Phishing Campaign Impersonates LastPass and Bitwarden Security Alerts to Deliver Fake DocuSign Pages
Phishing Campaign Impersonates LastPass and Bitwarden (TL-2026-1315), also tracked as LastPass/Bitwarden Compliance Phishing, is a medium-severity phishing campaign, first published 2026-07-14. It has no confirmed attribution, affects LastPass LastPass end users / brand identity, maps to 19 MITRE ATT&CK techniques (T1036, T1041, T1056.001), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-1315
- Threat ID
- TL-2026-1315
- Also known as
- LastPass/Bitwarden Compliance Phishing, DocuSign-Themed Password Manager Phishing
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-14
- Last reviewed
- 2026-07-14
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- all sectors - broad consumer enterprise password-manager user base
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Phishing Campaign Impersonates LastPass and Bitwarden
Malware and tooling: ScreenConnect, Syncro
A phishing campaign spoofs LastPass and Bitwarden corporate newsletter addresses (hello@lastpassnewsletter.com, hello@bitwardennewsletter.com) to send fake security-policy update emails, driving victims to fraudulent DocuSign-styled landing pages at lastpasscompliance[.]com and bitwardencompliance[.]com that prompt Windows/macOS downloads. It is the fourth documented wave of LastPass/Bitwarden brand-impersonation phishing since October 2025, following campaigns that delivered the Syncro RMM tool and ScreenConnect for full vault/endpoint compromise.
How Phishing Campaign Impersonates LastPass and Bitwarden works
On July 14, 2026, BleepingComputer reported an active phishing campaign impersonating both LastPass and Bitwarden — two of the most widely used cross-platform password managers — using spoofed corporate-newsletter sender addresses (hello@lastpassnewsletter.com and hello@bitwardennewsletter.com). The lures present as routine security-policy update notifications and direct recipients to "Review & Access Terms" on fraudulent, DocuSign-branded landing pages hosted at lastpasscompliance[.]com and bitwardencompliance[.]com. Both domains were flagged as malicious by Microsoft Defender for Office 365 and Cloudflare; the LastPass-themed domain was already taken offline by publication time, indicating active takedown response. The DocuSign-styled pages present a fake "document for review" and prompt victims to download a client supporting both Windows and macOS — mirroring the cross-platform delivery model used in prior waves of this same campaign family — with the final payload's objective unconfirmed at time of reporting.
This is not an isolated incident. It is the latest in a sustained, recurring pattern of LastPass/Bitwarden brand-impersonation phishing dating back at least to October 16, 2025, when a nearly identical campaign (sender domains lastpasspulse[.]blog / lastpasjournal[.]blog, weekend-timed for reduced defender response) used fake "we have been hacked" breach alerts to trick users into installing an MSI-based binary that silently deployed the Syncro remote monitoring and management (RMM) tool, beaconing to a C2 server roughly every 90 seconds and configured to evade Emsisoft, Webroot, and Bitdefender. Syncro was then used to pull down ScreenConnect for full interactive remote access, file enumeration, credential harvesting, and password-vault compromise. A follow-on wave beginning January 19, 2026 used fake "scheduled maintenance" emails urging users to create local vault backups within 24 hours (also credential-harvesting bait), and a March 1, 2026 wave used display-name-spoofed forwarded-message lures (subjects like "Re: pending approval", "Fwd: Re: your request") pointing to a fake LastPass SSO page at verify-lastpass[.]com, hosted behind compromised third-party redirect domains (hancochem[.]at, atomicminerals[.]ca, redlakegold[.]ca, bedfordmetals[.]com, 79resources[.]com). LastPass has publicly confirmed on its own blog that these campaigns are unauthorized abuse of its brand and that no LastPass systems were compromised.
The consistent playbook across all four waves — spoofed/lookalike sender infrastructure, urgency-driven security/compliance framing, cross-platform malicious downloads, and rapid domain rotation — indicates a persistent, financially motivated actor or affiliate group targeting the large installed base of password-manager users to obtain master-password/vault access, a high-value target because a single successful compromise can cascade into every credential a victim has stored. Neither the specific payload delivered by the July 14 DocuSign-styled pages nor definitive attribution linking it to the same actor behind the Syncro/ScreenConnect and verify-lastpass waves has been confirmed by public reporting; documentation below treats the July 14 IOCs as the confirmed incident and the prior waves as sourced related-campaign context supporting the TTP pattern.
MITRE ATT&CK techniques used in TL-2026-1315
Defense Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056.001 Keylogging; T1110 Brute Force; T1555 Credentials from Password Stores
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools
Discovery
T1083 File and Directory Discovery
Collection
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Persistence
T1547 Boot or Logon Autostart Execution
Initial Access
T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
T1583.001 Domains; T1585.002 Email Accounts; T1587.001 Malware
Reconnaissance
defense-impairment
Affected products and versions in Phishing Campaign Impersonates LastPass and Bitwarden
- LastPass — LastPass end users / brand identity
Vulnerable versions: N/A - social engineering, not a product vulnerability - Bitwarden — Bitwarden end users / brand identity
Vulnerable versions: N/A - social engineering, not a product vulnerability - DocuSign — DocuSign brand identity (impersonated landing-page template)
Vulnerable versions: N/A - brand spoofed, no DocuSign product involved
Remediation for Phishing Campaign Impersonates LastPass and Bitwarden
Immediate actions
- Block/sinkhole lastpasscompliance[.]com and bitwardencompliance[.]com at DNS/perimeter proxy
- Block sender domains lastpassnewsletter.com and bitwardennewsletter.com at the mail gateway
- Search mail logs for delivered messages from hello@lastpassnewsletter.com / hello@bitwardennewsletter.com and quarantine/recall
- Alert users: LastPass and Bitwarden do not send 'compliance' or 'terms of service' update emails requiring DocuSign-style document review
- Scan endpoints for unauthorized Syncro or ScreenConnect installations given the established payload pattern from prior waves of this campaign
Workarounds
- Verify any LastPass/Bitwarden security notification by navigating directly to the vendor's official site/app rather than clicking email links
- Treat any 'download a new desktop client' or 'review updated terms via DocuSign' request in a password-manager email as malicious
Longer-term hardening
- Deploy DMARC/DKIM/SPF enforcement and brand-impersonation detection to catch lookalike newsletter/compliance subdomains for high-value SaaS brands
- Restrict RMM tool installation via application allowlisting / approval workflow to prevent Syncro-class living-off-trusted-tools abuse
- User security-awareness training specifically covering password-manager 'breach alert' and 'compliance update' phishing lures
- Deploy hardware-based MFA on password-manager and email accounts to limit blast radius of master-password theft
Timeline of Phishing Campaign Impersonates LastPass and Bitwarden
- Syncro RMM agent observed beaconing to attacker C2 approximately every 90 seconds, subsequently used to deploy ScreenConnect for full remote access and vault-credential harvesting.
- First documented wave of this campaign family reported: fake LastPass/Bitwarden 'we have been hacked' breach alerts delivering an MSI-based Syncro RMM installer, timed over a holiday weekend to delay response.
- Second wave begins: fake 'scheduled maintenance' emails urge LastPass users to create a local vault backup within 24 hours, driving traffic to credential-harvesting pages.
- LastPass publishes an official blog post confirming the phishing campaign is unauthorized brand abuse and that no LastPass systems were compromised.
- Third wave begins: display-name-spoofed 'forwarded message' lures (e.g. 'Re: pending approval') direct victims to a fake LastPass SSO page at verify-lastpass[.]com, hosted via compromised third-party redirect domains.
- The lastpasscompliance[.]com domain is taken offline, indicating an active takedown response already underway at time of reporting.
- Both phishing domains are flagged as malicious by Microsoft Defender for Office 365 and Cloudflare.
- BleepingComputer reports the current wave: spoofed hello@lastpassnewsletter.com and hello@bitwardennewsletter.com senders driving victims to DocuSign-styled fraudulent landing pages at lastpasscompliance[.]com and bitwardencompliance[.]com.
Sources cited for Phishing Campaign Impersonates LastPass and Bitwarden
- LastPass, Bitwarden users targeted with fake security alerts
- Phishing Campaign Targets LastPass and Bitwarden Users
- LastPass and Bitwarden users are being targeted by phishing emails
- Fake LastPass and Bitwarden 'Breach Alerts' Lead to PC Hijacks via Remote Access Tools
- LastPass, Bitwarden spoofed in ongoing phishing campaign
- LastPass Warns of Fake Maintenance Messages Targeting Users' Master Passwords
- Fake LastPass maintenance emails target users
- LastPass warns of spoofed alerts aimed at stealing master passwords
- LastPass warns of fake security alerts targeting account credentials
- New Phishing Campaign Targeting LastPass Customers
- LastPass Alerts Customers of Fake Email Chains Used in New Phishing Campaign; No Impact to LastPass Systems
- Password Manager Phishing Attacks: How LastPass, 1Password & Bitwarden Are Impersonated
Threats related to Phishing Campaign Impersonates LastPass and Bitwarden
- Invisible Unicode Tag Characters Used to Evade Phishing Detection in Financial Scam Campaign
- Cross-Platform Phishing Campaigns Auto-Adapt Payloads to Victim Device/OS via Fingerprinting
- AI-Accelerated Phone Scam (Vishing/TOAD) Campaigns Impersonating Amazon, Microsoft, PayPal, Norton, GitHub, Canva, Geek Squad, Temu, Target and the FTC
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry
- 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud
- Fake Voicemail SVG Phishing Campaign Bypasses Email Filters via MIME Spoofing
Detection coverage for TL-2026-1315
As of 2026-07-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1315 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.