Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Fake LastPass Death Claims Breach Vaults

October 28, 2025
Reading Time: 3 mins read
in Alerts
Toys R Us Canada Data Breach Alert

LastPass has issued an urgent warning to its users regarding a significant phishing operation that began in mid-October. The campaign uses convincing emails that notify recipients of a purported “legacy inheritance” request, claiming a family member uploaded a death certificate to gain emergency access to the vault. Investigators have linked the domains and infrastructure used in this attack to a sophisticated, financially motivated threat group known as CryptoChameleon, or UNC5356, which is well-known for utilizing a specialized phishing kit to target cryptocurrency wallets like Binance, Coinbase, and Kraken, often leveraging fake sign-in pages for services such as Okta and Gmail.

The attack leverages the legitimate LastPass emergency access feature, which is designed to allow a designated individual to request access to the account holder’s vault in the event of death or incapacitation. When a legitimate request is opened, the user is notified via email and access is automatically granted after a specified waiting period, unless the user manually intervenes. The fraudulent emails mimic this process, even including a fabricated agent ID number to bolster credibility, and urge the recipient to “cancel” the request if they are not deceased. This urgent call to action is the core of the social engineering tactic, manipulating users into clicking a malicious link.

Upon clicking the cancellation link, victims are redirected to a fraudulent website, lastpassrecovery[.]com, where they are prompted to enter their master password into a login form. In some reported cases, the threat actors escalated the attack by directly calling the victims while posing as LastPass support staff, effectively directing them to the phishing site to input their credentials. This multi-layered approach highlights the group’s determination to harvest highly sensitive information for financial gain, building on a similar, though less extensive, campaign that targeted LastPass users back in April 2024.

A critical enhancement in this newest iteration of the CryptoChameleon attack is its focus on obtaining passkeys. LastPass reports that the attackers are now employing passkey-focused phishing domains, such as mypasskey[.]info and passkeysetup[.]com, indicating a clear attempt to steal these passwordless credentials. Passkeys, which rely on asymmetric cryptography via FIDO2 / WebAuthn protocols, represent the modern standard for authentication. As contemporary password managers, including LastPass, 1Password, and Bitwarden, increasingly store and synchronize passkeys across devices, they have become a direct and lucrative target for advanced threat actors.

This ongoing compromise adds to the security challenges LastPass has faced since a major data breach in 2022, during which attackers successfully stole encrypted vault backups. That breach was subsequently linked to targeted cryptocurrency theft that resulted in millions of dollars in losses. The current, broader, and more technically enhanced phishing campaign by CryptoChameleon underscores the persistent threat landscape, pushing users to remain vigilant against attempts to exploit both their master passwords and their newer, more secure passkey credentials.

Reference:

  • Fake LastPass Death Claims Used To Trick Users And Breach Password Vaults Widely
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityOctober 2025
ADVERTISEMENT

Related Posts

Toys R Us Canada Data Breach Alert

ChatGPT Atlas Browser Fooled By Fake Url

October 28, 2025
Toys R Us Canada Data Breach Alert

Chrome Zero Day Delivers LeetAgent

October 28, 2025
Qilin Ransomware Uses Hybrid Attack

Qilin Ransomware Uses Hybrid Attack

October 28, 2025
Qilin Ransomware Uses Hybrid Attack

Hackers Exploit Outdated WordPress Plugins

October 28, 2025
Smishing Triad Tied To Global Phishing

Smishing Triad Tied To Global Phishing

October 28, 2025
China Hackers Breach Telecom Firm

China Hackers Breach Telecom Firm

October 24, 2025

Latest Alerts

Fake LastPass Death Claims Breach Vaults

ChatGPT Atlas Browser Fooled By Fake Url

Chrome Zero Day Delivers LeetAgent

Smishing Triad Tied To Global Phishing

Qilin Ransomware Uses Hybrid Attack

Hackers Exploit Outdated WordPress Plugins

Subscribe to our newsletter

    Latest Incidents

    Google Contractor Steals Play Files

    Vibra Hospital Data Breach Probe

    Hackers Target Swedish Power Grid

    Ex-L3Harris Cyber Boss Charged With Espionage

    Safepay Hits Xortec Video Surveillance Firm

    Hackers Breach Verstappen Data

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial