LastPass Phishing Campaign Informs Users of Phony Death Notifications

KnowBe4 Team | Nov 6, 2025

LastPass Phishing CampaignA phishing campaign is targeting LastPass users with phony notifications informing users that someone has notified the company of the user’s death and is trying to gain access to their account. The emails have the subject line, “Legacy Request Opened (URGENT IF YOU ARE NOT DECEASED).”

LastPass describes the following attack flow:

  • “The email claims someone within the recipient’s family has opened a request to access the intended victim’s vault as a legacy user by uploading a death certificate.  
  • The email goes on to include a statement that a live case has been opened and includes fabricated information regarding a supposed agent assigned to the case, including an agent ID number, the date the case opened, and the case priority, all of which are false.  
  • The email then includes a link to cancel the request, which in fact directs the intended victim to the URL ‘https://lastpassrecovery[.]com,’ which then asks for the victim to enter their master password in an attempt to phish credentials.”

Notably, the attackers are also calling recipients of the emails and posing as LastPass representatives, adding another layer of legitimacy to the campaign. Additionally, the attackers are targeting users’ passkeys as well as their passwords.

“[S]everal of the phishing sites are clearly intended to target passkeys, reflecting both the increased interest on the part of cybercriminals in passkeys and the increased adoption on the part of consumers,” LastPass says. “For example, there are numerous variations of “mypasskey[.]info” linked to the malicious IPs.”

LastPass stresses that it will never ask for your master password, and users should maintain a healthy sense of suspicion when they receive unsolicited emails.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

LastPass has the story.


Live Demo: Supercharge Your Anti-Phishing Defense with PhishER Plus

Email alone is the highest cause of data breaches and 56% of all attacks bypass your legacy security filters! The upshot? Legacy email security layers let these digital time bombs slip into the inboxes of your users. Introducing PhishER Plus - the most powerful anti-phishing protection available in the world.

PhishER-Plus

To learn how we can make such a claim, get a product demonstration of the new PhishER add-on, PhishER Plus. In this live one-on-one demo we will show you how you can:

  • Block email threats that have bypassed all other email security filters or systems before they reach your users’ mailboxes with the Global Blocklist
  • Isolate malicious emails that already bypassed your mail filters through automated quarantine with Global PhishRIP
  • Crowdsource threat intelligence from 10+ million KnowBe4 trained users
  • Save time and budget by reducing the volume of remediation efforts handled by your SOC Team
  • Leverage the power of triple-validated threat intelligence to protect your organization from new attacks

Request A Demo

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/products/phisher-plus-request-a-demo



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.