
Attackers are running a phishing campaign aimed specifically at people who use password managers. If you use LastPass or Bitwarden, you may receive an email that looks like an official security warning from the service, claiming that someone has logged into your account or that your account has been locked for suspicious activity.
The email contains a link that leads to a convincing fake login page. If you enter your master password there, the attackers collect it immediately. With your master password, they can decrypt and access every username and password stored in your vault — your bank, email, social media, and anything else you’ve saved.
How to check if you’re affected
Affected versions include all versions of the LastPass and Bitwarden apps across desktop, browser extension, and mobile. Check your email inbox for any urgent-sounding messages from these services. If you clicked a link in such an email and entered your master password on a webpage, you should act immediately:
- Go directly to the official site by typing lastpass.com or bitwarden.com in your browser — never from a link in an email.
- Change your master password right away.
- Enable two-factor authentication if you haven’t already — this adds a second layer of protection even if your password is stolen.
Real security alerts from LastPass or Bitwarden will never ask you to log in by clicking a link in an email.
