Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Fake LastPass Death Claims Breach Vaults

October 28, 2025
Reading Time: 3 mins read
in Alerts
Toys R Us Canada Data Breach Alert

LastPass has issued an urgent warning to its users regarding a significant phishing operation that began in mid-October. The campaign uses convincing emails that notify recipients of a purported “legacy inheritance” request, claiming a family member uploaded a death certificate to gain emergency access to the vault. Investigators have linked the domains and infrastructure used in this attack to a sophisticated, financially motivated threat group known as CryptoChameleon, or UNC5356, which is well-known for utilizing a specialized phishing kit to target cryptocurrency wallets like Binance, Coinbase, and Kraken, often leveraging fake sign-in pages for services such as Okta and Gmail.

The attack leverages the legitimate LastPass emergency access feature, which is designed to allow a designated individual to request access to the account holder’s vault in the event of death or incapacitation. When a legitimate request is opened, the user is notified via email and access is automatically granted after a specified waiting period, unless the user manually intervenes. The fraudulent emails mimic this process, even including a fabricated agent ID number to bolster credibility, and urge the recipient to “cancel” the request if they are not deceased. This urgent call to action is the core of the social engineering tactic, manipulating users into clicking a malicious link.

Upon clicking the cancellation link, victims are redirected to a fraudulent website, lastpassrecovery[.]com, where they are prompted to enter their master password into a login form. In some reported cases, the threat actors escalated the attack by directly calling the victims while posing as LastPass support staff, effectively directing them to the phishing site to input their credentials. This multi-layered approach highlights the group’s determination to harvest highly sensitive information for financial gain, building on a similar, though less extensive, campaign that targeted LastPass users back in April 2024.

A critical enhancement in this newest iteration of the CryptoChameleon attack is its focus on obtaining passkeys. LastPass reports that the attackers are now employing passkey-focused phishing domains, such as mypasskey[.]info and passkeysetup[.]com, indicating a clear attempt to steal these passwordless credentials. Passkeys, which rely on asymmetric cryptography via FIDO2 / WebAuthn protocols, represent the modern standard for authentication. As contemporary password managers, including LastPass, 1Password, and Bitwarden, increasingly store and synchronize passkeys across devices, they have become a direct and lucrative target for advanced threat actors.

This ongoing compromise adds to the security challenges LastPass has faced since a major data breach in 2022, during which attackers successfully stole encrypted vault backups. That breach was subsequently linked to targeted cryptocurrency theft that resulted in millions of dollars in losses. The current, broader, and more technically enhanced phishing campaign by CryptoChameleon underscores the persistent threat landscape, pushing users to remain vigilant against attempts to exploit both their master passwords and their newer, more secure passkey credentials.

Reference:

  • Fake LastPass Death Claims Used To Trick Users And Breach Password Vaults Widely
Tags: Cyber AlertsCyber Alerts 2025CyberattackCybersecurityOctober 2025
ADVERTISEMENT

Related Posts

ShadowPad Exploits WSUS Flaw For Access

Windows 11 24H2 Explorer And Start Crash

November 24, 2025
ShadowPad Exploits WSUS Flaw For Access

Matrix Push C2 Uses Browser Alerts To Phish

November 24, 2025
ShadowPad Exploits WSUS Flaw For Access

ShadowPad Exploits WSUS Flaw For Access

November 24, 2025
Salesforce Breach Hits Over 200 Victims

Sturnus Trojan Steals Android Chats

November 21, 2025
Salesforce Breach Hits Over 200 Victims

Tsundere Botnet Grows via Game Lures

November 21, 2025
APT24 Uses BADAUDIO in Taiwan Spying

APT24 Uses BADAUDIO in Taiwan Spying

November 21, 2025

Latest Alerts

Windows 11 24H2 Explorer And Start Crash

Matrix Push C2 Uses Browser Alerts To Phish

ShadowPad Exploits WSUS Flaw For Access

Sturnus Trojan Steals Android Chats

Tsundere Botnet Grows via Game Lures

APT24 Uses BADAUDIO in Taiwan Spying

Subscribe to our newsletter

    Latest Incidents

    Delta Dental Virginia Breach Hits 146000

    Iberia Alerts Customers To Data Breach

    Cox Confirms Oracle Hack As Victims Named

    Over 50000 Asus Routers Compromised

    Salesforce Breach Hits Over 200 Victims

    Almaviva Leak Exposes FS Group Data

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial