- Attackers are spoofing LastPass and Bitwarden with phishing emails from fake newsletter domains, tricking users into signing bogus DocuSign documents
- Victims are redirected to malicious “compliance” domains flagged by Microsoft Defender and Cloudflare, already taken offline
- Neither password manager was breached; this is domain spoofing, and users are urged to verify sender addresses and domains before clicking links
Criminals have been found impersonating popular password managers LastPass and Bitwarden online in an attempt to trick users into sharing their login credentials, and thus access to a treasure trove of passwords and other secrets.