LastPass warns of campaign to grab master passwords

Password manager firm LastPass is warning customers to be on guard for a new phishing campaign which is attempting to steal master passwords.

The campaign was first detected over the weekend, which the company suspects was timed to coincide with Martin Luther King Jr Day on Monday. This gives US companies a long weekend when they may have fewer security staff on duty than normal.

The phishing emails claim that LastPass is conducting maintenance and prompts users to backup their password vaults in the next 24 hours. The email contains a link to “Create Backup Now”, which redirects to a malicious phishing site where customers are prompted to enter their password.

LastPass says it is “working with third-party partners to have this domain taken down as soon as possible”.

LastPass’s security notice also includes the URLs and IP addresses associated with the attack, which companies may want to add to their own blocklists in the meantime.

Password manager attacks

Although the use of password managers is generally considered to be much safer than committing passwords to memory, attacks such as this highlight the vulnerability of password managers if malicious actors gain access to master passwords.

Most password managers (including LastPass) offer some form of two-factor authentication, which means that even if hackers manage to gain access to your master password, they wouldn’t be able to log in on a new device without getting a code from an authenticator app or SMS message.

However, two-factor authentication isn’t mandatory on LastPass accounts. The company recommends that admins for LastPass Teams or LastPass Business do enable multi-factor authentication, giving instructions on how to set this up on the LastPass support page.

Last year, LastPass was fined ยฃ1.2 million by the UK’s Information Commissioner’s Office for failings in a 2022 data breach with saw customers’ personal data compromised. A hacker installed malware on an employee’s laptop and used that to steal their master password, giving the hacker access to the firm’s customer database.

The ICO found that “LastPass failed to implement sufficiently robust technical and security measures, which ultimately enabled a hacker to gain unauthorised access to its backup database”.

Avatar photo
Barry Collins

Barry has 25 years of experience working on national newspapers, websites and magazines. He was editor of PC Pro and is co-editor and co-owner of BigTechQuestion.com. He has published a number of articles on TechFinitive covering data, innovation and cybersecurity.