← Blog
For businesses

The LastPass Phishing Email Targeting Businesses: How It Works and How to Stop It

Explore an AI summary

LastPass told its customers this week that attackers are impersonating the company in a phishing campaign built to steal master passwords. To be clear about one thing up front: LastPass was not breached. Its systems are fine. The target is its customers, and for any business whose employees use LastPass, that distinction does not make the risk smaller. A stolen master password is a key to everything behind it.

This is a textbook example of the attack pattern that now costs businesses the most: a trusted brand, an urgent security notice, and a fake login page. Here is how the LastPass phishing email works, why employee training does not reliably stop it, and what businesses can do.


What happened

On July 13, 2026, LastPass's Threat Intelligence team alerted customers to an active phishing campaign. The emails arrive from hello@lastpassnewsletter.com with the subject line "Action Required: Review Updated LastPass Security Policies." They are designed to look like an official LastPass security notice and instruct the recipient to review updated policies through a link.

The attackers registered two lookalike domains that have nothing to do with LastPass: lastpassnewsletter[.]com, used to send the emails, and lastpasscompliance[.]com, the destination site. The link leads to a page that impersonates a third-party service, in this case DocuSign, and prompts the visitor to download software. The end goal is to trick people into handing over their LastPass master password. Microsoft Defender for Office 365 and Cloudflare have both classified the site as malicious.

As LastPass put it, no one at LastPass will ever ask for your master password. The whole campaign runs on manufactured urgency, an "action required" security alert that pressures people to act before they think.


Keep your business safe from online threats

Haven for Business protects every employee from phishing, fake sites, and browser-based attacks.

Why this is dangerous for businesses

The reason a LastPass phishing email is a business problem, not just a personal one, comes down to what the stolen credential unlocks. A master password is not one login among many. It opens the vault that holds every other login an employee uses, including access to company systems, shared credentials, and admin accounts. Compromise one employee's password manager and an attacker may inherit the keys to a large part of your environment.

This is why credential phishing attacks remain the leading way businesses get breached. Attackers no longer need to break your defenses when they can convince one employee to open the door. And the LastPass campaign shows how they do it: impersonate a trusted vendor, wrap the request in the language of security and compliance ("review updated security policies"), and route the victim to a page that looks legitimate.

Three details make this hard for a business to defend with the usual tools. The sending domain is a plausible lookalike, not an obvious fake. The pretext is a routine security-policy update, exactly the kind of message employees are trained to comply with quickly. And the malicious payload sits behind a link, so the email itself can look clean until someone clicks. By the time an employee is on the fake page entering a password, the trust decision has already been made.


Why training and filters are not enough on their own

Security awareness training helps, but it asks employees to notice something is wrong in the exact moment an attacker has engineered to feel normal. A message that impersonates your password manager and cites a security-policy update is designed to pass the sniff test. Filters help too, but lookalike domains and freshly registered phishing pages can slip through before they are widely flagged, and the malicious step often happens after the click, on the web page rather than in the inbox.

That gap, between the click and the credential, is where this campaign does its work. It is also the layer most business security stacks watch the least.


How Haven helps businesses protect employees from phishing

Haven is a browser-security companion that works at that exact moment, when an employee lands on a page and is about to enter credentials. Detecting fake and impersonated login pages is what Haven does. When a site mimics a trusted brand, copying the look, the layout, and the branding to harvest credentials, Haven is designed to recognize it as fraudulent and warn the person before they type anything.

It does not matter how the link arrived, an email, a chat message, a search result, or how convincing the page looks. Haven analyzes the page in front of the employee rather than trusting the sender or the branding. For a campaign like this one, which puts real effort into making every step look legitimate right up to the fake login, that browser-level check is the layer built to catch what training and email filters miss.

Haven is free for individual use, so employees can protect their own browsing immediately, and Haven for Business extends that browser-level protection across a team. No tool can promise to stop every attack, and we will not claim that. What Haven offers is coverage where businesses are most exposed, the moment an employee decides to trust a login page.


What to do now

If your organization uses LastPass, or any password manager or major vendor, a few steps reduce your exposure to this campaign and the ones that follow it.

Tell your team about this specific lure: an email from lastpassnewsletter.com with the subject "Action Required: Review Updated LastPass Security Policies." Remind everyone that no one at LastPass will ever ask for a master password. Reinforce the habit of reaching vendors directly, by typing the address or using a bookmark, rather than clicking links in security-alert emails. Prioritize phishing-resistant multi-factor authentication, such as hardware keys or passkeys, for high-value accounts. And add a browser-layer control that flags fake login pages at the point of credential entry, so a convincing lookalike cannot quietly harvest an employee's password.

If an employee did enter their master password, have them change it immediately from a trusted device and review the vault for unexpected activity, and report the email to the vendor (LastPass asks customers to forward suspicious messages to abuse@lastpass.com).

The LastPass phishing email is a reminder that attackers do not need to breach a security company to exploit its brand. They only need one employee to trust the wrong page. Closing that gap, at the browser, in the moment of the decision, is increasingly part of what it means to protect a business from phishing.


About Haven

Haven is a browser-security companion that helps people and organizations make safer trust decisions online. It works at the browser level, in the moment between clicking a link and entering your information, to flag suspicious sites, fake login pages, and phishing before you act on them. Rather than relying only on lists of known threats, Haven analyzes the page in front of you, which helps it catch newly created and impersonated pages that other tools can miss.

Haven is free for individual use, and Haven for Business extends browser-level protection across a team. Haven is operated by MirrorTab, Inc.


FAQs

Is the LastPass "security policies" email real?

No. The email with the subject "Action Required: Review Updated LastPass Security Policies," sent from hello@lastpassnewsletter.com, is a phishing scam. LastPass confirmed it is not an official message and that its systems were not breached. The email impersonates a LastPass security notice to trick recipients into entering their master password on a fake site. Do not click the links.

Did LastPass get breached in this attack?

No. LastPass stated that its systems are not affected. This is an impersonation campaign that abuses the LastPass brand and lookalike domains to phish customers directly. The risk comes from employees being tricked into handing over their master password, not from a compromise of LastPass itself.

Why is a LastPass phishing email a risk for businesses?

Because a master password unlocks an employee's entire password vault, which can include access to company systems, shared credentials, and admin accounts. A single successful credential phishing attack against one employee can expose a large part of an organization's environment, which is why this is a business security issue and not only a personal one.

How can businesses protect employees from phishing like this?

Combine awareness of the specific lure with controls that work at the moment of risk. Tell employees not to act on urgent security-policy emails, reinforce reaching vendors directly instead of via email links, require phishing-resistant multi-factor authentication for high-value accounts, and add a browser-layer tool that flags fake login pages before credentials are entered. Layered defenses matter because no single control catches everything.

What is a lookalike domain?

A lookalike domain is a web address registered to resemble a trusted brand so that phishing emails and pages appear legitimate. In this campaign, attackers used lastpassnewsletter[.]com and lastpasscompliance[.]com, neither of which is affiliated with LastPass. Lookalike domains are effective because they pass a quick glance and can slip past filters before they are widely flagged.

How does Haven help against credential phishing attacks?

Haven is a browser-security companion that detects fake and impersonated login pages and warns the user before they enter their credentials. Because it analyzes the actual page rather than trusting the sender or branding, it is built to catch convincing lookalike login pages regardless of how the link was delivered. Haven is free for individual use, and Haven for Business extends browser-level protection across a team.