Welcome to PhishQueue Phishing News, your monthly update on staying ahead of phishing threats.
Fake “Security Policy Update” Emails Are Targeting Password Manager Users
LastPass has confirmed an active phishing campaign that starts with an email designed to look like an official security notice. The email claims you must review updated security policies and “agree” to new terms within 14 days or lose access to your account.
This is a classic phishing setup: an urgent, official-looking email, a countdown, and a link that leads to a fake website built to steal your credentials. The senders are not affiliated with LastPass at all, they simply built a message that looks like it.
How It Works
- You receive an email from an address like hello@lastpassnewsletter.com with the subject “Action Required: Review Updated LastPass Security Policies.”
- The email mentions a recent security incident and asks you to accept new terms, often “via DocuSign,” to keep your account working.
- It warns that your account access will be restricted if you do not act within 14 days, creating pressure to click quickly.
- The link leads to a fake website that impersonates a legitimate service and prompts you to enter credentials or download software.
- Anything entered on that fake site, especially a master password, goes straight to the attacker.
Why It Is Dangerous
- It targets password manager accounts, which can hold the keys to every other account you own.
- The sender name and email design are built to look like a routine, official notice.
- The countdown and “restricted access” warning are designed to make you act before you think.
- The same playbook (urgent email, fake policy update, lookalike domain) works against almost any online account, not just password managers.
Source: blog.lastpass.com
Your Best Defense
Guessing is not your most effective move.
When in doubt, let PhishQueue check it out. PhishQueue will analyze the message for you and tell you if it is safe or malicious, with no risk to you.
What You Can Do Now
- Do not click links in unexpected “security policy” or “account action required” emails.
- Check the sender’s actual email address, not just the display name, before trusting a message.
- No legitimate provider will ever ask for your master password or main account password by email.
- Always use the PhishQueue “Report Phish” button when you are unsure.
Submitting suspicious emails to PhishQueue helps protect you and prevents scams from spreading to others.
Real-World Examples
LastPass Threat Intelligence Blog: LastPass’s own security team describes the campaign, the fake sender domain, and the lookalike site used to steal credentials. (LastPass)
Forbes Coverage: Reporting walks through the actual email wording, the fake urgency tactics used, and why the message is convincing enough to fool a distracted reader. (Forbes)
The Bottom Line
A believable sender name and an urgent deadline do not make an email legitimate. When an email pushes you to act fast on an account policy change, slow down and verify it another way.
Stay safe with PhishQueue.
Quick Tips to Stay Safe
- Pause before clicking any link in an email about account policies or security updates.
- Never enter your password on a site you reached by clicking a link in an email.
- Go directly to the provider’s website by typing the address yourself, instead of clicking through an email.
- Report suspicious messages to PhishQueue instead of trying to determine whether they are legitimate yourself.
Phishing Joke of the Month
Why did the phishing email include a 14-day deadline?
Because “take your time and think it over” has never tricked anyone into anything.
Cybersecurity is serious, but staying informed does not have to be dull!
Stay vigilant,
PhishQueue Team