Back to news
Cybersecurity Alert
July 19, 2026 by EmailMeNow IT Consulting

Phishing Campaign Hits LastPass and Bitwarden Users With Fake Security Policy Emails

LastPass warned July 13, 2026 of lookalike-domain phishing (lastpassnewsletter.com / lastpasscompliance.com) impersonating DocuSign. A parallel Bitwarden lure uses bitwardennewsletter.com. Neither vault vendor was breached. Audits: bitwarden.com 78%, docusign.com 72%, lastpass.com 66% — all below the 100% ideal, with lastpass.com at 15% transport.

Source: LastPass Threat Intelligence · TechRadar

NewsPhishingLastPassBitwardenPassword ManagersCybersecurity
Password vault under phishing attack from fake policy emails and a deceptive compliance portal

Password-manager customers are being hunted with fake “security policy” emails — not a vault-vendor breach. On July 13, 2026, LastPass Threat Intelligence warned of an active phishing campaign using lookalike domains. Coverage from TechRadar and independent analysis also describes a parallel Bitwarden-themed lure. LastPass systems were not affected; the goal is to steal master passwords and push a malicious download via a fake DocuSign-style portal.

This is separate from our earlier June 2026 LastPass / Klue supply-chain report, which involved stolen CRM/support metadata — not this lookalike-domain compliance scam.

We scanned lastpass.com, bitwarden.com, and docusign.com (the brand being impersonated on the landing page) to assess public email and domain security posture while this campaign is active.

Password vault under phishing attack from fake policy emails and a deceptive compliance portal

What Happened

According to the LastPass TIME advisory and corroborating reporting:

FieldDetail
IdentifiedJuly 13, 2026 (LastPass TIME)
TargetsLastPass users; parallel Bitwarden-themed lure reported
Vendor systemsNot compromised (LastPass explicitly; campaign is phishing, not a product breach)
LastPass lure senderhello@lastpassnewsletter.com
LastPass subjectAction Required: Review Updated LastPass Security Policies
Lookalike mail domainlastpassnewsletter.com (Amazon SES sending IP cited by LastPass)
Fake landinglastpasscompliance.com — DocuSign-style page prompting a software download
Bitwarden parallelhello@bitwardennewsletter.combitwardencompliance.com (per campaign analysis)
Defenses that flagged itMicrosoft Defender for Office 365 SafeLinks; Cloudflare “Suspected Phishing”
Artifact (SHA-256)8ae49ed3cb1e076fd12eb1f5489f1be0c9be4264731b3afd4175cf3284bc1b79

Attack flow

  1. Urgency email — “review updated security policies” from a lookalike newsletter domain.
  2. Brand handoff — button leads to a password-manager-themed compliance host.
  3. Fake DocuSign screen — pressure to download a “desktop application” to review or sign.
  4. Master-password / malware risk — entering the vault master password or running the download can expose every credential the vault protects.

Legitimate vault app contrasted with a fake DocuSign-style compliance download page

Real vs fake — quick checks

CheckWhat to verify
Sender domainOfficial LastPass mail uses LastPass domains — not *newsletter.com / *compliance.com. Bitwarden automated mail is documented from official Bitwarden senders (e.g. no-reply@bitwarden.com), not lookalike newsletter hosts.
DestinationPreview the real host before clicking; prefer the saved app or a typed bookmark.
Master passwordPassword managers should not autofill the master password on lookalike domains. Never type it from an unexpected email.
Download requestA policy notice should not require an unknown “DocuSign desktop app.” Stop before downloading.

LastPass will never ask for your master password. Forward suspicious LastPass-branded mail to abuse@lastpass.com.

Campaign pattern in 2026

WaveFocusMethod
January 2026LastPassFake vault-backup / deadline alerts
March 2026LastPassImpersonated unauthorized-access warnings
July 2026LastPass and BitwardenFake compliance + DocuSign download lure

Independent Cybersecurity Audit

We ran an EmailMeNow Cybersecurity Audit of the legitimate brand domains on July 19, 2026 (ideal score = 100%):

DomainOverallIdentityTransportWebsiteRisk
bitwarden.com78%65%45%100%Good
docusign.com72%95%45%40%Good
lastpass.com66%50%15%100%Above Average

Key findings:

  • None reach the 100% ideal. Bitwarden leads overall at 78% (Good); LastPass sits at 66% (Above Average) despite a perfect Website score.
  • lastpass.com shows 50% Identity and 15% Transport — gaps that make spoofed or weakly authenticated “security notice” mail easier to deliver into the same inboxes attackers are already targeting with lookalike domains.
  • bitwarden.com (65% Identity / 45% Transport) is stronger on transport than LastPass in this pass, but still below the ideal for a vault vendor whose customers are high-value phishing targets.
  • docusign.com scores 95% Identity — strong public spoofing controls on the real brand, while attackers abuse unrelated lookalike hosts to fake a DocuSign experience. Impersonation of a well-hardened brand does not require compromising that brand’s DNS.

Illustration of incomplete email domain security gauges versus a 100 percent ideal target

Public audit scores do not cause this phishing wave. They do show why hardening identity and transport toward 100% still matters: when lookalike domains fail, attackers fall back on spoofed display names and weak mail paths against the real brands customers trust.

Audit links:

Website stack note

Passive website-tech probes on July 19, 2026 completed for 3 of 3 audited domains. The passive probe found no notable public CMS, PHP, CVE-hint, or short-horizon TLS signals. docusign.com resolved as Next.js (version not exposed; no automated freshness flag).

These marketing-site results do not test the phishing lookalike hosts and do not invalidate the primary disclosure: the risk in this story is credential theft via fake policy email + DocuSign-style download, not a CMS-core headline on lastpass.com / bitwarden.com.

These passive observations are point-in-time public signals. They do not prove exploitability, identify a breach path, or establish that a detected major version is unsupported.

Priority Actions

If you use LastPass or Bitwarden:

  1. Do not click links in unexpected “security policy” or “compliance” mail — open the official app or type the known URL.
  2. Never enter your master password on a page reached from email.
  3. If you entered the master password: change it from a trusted device, revoke other sessions, review vault activity / MFA, then rotate high-value stored passwords.
  4. If you downloaded a file: do not run it; delete it and scan. If you ran it: isolate the device, scan thoroughly, and change passwords only from a clean machine.
  5. Report LastPass-themed lures to abuse@lastpass.com; Bitwarden users should contact support via the official site.

For IT / security teams:

  • Block and hunt the known lookalike domains and the published SHA-256 artifact.
  • Enforce DMARC p=reject, aligned SPF, and MTA-STS mode=enforce on every customer-facing domain — aim for the 100% ideal, not “good enough.”
  • Train users that password managers and e-sign brands are high-value phishing brands in 2026, even when vendor systems are healthy.

Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for DMARC enforcement, MTA-STS deployment, and phishing-response planning.


Sources: LastPass — July 2026 phishing campaign advisory · TechRadar — New phishing campaign hits LastPass, Bitwarden users · EmailMeNow audits — lastpass.com · bitwarden.com · docusign.com