word “LastPass.”

If a password manager refuses to fill credentials on a website, that should be treated as a warning. Users should not copy and paste passwords to bypass the block. Instead, they should close the page and access their account through the official app or website. After logging in through a trusted route, users should change their master password immediately and review their vault for any unexpected activity. Sensitive accounts stored in the vault, particularly email, financial accounts, and cloud storage, should have their passwords changed if there are signs of unauthorized access.

Multi-factor authentication can provide an additional layer of security, potentially blocking access even if a master password is compromised. Password managers remain a valuable tool for protecting online accounts, and autofill features can help expose fake websites because the manager should recognize the legitimate domain. Users are encouraged to stay informed about the latest threats and to adopt cautious habits when handling unsolicited communications.